我刚安装了一台华三的日志审计系统,交换机通过配置
info-center loghost x.x.x.x命令,可以将日志发给日志审计系统。
请问Windows系统如何将日志发给日志审计?该如何设置?
刚百度了半天没找到,特意来知了社区咨询,非常感谢!
打华三客户,客服说他只管华三的日志审计系统,不管Windows系统如何操作。
(0)
最佳答案
您好,请知:
nxlog下载地址:https://download.csdn.net/download/c1052981766/10299741
下载之后进行安装;
查看服务:
修改配置文件:C:\Program Files (x86)\nxlog\conf\nxlog.conf
## This is a sample configuration file. See the nxlog reference manual about the## configuration options. It should be installed locally and is also available## online at ***.***/nxlog-docs/en/nxlog-reference-manual.html ## Please set the ROOT to the folder your nxlog was installed into, ## otherwise it will not start. #define ROOT C:\Program Files\nxlog define ROOT C:\Program Files (x86)\nxlog Moduledir %ROOT%\modules CacheDir %ROOT%\data Pidfile %ROOT%\data\nxlog.pid SpoolDir %ROOT%\data LogFile %ROOT%\data\nxlog.log <Input in> Module im_msvistalog # For windows 2003 and earlier use the following: # Module im_mseventlogReadFromLast TRUE SavePos FALSE Query <QueryList>\ <Query >\ <Select Path="System">*</Select>\ <Select Path="Security">*</Select>\ </Query>\ </QueryList> </Input> <Output out> Module om_udp Host 192.168.25.65 Port 514 </Output> <Route 1> Path in => out </Route>
服务端进行监听:
tcpdump udp and src ip -w 25.221.cap
wireshark查看:
(0)
亲~登录后才可以操作哦!
确定你的邮箱还未认证,请认证邮箱或绑定手机后进行当前操作
举报
×
侵犯我的权益
×
侵犯了我企业的权益
×
抄袭了我的内容
×
原文链接或出处
诽谤我
×
对根叔社区有害的内容
×
不规范转载
×
举报说明
暂无评论