That is one way to do it, this works up to server 2003, server 2008 and so 
on is a little different,
this way there is better handling of the logs.

define ROOT C:\Program Files\nxlog
#define ROOT C:\Program Files (x86)\nxlog

Moduledir %ROOT%\modules
CacheDir %ROOT%\data
Pidfile %ROOT%\data\nxlog.pid
SpoolDir %ROOT%\data
LogFile %ROOT%\data\nxlog.log

<Extension gelf>
    Module       xm_gelf
</Extension>

<Input in>
   Module            im_mseventlog
   Sources           Application,System
</Input>

<Output out>
    Module      om_udp
    Host        10.64.91.18
    Port        8000
    OutputType  GELF
</Output>

 

<Route 1>
    Path        in => out
</Route>

Op maandag 1 juni 2015 09:04:28 UTC+2 schreef [email protected]:
>
> Hello
>
> Found the issue, it was the configuration of NXLOG, I had to tell NXLOG 
> that the input was multiline and the headline/endline were {}, I changed 
> the nxlog.conf as below:
>
> <Extension gelf>
>     Module      xm_gelf
> </Extension>
>
> <Extension multiline>
>     Module      xm_multiline
>     HeaderLine  /^{/
>     EndLine     /^}/
> </Extension>
>
> <Input in>
>
>         Module  im_file
>         File    "/media/winlogs/*"
>         SavePos  TRUE
>         Recursive TRUE
>         InputType       multiline
> </Input>
>
> <Output out>
>     Module      om_udp
>     Host        127.0.0.1
>     Port        12201
>     OutputType  GELF
> </Output>
>
> #<Output out>
> #    Module     om_file
> #    File       "/tmp/output"
> #</Output>
>
>
>
>
> On Sunday, May 31, 2015 at 1:49:06 AM UTC+10, [email protected] wrote:
>>
>> Hello
>>
>> I'm having a problem with graylog and nxlog feed 
>>
>> I have a huge archive of windows event logs, I have been trying to import 
>> these logs into graylog using nxlog and gelf
>>
>> It all works well, nxlog pickup the logs and imports them but the 
>> messages are being split in several records rather tha a single one, 
>>
>>
>> Example if the event log contains the follow
>>
>>
>> *{"1331892664000, 4624, "Success", "Security", 
>> "Microsoft-Windows-Security-Auditing", "An account was successfully logged 
>> on.*
>>
>> *Subject:*
>> * Security ID: S-1-0-0*
>> * Account Name: -*
>> * Account Domain: -*
>> * Logon ID: 0x0*
>>
>> *Logon Type: 3*
>>
>>
>> *This event is generated when a logon session is created. It is generated 
>> on the computer that was accessed.*
>>
>> *Key length indicates the length of the generated session key. This will 
>> be 0 if no session key was requested." "}  *
>>
>>
>> It gets loaded into graylog as:
>>
>> Record 1: *{"1331892664000, 4624, "Success", "Security", 
>> "Microsoft-Windows-Security-Auditing", "An account was successfully logged 
>> on.*
>> Record 2: *Subject*
>> Record 3*: **Security ID: S-1-0-0*
>>
>> etc.
>> etc
>>
>>
>> I just would like to have all the message stored in one record
>>
>> Do you have any idea how this could be achieved?
>>
>> Thanks!
>> Mark
>>
>>
>>
>>
>>
>>

-- 
You received this message because you are subscribed to the Google Groups 
"graylog2" group.
To unsubscribe from this group and stop receiving emails from it, send an email 
to [email protected].
For more options, visit https://groups.google.com/d/optout.

Reply via email to