The windows-eventlog-xml-parser() can parse messages in the Windows XML Event Log (EVTX) format.
Prerequisites
Available in AxoSyslog version 4.5 and later.
On Debian/Ubuntu, this feature is available in a separate module: install the axosyslog-mod-xml-parser package. On RHEL and compatible distributions, it’s part of the axosyslog base package. If the module isn’t installed, AxoSyslog fails to start with an unexpected LL_IDENTIFIER error.
Configuration
See also the equivalent FilterX function, parse_windows_eventlog_xml().
Example configuration:
parser p_win {
windows-eventlog-xml-parser(prefix(".winlog."));
};The windows-eventlog-xml-parser() parser has the same parameters are the same as the xml() parser.
Don’t forget to include the parsers in a log statement to actually use it:
log {
source(s_local);
parser(windows-eventlog-xml-parser(prefix(".winlog.")));
destination(d_local);
};