Page 1 of 1

Adding additional Windows Log?

Posted: Fri Feb 22, 2019 1:21 pm
by ajwilliamson
I have a new installation of Log Server that I am just beginning to become familiar with.

I had a request come across my desk to day to see if can can alert on a particular Windows server log entry.

I installed NXLog on my first windows server and have logs flowing to the Log Server.

My question is this: Does the NXlog software only forward entries from the big three logs (Application/Security/System)? Or all within a certain directory?

I was asked to alert on event 276 from the 'Admin' Log under "Event Viewer / Applications and Services Logs / AD FS".

I've tried reading through some of the documentation and even looked through several pages on this forum but haven't anything that answers the above.

Any help would be very much appreciated.

Thanks

Re: Adding additional Windows Log?

Posted: Fri Feb 22, 2019 4:37 pm
by npolovenko
Hello, @ajwilliamson. I believe by nxlog pulls all event logs by default. Can you upload the nxlog.conf file so that I could review it? Please keep in mind that when you configure the nxlog only new events will be forwarded to the Logserver.

Re: Adding additional Windows Log?

Posted: Tue Feb 26, 2019 10:13 am
by ajwilliamson
Thanks for the reply.

It appears you are correct, I am indeed receiving the events from all of the logs, I just needed to be patient.

Re: Adding additional Windows Log?

Posted: Tue Feb 26, 2019 1:22 pm
by scottwilkerson
ajwilliamson wrote:Thanks for the reply.

It appears you are correct, I am indeed receiving the events from all of the logs, I just needed to be patient.
Great! Glas it is resolved.

Locking thread