Collecting events logs from Windows systems is a complex problem. Windows does not use syslog natively, and important data is spread between the Windows event logs and flat files. Additionally, without tuning, the logs are not verbose enough to find threats.
NXLog has the ability to pull Windows events. The procedure in this section shows how to install NXLog and ingest Windows Security logs. NXLog can read from flat files for DNS, DHCP, Netlogon, IIS, and any other log file on Windows. However, however, NXLog must first be configured to do so. Please consult Trellix Technical Support for additional configurations beyond Windows Security Logs.
Note
JSON structured data file uploads should use port 515.