Glad to have found this thread. I am close but not successful yet.
I have a Windows 2012 (test server) and want to get the logs into the system.
- I started over and downloaded a Ubuntu virtual machine as outlinned in the docs to run GrayLog. (it is running)
- I downloaded and installed NXLog onto my Windows Test Server, and started a service with pointer to my log files ‘u_ex*.log’ from the inside of my Windows Test Server.
I have not done anything with: SideCar, and cannot get a HTTP message to show up on the VM.
I am sure that I am close but not there .
If anyone sees something wrong with the setup I am attempting, or the information below I would welcome input.
MyConf file from the TestServer
define ROOT C:\Program Files (x86)\nxlog
Fields $date, $time, $s-sitename, $s-computername, $s-ip, $cs-method, $cs-uri-stem, $cs-uri-query, $s-port, $cs-username, $c-ip, $cs-version, $cs(User-Agent), $cs(Cookie), $cs(Referer), $cs-host, $sc-status, $sc-substatus, $sc-win32-status, $sc-bytes, $cs-bytes $time-taken
FieldTypes string, string, string, string, string, string, string, string, string, string, string, string, string, string, string, string, integer, integer, integer, string, string, string
Delimiter ' '
Exec if $raw_event =~ /^#/ drop(); \
$EventTime = parsedate($date + " " + $time); \
$SourceName = "IIS"; \
$Message = to_json(); \
Host xx.xx.xx.xx #my Graylog VM
Path eventlog => graylog
Path iis => graylog
My Log from ‘nxlog.log’
2017-06-16 11:33:09 WARNING stopping nxlog service
2017-06-16 11:33:09 WARNING nxlog-ce received a termination request signal, exiting...
2017-06-16 11:33:10 INFO connecting to xx.xx.xx.xx:12201
2017-06-16 11:33:10 INFO nxlog-ce-2.9.1716 started
My Source on the instance of GrayLog I am running on the downloaded VM I am running.