Advertisement
Not a member of Pastebin yet?
Sign Up,
it unlocks many cool features!
- ## This is a sample configuration file. See the nxlog reference manual about the
- ## configuration options. It should be installed locally and is also available
- ## online at http://nxlog.org/nxlog-docs/en/nxlog-reference-manual.html
- ## Please set the ROOT to the folder your nxlog was installed into,
- ## otherwise it will not start.
- #define ROOT C:\Program Files\nxlog
- define ROOT C:\Program Files (x86)\nxlog
- Moduledir %ROOT%\modules
- CacheDir %ROOT%\data
- Pidfile %ROOT%\data\nxlog.pid
- SpoolDir %ROOT%\data
- LogFile %ROOT%\data\nxlog.log
- <Extension json>
- Module xm_json
- </Extension>
- <Extension w3c>
- Module xm_csv
- Fields $date, $time, $s-ip, $cs-method, $cs-uri-stem, $cs-uri-query, $s-port, $cs-username, $c-ip, $csUser-Agent, $cs-Referer, $sc-status, $sc-substatus, $sc-win32-status, $time-taken
- FieldTypes string, string, string, string, string, string, integer, string, string, string, string, integer, integer, integer, integer
- Delimiter ' '
- QuoteChar '"'
- EscapeControl FALSE
- UndefValue -
- </Extension>
- <Extension fileop>
- Module xm_fileop
- </Extension>
- <Input internal>
- Module im_internal
- Exec to_json();
- </Input>
- <Input eventlog>
- Module im_msvistalog
- Query <QueryList>\
- <Query Id="0">\
- <Select Path="Application">*</Select>\
- <Select Path="System">*</Select>\
- </Query>\
- </QueryList>
- Exec to_json();
- </Input>
- <Input iis_1>
- Module im_file
- File "D:\\RT\\Logs\\Web Pages\\W3SVC1\\u_ex*"
- Exec file_write("C:\\Program Files (x86)\\nxlog\\data\\nxlog_output.log",$raw_event);
- Exec if $raw_event =~ /^#/ drop(); \
- else \
- { \
- w3c->parse_csv(); \
- $EventTime = parsedate($date + " " + $time); \
- to_json (); \
- }
- </Input>
- <Input iis_2>
- Module im_file
- File "D:\\RT\\Logs\\Web Pages\\W3SVC2\\u_ex*"
- Exec file_write("C:\\Program Files (x86)\\nxlog\\data\\nxlog_output.log",$raw_event);
- Exec if $raw_event =~ /^#/ drop(); \
- else \
- { \
- w3c->parse_csv(); \
- $EventTime = parsedate($date + " " + $time); \
- to_json (); \
- }
- </Input>
- <Output out>
- Module om_tcp
- Host 172.16.1.119
- Port 3515
- </Output>
- <Output out_iis>
- Module om_tcp
- Host 172.16.1.119
- Port 3518
- </Output>
- <Route 1>
- Path eventlog, internal => out
- </Route>
- <route 2>
- path iis_1,iis_2 => out_iis
- </route>
Advertisement
Add Comment
Please, Sign In to add comment
Advertisement