This discussion has been locked. The information referenced herein may be inaccurate due to age, software updates, or external references.
You can no longer post new replies to this discussion. If you have a similar question you can start a new discussion in this forum.

How to configure Kiwi Syslog Event Forwarder installed in Windows Server to send syslog in XML format?

We have configured Kiwi Syslog event forwarder on our windows server and its sending to our syslog server in a format that is hard to ingest.

We want the Kiwi Syslog forwarder to send in XML format.

Is it possible, or I have to use an alternative like NXLog?

Parents
  • This is how the MS Event log look like  when forwarded by Kiwi Syslog Event Forwarder:

    Oct 5 10:33:14 <hostname> MSWinEventLog  7  System 2382912 Tue Oct 05 10:33:12 2021 7392 ServiceControl

    Manager   N/A Information <hostname> 0 The Microsoft Account Sign-in Assistant service entered the running state

    Oct 5 10:33:18  <hostname> MSWinEventLog 5 Security2489291 Tue Oct 05 10:33:16 2021 4624 Microsoft-Windows-

    Security-Auditing  N/A Audit Success  <hostname> 2283  An Account was successfully logged on.

    Subject: 

            Security ID: S-x-x-x

           Account Name:   xxx

            Account Domain: xx

           Logon ID: 0xx

    Logon Information:  

                  Logon Type: 5

                  Restrcted Admin Mode:

                  Virtual Account : No

                   Elevated Token:  Yes

    Impersonation Level: Impersonation

    New Logon:

    You get the idea, the info that is sent is very disorganized, can it send using the original XML format?

Reply
  • This is how the MS Event log look like  when forwarded by Kiwi Syslog Event Forwarder:

    Oct 5 10:33:14 <hostname> MSWinEventLog  7  System 2382912 Tue Oct 05 10:33:12 2021 7392 ServiceControl

    Manager   N/A Information <hostname> 0 The Microsoft Account Sign-in Assistant service entered the running state

    Oct 5 10:33:18  <hostname> MSWinEventLog 5 Security2489291 Tue Oct 05 10:33:16 2021 4624 Microsoft-Windows-

    Security-Auditing  N/A Audit Success  <hostname> 2283  An Account was successfully logged on.

    Subject: 

            Security ID: S-x-x-x

           Account Name:   xxx

            Account Domain: xx

           Logon ID: 0xx

    Logon Information:  

                  Logon Type: 5

                  Restrcted Admin Mode:

                  Virtual Account : No

                   Elevated Token:  Yes

    Impersonation Level: Impersonation

    New Logon:

    You get the idea, the info that is sent is very disorganized, can it send using the original XML format?

Children
No Data