Advertisement
Not a member of Pastebin yet?
Sign Up,
it unlocks many cool features!
- ## Please set the ROOT to the folder your nxlog was installed into,
- ## otherwise it will not start.
- #define ROOT C:\Program Files\nxlog
- define ROOT C:\Program Files (x86)\nxlog
- Moduledir %ROOT%\modules
- CacheDir %ROOT%\data
- Pidfile %ROOT%\data\nxlog.pid
- SpoolDir %ROOT%\data
- LogFile %ROOT%\data\nxlog.log
- <Extension json>
- Module xm_json
- </Extension>
- # Nxlog internal logs
- <Input internal>
- Module im_internal
- Exec $EventReceivedTime = integer($EventReceivedTime) / 1000000; to_json();
- </Input>
- # Windows Event Log
- <Input eventlog>
- # Uncomment im_msvistalog for Windows Vista/2008 and later
- Module im_msvistalog
- Query <QueryList>\
- <Query Id="0">\
- <Select Path='Security'>*[System[(EventID='4624') ]]</Select> \
- <Select Path='Security'>*[System[(EventID='4625') ]]</Select> \
- <Select Path='Security'>*[System[(EventID='4648') ]]</Select> \
- <Select Path='Security'>*[System[(EventID='4728') ]]</Select> \
- <Select Path='Security'>*[System[(EventID='4732') ]]</Select> \
- <Select Path='Security'>*[System[(EventID='4634') ]]</Select> \
- <Select Path='Security'>*[System[(EventID='4735') ]]</Select> \
- <Select Path='Security'>*[System[(EventID='4740') ]]</Select> \
- <Select Path='Security'>*[System[(EventID='4756') ]]</Select> \
- </Query>\
- <Query Id="1"> \
- <Select Path='Security'>*[System[(EventID='1022') ]]</Select> \
- <Select Path='Security'>*[System[(EventID='4633') ]]</Select> \
- <Select Path='Security'>*[System[(EventID='5038') ]]</Select> \
- <Select Path='Security'>*[System[(EventID='6281') ]]</Select> \
- <Select Path='Security'>*[System[(EventID='219') ]]</Select> \
- <Select Path='Security'>*[System[(EventID='104') ]]</Select> \
- <Select Path='Security'>*[System[(EventID='1102') ]]</Select> \
- <Select Path='Security'>*[System[(EventID='7045') ]]</Select> \
- </Query> \
- <Query Id="2">\
- <Select Path='Security'>*[System[(EventID='43') ]]</Select> \
- <Select Path='Security'>*[System[(EventID='400') ]]</Select> \
- <Select Path='Security'>*[System[(EventID='410') ]]</Select> \
- </Query>\
- </QueryList>
- # Uncomment im_mseventlog for Windows XP/2000/2003
- # Module im_mseventlog
- Exec $EventReceivedTime = integer($EventReceivedTime) / 1000000; to_json();
- </Input>
- <Output out>
- Module om_tcp
- Host 120.40.80.131
- Port 5516
- </Output>
- <Route 1>
- Path internal, eventlog => out
- </Route>
Advertisement
Add Comment
Please, Sign In to add comment
Advertisement