NXLog
NXLog is the workhorse of Windows logging plugins. You can use our configuration file for NXLog to set up the ingestion of Windows events logs to Mezmo.
Set Up NXLog Log Ingestion
Follow the instructions in the Mezmo Web App to set up NXLog log ingestion using your Mezmo syslog port and security certificate
- Log in to the Mezmo Web App.
- In the bottom section of the left-hand navigation, click Help.
- Select Add Log Sources.
- Under Via platform, click NXLog.
- Follow the instructions to set up NXLog log ingestion.
You can also get a copy of the NXLog configuration file from our GitHub repository.
Example NXLog Configuration File
Copy the following config to $NXLOGDIR\conf\nxlog.conf, where $NXLOGDIR is directory nxlog is installed in.
Customizing the Config
-
Windows Event Logging is captured in lines
61—73.- Uncomment the lines to enable logging from the specified channels
- Comment out the lines to disable logging from the specified channels
- Add custom channels to enable logging from into the same
Queryblock
-
Windows File Logging is capture in lines
47—59.- Update log directory where to stream logs from log files located in line
48 - Update log files to stream logs from in line
52
- Update log directory where to stream logs from log files located in line
-
All input, processor, and output channels are connected in route block.
- Comment out the whole block and remove from the route to disable logging from specific input channel
- Add new input modules with unique names to be added to the route to enable logging from new sources
Example for Tailing Additional Log Files
You can add additional logfiles by creating a new
<Input {name}>section that imitates the previous ones, and adding the name of that section to<Route 1>at the end.
---published
NXLog is the workhorse of Windows logging plugins. You can use our configuration file for NXLog to set up the ingestion of Windows events logs to Mezmo.
Set Up NXLog Log Ingestion
Follow the instructions in the Mezmo Web App to set up NXLog log ingestion using your Mezmo syslog port and security certificate
- Log in to the Mezmo Web App.
- In the bottom section of the left-hand navigation, click Help.
- Select Add Log Sources.
- Under Via platform, click NXLog.
- Follow the instructions to set up NXLog log ingestion.
You can also get a copy of the NXLog configuration file from our GitHub repository.
Example NXLog Configuration File
You can add additional logfiles by creating a new
<Input {name}>section that imitates the previous ones, and adding the name of that section to<Route 1>at the end.