Step-by-Step Guide: Sending Windows Event Logs to Graylog With NXLOG
Lawrence Systems Lawrence Systems
326K subscribers
13,426 views
0

 Published On Jan 21, 2024

https://lawrence.video/

This is a guide for sending logs from Windows to Graylog using NXLog and the Graylog GELF format. The tutorial uses sysmon-modular which also adds the MITRE ATT&CK to the log files based on certain commands being run.

Forum post with links & downloads used in the video:
https://lawrence.video/graylogwindows

How To Install Graylog Tutorial
   • Graylog: Your Comprehensive Guide to ...  


Connecting With Us
---------------------------------------------------
+ Hire Us For A Project: https://lawrencesystems.com/hire-us/
+ Tom Twitter 🐦   / tomlawrencetech  
+ Our Web Site https://www.lawrencesystems.com/
+ Our Forums https://forums.lawrencesystems.com/
+ Instagram   / lawrencesystems  
+ Facebook   / lawrencesystems  
+ GitHub https://github.com/lawrencesystems/
+ Discord   / discord  

Lawrence Systems Shirts and Swag
---------------------------------------------------
►👕 https://lawrence.video/swag/


AFFILIATES & REFERRAL LINKS
---------------------------------------------------
Amazon Affiliate Store
🛒 https://www.amazon.com/shop/lawrences...

UniFi Affiliate Link
🛒 https://store.ui.com?a_aid=LTS

All Of Our Affiliates that help us out and can get you discounts!
🛒 https://lawrencesystems.com/partners-...

Gear we use on Kit
🛒 https://kit.co/lawrencesystems

Use OfferCode LTSERVICES to get 10% off your order at
🛒 https://www.techsupplydirect.com?aff=2

Digital Ocean Offer Code
🛒 https://m.do.co/c/85de8d181725

HostiFi UniFi Cloud Hosting Service
🛒 https://hostifi.net/?via=lawrencesystems

Protect you privacy with a VPN from Private Internet Access
🛒 https://www.privateinternetaccess.com...

Patreon
💰   / lawrencesystems  

Chapters
00:00 Sending Windows Event Logs to Graylog With NXLOG
02:16 Sysmon and Sysmon-Modular
03:27 Download NXLOG
04:16 Gralog GELF input Setup
04:53 Installing Sysmon and NXLOG
07:00 Showing MITRE ATT&CK Log Data

#graylog #logging #siem

show more

Share/Embed