@tmacgbay Hi so i think i have been able to get rid of some of the errors but i’m not receiving any logs on graylog server
My SIdecar logs
ime=“2019-04-24T15:50:52+01:00” level=info msg=“Starting signal distributor”
time=“2019-04-24T15:51:02+01:00” level=info msg=“Adding process runner for: nxlog”
time=“2019-04-24T15:51:02+01:00” level=info msg="[nxlog] Configuration change detected, rewriting configuration file."
time=“2019-04-24T15:51:02+01:00” level=info msg="[nxlog] Starting (svc driver)"
019-04-24 15:51:02 INFO nxlog-ce-2.10.2150 started 2019-04-24 15:51:02 ERROR apr_sockaddr_info failed for 192.168.3.44:5044:5044; No such host is known. 2019-04-24 15:51:03 WARNING Due to a limitation in the Windows EventLog subsystem, a query cannot contain more than 256 sources. 2019-04-24 15:51:03 WARNING The following sources are omitted to avoid exceeding the limit in the generated query: Microsoft-Windows-SMBServ
Sorry for bombarding you with so much info