Hello,
I have the graylog sidecar and nxlog installed and configured on my DC in order to send windows events log, the issue is, although i receive the logs (Application,Security,Setup) properly, i don’t receive all System logs properly, specifically the 104 event id, for event log cleared, although the event id is actually exists and appears in the System log when i check it on Event Viewer.
I am using collector sidecar version 0.1.3 and the DC is a Windows Server 2008r2.
Am i missing anything? Do i need to configure anything else, in the graylog web ui or something?
Thank you