Advertisement
Not a member of Pastebin yet?
Sign Up,
it unlocks many cool features!
- ## Please set the ROOT to the folder your nxlog was installed into,
- ## otherwise it will not start.
- #define ROOT C:\Program Files\nxlog
- define ROOT C:\Program Files (x86)\nxlog
- Moduledir %ROOT%\modules
- CacheDir %ROOT%\data
- Pidfile %ROOT%\data\nxlog.pid
- SpoolDir %ROOT%\data
- LogFile %ROOT%\data\nxlog.log
- <Extension json>
- Module xm_json
- </Extension>
- <Extension syslog>
- Module xm_syslog
- </Extension>
- <Processor transformer>
- Module pm_transformer
- OutputFormat syslog_rfc3164
- </Processor>
- # Nxlog internal logs
- <Input internal>
- Module im_internal
- Exec $EventReceivedTime = integer($EventReceivedTime) / 1000000; to_json();
- </Input>
- # Windows Event Log
- <Input eventlog>
- # Uncomment im_msvistalog for Windows Vista/2008 and later
- Module im_msvistalog
- # Uncomment im_mseventlog for Windows XP/2000/2003
- # Module im_mseventlog
- Query <QueryList>\
- <Query Id="0">\
- <Select Path="Security">*</Select>\
- <Suppress Path="Security">*[System[(EventID=4624 or EventID=4776 or EventID=4634 or EventID=4672 or EventID=4688)]]</Suppress>\
- <Select Path="System">*[System[(EventID=1074 or (EventID >= 6005 and EventID <= 6009) or EventID=6013)]]</Select>\
- <Select Path="Microsoft-Windows-TerminalServices-LocalSessionManager/Operational">*</Select>\
- </Query>\
- </QueryList>
- Exec $EventReceivedTime = integer($EventReceivedTime) / 1000000; to_json();
- </Input>
- <Input IIS_In>
- Module im_file
- File "C:\inetpub\logs\LogFiles\W3SVC2\u_ex*"
- Exec $Message = $raw_event;
- SavePos TRUE
- Recursive TRUE
- </Input>
- #<Input vCenter_vpxd>
- #Module im_file
- #File "C:\ProgramData\VMware\VMware VirtualCenter\Logs\vpxd-[0-5][0-9].log"
- #Exec $Message = to_json();
- #SavePos TRUE
- #Recursive TRUE
- #</Input>
- #<Input vCenter_vpxd_alert>
- #Module im_file
- #File "C:\ProgramData\VMware\VMware VirtualCenter\Logs\vpxd-alert-[0-5][0-9].log"
- #Exec $Message = to_json();
- #SavePos TRUE
- #Recursive TRUE
- #</Input>
- <Output eventlog_out>
- Module om_tcp
- Host 10.0.2.13
- Port 3515
- </Output>
- <Output IIS_Out>
- Module om_tcp
- Host logstash
- Port 3525
- </Output>
- #<Output vCenter_out>
- #Module om_tcp
- #Host logstash
- #Port 1515
- #</Output>
- <Route 1>
- Path internal, eventlog => eventlog_out
- </Route>
- <Route 2>
- Path IIS_In => transformer => IIS_Out
- </Route>
- #<Route 3>
- #Path vCenter_vpxd, vCenter_vpxd_alert => vCenter_out
- #</Route>
Advertisement
Add Comment
Please, Sign In to add comment
Advertisement