服务器系统日志怎么拷贝,Windows系统如何将日志发给日志审计服务器?

您好,请知:

使用Nxlog将Windows日志以syslog形式发送至日志Syslog服务器

nxlog下载地址:https://download.csdn.net/download/c1052981766/10299741

下载之后进行安装;

查看服务:

5a1003720990431cf2db5bcbdb1b52bb.png

修改配置文件:C:\Program Files (x86)\nxlog\conf\nxlog.conf

## This is a sample configuration file. See the nxlog reference manual about the## configuration options. It should be installed locally and is also available## online at http://nxlog.org/nxlog-docs/en/nxlog-reference-manual.html ## Please set the ROOT to the folder your nxlog was installed into, ## otherwise it will not start. #define ROOT C:\Program Files\nxlog define ROOT C:\Program Files (x86)\nxlog Moduledir %ROOT%\modules CacheDir %ROOT%\data Pidfile %ROOT%\data\nxlog.pid SpoolDir %ROOT%\data LogFile %ROOT%\data\nxlog.log Module im_msvistalog # For windows 2003 and earlier use the following: # Module im_mseventlogReadFromLast TRUE SavePos FALSE Query \ \ *\ *\ \ Module om_udp Host 192.168.25.65 Port 514 Path in => out

服务端进行监听:

tcpdump udp and src ip -w 25.221.cap

wireshark查看:

bb809d4d4978c2eeca6b1c077863cbb1.png

评论
添加红包

请填写红包祝福语或标题

红包个数最小为10个

红包金额最低5元

当前余额3.43前往充值 >
需支付:10.00
成就一亿技术人!
领取后你会自动成为博主和红包主的粉丝 规则
hope_wisdom
发出的红包
实付
使用余额支付
点击重新获取
扫码支付
钱包余额 0

抵扣说明:

1.余额是钱包充值的虚拟货币,按照1:1的比例进行支付金额的抵扣。
2.余额无法直接购买下载,可以购买VIP、付费专栏及课程。

余额充值