Hi,
There is a known issue with recent windows versions (e.g. windows 8) as
some eventlog sources are giving ERROR_INVALID_DATA.
The workaround is to specify the QueryXML manually, which will
unfortunately omit some sources, but may be sufficient for most users:
Query <QueryList>\
<Query Id="0">\
<Select Path="Application">*</Select>\
<Select Path="System">*</Select>\
<Select Path="Security">*</Select>\
</Query>\
</QueryList>
What version of windows are you using?
We are working on the fix for this issue and will be able to provide a
solution in the next release. Unfortunately some of this is likely to be a
problem in windows, since Analytic sources are not (cannot be) monitored,
yet the "Microsoft-Windows-DxpTaskRingtone/Analytic" claims that it is not
"analytic" (thus the warning). Not sure if the "Couldn't read next event,
corrupted eventlog" error is related to this or not.
Regards,
Botond
On Sat, Mar 22, 2014 at 9:18 PM, Jenei Gábor <jen...@elte.hu> wrote:
> Hello
>
>
>
>
>
>
>
> I've just found nxlog which would be quite useful for me, as I'm trying to
> make a log analyzer that listens on port 514 TCP, and I'd like to capture
> windows event log messages here. But as I start nxlog it doesn't send
> messages :( In the error log I've found:
>
>
>
> 2014-03-22 20:04:28 INFO nxlog-ce-2.7.1191 started
>
> 2014-03-22 20:04:28 INFO connecting to localhost:514
>
> 2014-03-22 20:04:28 WARNING ignoring source as it cannot be subscribed to
> (error code: 2): <Query Id='87'><Select
> Path='Microsoft-Windows-DxpTaskRingtone/Analytic'>*</Select></Query>
>
> 2014-03-22 20:04:29 ERROR Couldn't read next event, corrupted eventlog?;
> Érvénytelen adatok.
>
>
>
> the last one says in hungarian: Invalid data. Could you help me to resolve
> this problem?
>
>
>
> Thank you,
>
>
>
> Gábor Jenei
>
------------------------------------------------------------------------------
Learn Graph Databases - Download FREE O'Reilly Book
"Graph Databases" is the definitive new guide to graph databases and their
applications. Written by three acclaimed leaders in the field,
this first edition is now available. Download your free book today!
http://p.sf.net/sfu/13534_NeoTech
_______________________________________________
nxlog-ce-users mailing list
nxlog-ce-users@lists.sourceforge.net
https://lists.sourceforge.net/lists/listinfo/nxlog-ce-users