Versions Compared

Key

  • This line was added.
  • This line was removed.
  • Formatting was changed.

To export logs from Windows machines/servers, we use a third party software called "Nxlog".

NXLog is a multi-platform log management tool that helps to easily identify security risks, policy breaches or analyze operational problems in server logs, operation system logs and application logs. In concept, NXLog is similar to syslog-ng or Rsyslog but it is not limited to UNIX and syslog only. It supports different platforms(like windows in our case), log sources and formats, so NXLog can be used to implement a centralized, scalable logging system. NXLog Community Edition is open source and can be downloaded free of charge with no license costs or limitations.

A. Types of Windows logs

Windows servers have two type of logs:

...

For these, we can use both the Event collection options - AB.1 or AB.2 below, to collect the events. Example - OS Logs, Audit Logs and USB Logs.

...