# Windows Event Forwarding to Linux server using Nxlog

## Introduction

Windows Event Forwarding (WEF) allows the collection of event logs from multiple Windows machines and their forwarding to a centralized server. Using Nxlog, you can send these logs to a Linux server for storage and analysis. This documentation provides a step-by-step guide to set up Windows Event Forwarding using Nxlog to send logs to a Linux server.

## Prerequisites

- **Windows Server or Workstation**: The machine that will send logs.
- **Linux Server**: The machine that will receive logs.
- **Nxlog**: Download the latest version of Nxlog for Windows from [Nxlog's official website](https://nxlog.co/downloads).
- **Network Connectivity**: Ensure both machines can communicate over the network.
- **Rsyslog:** Download the latest version of Rsyslog for Linux server or workstation.

<div class="group/conversation-turn relative flex w-full min-w-0 flex-col agent-turn" id="bkmrk-"><div class="flex-col gap-1 md:gap-3"><div class="flex max-w-full flex-col flex-grow"><div class="min-h-8 text-message flex w-full flex-col items-end gap-2 whitespace-normal break-words [.text-message+&]:mt-5" data-message-author-role="assistant" data-message-id="8bbd0118-21e6-4342-99e3-f13ec63cf796" data-message-model-slug="gpt-4o-mini" dir="auto"><div class="flex w-full flex-col gap-1 empty:hidden first:pt-[3px]"></div></div></div></div></div>## Installing Nxlog on Windows

<div class="group/conversation-turn relative flex w-full min-w-0 flex-col agent-turn" id="bkmrk-download-nxlog%3A-obta"><div class="flex-col gap-1 md:gap-3"><div class="flex max-w-full flex-col flex-grow"><div class="min-h-8 text-message flex w-full flex-col items-end gap-2 whitespace-normal break-words [.text-message+&]:mt-5" data-message-author-role="assistant" data-message-id="8bbd0118-21e6-4342-99e3-f13ec63cf796" data-message-model-slug="gpt-4o-mini" dir="auto"><div class="flex w-full flex-col gap-1 empty:hidden first:pt-[3px]"><div class="markdown prose w-full break-words dark:prose-invert light">1. **Download Nxlog**:
    
    
    - Obtain the Nxlog Community Edition installer from the official website.
2. **Install Nxlog**:
    
    
    - Run the installer and follow the prompts to complete the installation.
3. **Start Nxlog Service**:
    
    
    - Start the Nxlog service using the Services management console or command line: **net start nxlog**  
        <div class="flex items-center text-token-text-secondary px-4 py-2 text-xs font-sans justify-between rounded-t-md h-9 bg-token-sidebar-surface-primary dark:bg-token-main-surface-secondary">  
        </div>

</div></div></div></div></div></div>## Configuring Nxlog on Windows

1. **Open Configuration File**:
    
    
    - Edit the Nxlog configuration file located at `C:\Program Files\nxlog\conf\nxlog.conf`.
2. **Configure File**:
    
    
    - Add the following lines to capture Windows Event Logs and send the logs : <div class="overflow-y-auto p-4" dir="ltr"><div>\# Input Module</div><div>&lt;Input eventlog&gt;</div><div> Module im_msvistalog</div><div> ReadFromLast True</div><div> &lt;QueryXML&gt;</div><div>&lt;QueryList&gt;</div><div>&lt;Query Id='1'&gt;</div><div>&lt;Select Path='Application'&gt;*&lt;/Select&gt;</div><div>&lt;Select Path='Security'&gt;*&lt;/Select&gt;</div><div>&lt;Select Path='System'&gt;*&lt;/Select&gt;</div><div>&lt;/Query&gt;</div><div>&lt;/QueryList&gt;</div><div> &lt;/QueryXML&gt;</div><div>&lt;/Input&gt;</div><div>  
        </div><div>\# Output Module</div><div>&lt;Output out&gt;</div><div> Module om_udp</div><div> Host 192.168.20.24 </div><div> Port 514 </div><div> # Exec $raw_event = "&lt;" + $syslog_severity + "&gt;" + $time + " " + $hostname + " " + $procname + ": " + $raw_event; </div><div> Exec parse_syslog_ietf();</div><div>&lt;/Output&gt;</div><div>  
        </div><div>\# Route</div><div>&lt;Route r&gt;</div><div> Path eventlog =&gt; out</div><div>&lt;/Route&gt;</div><div>  
        </div><div>\# Include any other necessary modules/extensions</div><div>&lt;Extension _syslog&gt;</div><div> Module xm_syslog</div><div>&lt;/Extension&gt;</div></div>

### Installing Rsyslog on Linux

- **Install Rsyslog**:
    
