Advertisement
Not a member of Pastebin yet?
Sign Up,
it unlocks many cool features!
- define ROOT C:\Program Files (x86)\nxlog
- Moduledir %ROOT%\modules
- CacheDir %ROOT%\data
- Pidfile %ROOT%\data\nxlog.pid
- SpoolDir %ROOT%\data
- LogFile %ROOT%\data\nxlog.log
- <Extension gelf>
- Module xm_gelf
- </Extension>
- <Input in>
- Module im_msvistalog
- ReadFromLast True
- <QueryXML>
- <QueryList>
- <Query Id="0">
- <Select Path="Account Management">*[User Account Management[(EventID='4720, 4722, 4723, 4724, 4725, 4726, 4738, 4740', 4767, 4781, 4798')]]</Select>
- <Select Path="Account Management">*[Security Group Management[(EventID='4727, 4728, 4729, 4730, 4731, 4732, 4733, 4734, 4735, 4737, 4754, 4755, 4756, 4757, 4758, 4764, 4799')]]</Select>
- <Select Path="Account Management">*[Computer Account Management[(EventID='4742, 4743')]]</Select>
- <Select Path="Account Management">*[Distribution Group Management[(EventID='4744, 4745, 4746, 4747, 4748, 4749, 4750, 4751, 4752, 4753, 4759, 4760, 4761, 4762')]]</Select>
- <Select Path="DS Access">*[Directory Service Access[(EventID='5136, 5137, 5138, 5139, 5141')]]</Select>
- <Select Path="Object Access">*[File Share[(EventID='5142, 5143, 5144')]]</Select>
- <Select Path="Policy Change">*[Authorization Policy Change[(EventID='4704, 4705')]]</Select>
- <Select Path="Policy Change">*[Audit Policy Change[(EventID='4719')]]</Select>
- <Select Path="Policy Change">*[Authentication Policy Change[(EventID='4739')]]</Select>
- </Query>
- </QueryList>
- </QueryXML>
- </Input>
- <Output out>
- Module om_tcp
- Host 127.0.0.1
- Port 12201
- OutputType GELF_TCP
- </Output>
- <Route 1>
- Path in => out
- </Route>
Advertisement
Advertisement
Advertisement
RAW Paste Data
Copied
Advertisement