I am using nxlog with sidecars to collect windows logs from 5 machines. I can only see logs from 1 machine at a time in Graylog UI. On restarting Graylog, logs from the other machine will show up, but logs from one machine at a time is visible. Nxlog file configuration is same on all machines and sidecar status is looking healthy. tcpdump shows logs from all machines.
I have no idea what to look for. Any help will be appreciated.
Are all graylog sidecar services running on your windows systems (like “Graylog Sidecar” and like Graylog Collector)?
Have you checked the current sidecar logfile on your windows system: C:\Program Files\Graylog\sidecar\logs\sidecar.txt ?
Have you tried to collect the logs with winlogbeat?
The hostnames (and IP adresses) are not the same on the windows systems?
There are not that many log entries for the “Security” log (your only input). Try to extend your Querylist with e.g. “Application” and “System” and / or trigger an event manually on the cmd: eventcreate /T ERROR / ID 100 /L Security /D "Test Entry"
Adding on to @valhaim suggested. What type of INPUT are you using that you have to configure your output with an Exec to JSON then with to_syslog_bsd? Just curious.
Was this working before or this just happen?
Thanks for your reply. I am using syslog UDP input as the logs are being converted to Syslog from Jason format.
It started working a few days ago but having some hiccups again. Logs are coming from a few machines without any issues which means my script and input are working fine. A few machine disappears in between. tcpdump is all good, restarting graylog fix everything for a few minutes. I have 150 log sources, but windows are problematic,
I do have some index failure messages, however unable to figure out what messages are being dropped. Any help on finding the log messages with letter id would be appreciated.
This depends on your Windows log shipper configuration, perhaps what type of Input your using. Input (Syslog UDP) should not create that many fields, GELF or using a bunch of extractors/pipelines would possably create that many.