Advertisement
Guest User

Untitled

a guest
Oct 16th, 2017
210
Never
Not a member of Pastebin yet? Sign Up, it unlocks many cool features!
  1. define ROOT C:\Program Files (x86)\nxlog
  2.  
  3. Moduledir %ROOT%\modules
  4. CacheDir %ROOT%\data
  5. Pidfile %ROOT%\data\nxlog.pid
  6. SpoolDir %ROOT%\data
  7. LogFile %ROOT%\data\nxlog.log
  8.  
  9. <Extension gelf>
  10.     Module xm_gelf
  11. </Extension>
  12.  
  13. <Input in>
  14.     Module im_msvistalog
  15.     ReadFromLast    True
  16.     <QueryXML>
  17.         <QueryList>
  18.             <Query Id="0">
  19.                 <Select Path="Account Management">*[User Account Management[(EventID='4720, 4722, 4723, 4724, 4725, 4726, 4738, 4740', 4767, 4781, 4798')]]</Select>
  20.                 <Select Path="Account Management">*[Security Group Management[(EventID='4727, 4728, 4729, 4730, 4731, 4732, 4733, 4734, 4735, 4737, 4754, 4755, 4756, 4757, 4758, 4764, 4799')]]</Select>
  21.                 <Select Path="Account Management">*[Computer Account Management[(EventID='4742, 4743')]]</Select>
  22.                 <Select Path="Account Management">*[Distribution Group Management[(EventID='4744, 4745, 4746, 4747, 4748, 4749, 4750, 4751, 4752, 4753, 4759, 4760, 4761, 4762')]]</Select>
  23.                 <Select Path="DS Access">*[Directory Service Access[(EventID='5136, 5137, 5138, 5139, 5141')]]</Select>
  24.                 <Select Path="Object Access">*[File Share[(EventID='5142, 5143, 5144')]]</Select>
  25.                 <Select Path="Policy Change">*[Authorization Policy Change[(EventID='4704, 4705')]]</Select>
  26.                 <Select Path="Policy Change">*[Audit Policy Change[(EventID='4719')]]</Select>
  27.                 <Select Path="Policy Change">*[Authentication Policy Change[(EventID='4739')]]</Select>
  28.             </Query>
  29.         </QueryList>
  30.     </QueryXML>
  31. </Input>
  32.  
  33. <Output out>
  34.     Module      om_tcp
  35.     Host        127.0.0.1
  36.     Port        12201
  37.     OutputType  GELF_TCP
  38. </Output>
  39.  
  40. <Route 1>
  41.     Path        in => out
  42. </Route>
Advertisement
Advertisement
Advertisement
RAW Paste Data Copied
Advertisement