    
    - For Ubuntu, run: <div class="contain-inline-size rounded-md border-[0.5px] border-token-border-medium relative bg-token-sidebar-surface-primary dark:bg-gray-950"><div class="sticky top-9 md:top-[5.75rem]"></div><div class="overflow-y-auto p-4" dir="ltr">**sudo apt update sudo apt install rsyslog**</div></div>
- **Enable Rsyslog**:
    
    
    - Ensure Rsyslog is enabled and started: <div class="contain-inline-size rounded-md border-[0.5px] border-token-border-medium relative bg-token-sidebar-surface-primary dark:bg-gray-950"><div class="overflow-y-auto p-4" dir="ltr">**sudo systemctl enable rsyslog sudo systemctl start rsyslog**</div></div><div class="overflow-y-auto p-4" dir="ltr"></div>

#### Configuring Rsyslog on Linux

1. **Open Configuration File**:
    
    
    - Edit /etc/rsyslog.conf or create a new config file in /etc/rsyslog.d/.
2. **Configure Rsyslog to Listen for UDP**:**module(load="imudp") # Load UDP listener input(type="imudp" port="514")**
3. **Define Output File**:
    
    
    - Specify where to store the incoming logs:
    
    <div class="contain-inline-size rounded-md border-[0.5px] border-token-border-medium relative bg-token-sidebar-surface-primary dark:bg-gray-950"><div class="sticky top-9 md:top-[5.75rem]"></div><div class="overflow-y-auto p-4" dir="ltr">**\*.\* /var/log/windows\_events.log**</div></div>
4. **Save and Exit**:
    
    
    - Save the configuration file and restart Rsyslog: <div class="contain-inline-size rounded-md border-[0.5px] border-token-border-medium relative bg-token-sidebar-surface-primary dark:bg-gray-950"><div class="overflow-y-auto p-4" dir="ltr">**sudo systemctl restart rsyslog**</div></div><div class="overflow-y-auto p-4" dir="ltr"></div>

#### Firewall Configuration

#### Windows Firewall

1. **Open Windows Defender Firewall**:
    
    
    - Go to **Control Panel** &gt; **System and Security** &gt; **Windows Defender Firewall**.
2. **Allow Port 514**:
    
    
    - In the left pane, click **Advanced settings**.
    - Select **Inbound Rules** and click on **New Rule**.
    - Choose **Port**, then click **Next**.
    - Select **UDP** and enter **514** in the Specific local ports field.
    - Allow the connection and complete the rule setup.

#### Firewalld Configuration on Linux

1. **Open Port 514 for UDP**:
    
    <div class="contain-inline-size rounded-md border-[0.5px] border-token-border-medium relative bg-token-sidebar-surface-primary dark:bg-gray-950"><div class="sticky top-9 md:top-[5.75rem]"></div><div class="overflow-y-auto p-4" dir="ltr">**sudo firewall-cmd --permanent --add-port=514/udp**</div></div>
2. **Reload Firewalld**:
    
    <div class="contain-inline-size rounded-md border-[0.5px] border-token-border-medium relative bg-token-sidebar-surface-primary dark:bg-gray-950"><div class="sticky top-9 md:top-[5.75rem]"></div><div class="overflow-y-auto p-4" dir="ltr">**sudo firewall-cmd --reload**</div></div>
3. **Verify Open Ports**:
    
    <div class="contain-inline-size rounded-md border-[0.5px] border-token-border-medium relative bg-token-sidebar-surface-primary dark:bg-gray-950"><div class="sticky top-9 md:top-[5.75rem]"></div><div class="overflow-y-auto p-4" dir="ltr">**sudo firewall-cmd --list-all**</div></div>

### Verifying Event Forwarding

1. **Check Nxlog Status on Windows**:
    
    <div class="contain-inline-size rounded-md border-[0.5px] border-token-border-medium relative bg-token-sidebar-surface-primary dark:bg-gray-950"><div class="sticky top-9 md:top-[5.75rem]"></div><div class="overflow-y-auto p-4" dir="ltr">**nxlog -v**  
    </div></div>
2. **Monitor Logs on Linux**:
    
    
    - Use the following command to view the log file:
    
    <div class="contain-inline-size rounded-md border-[0.5px] border-token-border-medium relative bg-token-sidebar-surface-primary dark:bg-gray-950"><div class="sticky top-9 md:top-[5.75rem]"></div><div class="overflow-y-auto p-4" dir="ltr">**tail -f /var/log/windows\_events.log**</div></div>
3. **Review Rsyslog Logs**:
    
    
    - If issues arise, check Rsyslog logs located at **/var/log/syslog** or **/var/log/messages.**