Advertisement
Not a member of Pastebin yet?
Sign Up,
it unlocks many cool features!
- define ROOT C:\Program Files (x86)\nxlog
- Moduledir %ROOT%\modules
- CacheDir %ROOT%\data
- Pidfile %ROOT%\data\nxlog.pid
- SpoolDir %ROOT%\data
- LogFile %ROOT%\data\nxlog.log
- <Extension gelf>
- Module xm_gelf
- </Extension>
- <Input in>
- Module im_msvistalog
- ReadFromLast True
- Query <QueryList>\
- <Query Id="0">\
- <Select Path="Security">*[Security[(EventID='4704, 4705, 4719, 4720, 4722, 4723, 4724, 4725, 4726, 4727, 4728, \
- 4729, 4730, 4731, 4732, 4733, 4734, 4735, 4737, 4738, 4739, 4740, 4742, 4743, 4744, 4745, 4746, 4747, 4748, 4749, \
- 4750, 4751, 4752, 4753, 4754, 4755, 4756, 4757, 4758, 4759, 4760, 4761, 4762, 4764, 4767, 4781, 4798, 4799, 5136, \
- 5137, 5138, 5139, 5141, 5142, 5143, 5144')]]</Select>\
- </Query>\
- </QueryList>
- </Input>
- <Output out>
- Module om_tcp
- Host 10.105.150.241
- Port 12201
- OutputType GELF_TCP
- </Output>
- <Route 1>
- Path in => out
- </Route>
Advertisement
Add Comment
Please, Sign In to add comment
Advertisement