Ad Widget

Collapse

Win Eventlog from non canonical (from System, Application, etc. it works perfectly)

Collapse
X
 
  • Time
  • Show
Clear All
new posts
  • GlobalVision
    Junior Member
    • Feb 2022
    • 11

    #1

    Win Eventlog from non canonical (from System, Application, etc. it works perfectly)

    Hi everyone,

    I am new in this field and I cannot receive data from non-canonical registers (from System, Application, etc. works perfectly)

    How do I get the data from the "Kaspersky Event Log" for example?

    ​​

    Since in the properties the name appears to be "Kaspersky Event Log" and the log file is "%SystemRoot% \ System32 \ Winevt \ Logs \ Kaspersky Event Log.evtx"
    I tried this but it doesn't work: eventlog [Kaspersky Event Log ,,,,,, skip]

    I believe the problem is the syntax of the name of the voice I want to log.

    Can you help me ?

    Thanks everyone!
  • cyber
    Senior Member
    Zabbix Certified SpecialistZabbix Certified Professional
    • Dec 2006
    • 4807

    #2
    If in doubt, quote it...
    eventlog ["Kaspersky Event Log" ,,,,,, skip]

    Comment

    • GlobalVision
      Junior Member
      • Feb 2022
      • 11

      #3
      Thank you Cyber for you reply !


      I tried but it still doesn't work. Other Ideas ?

      Comment

      • cyber
        Senior Member
        Zabbix Certified SpecialistZabbix Certified Professional
        • Dec 2006
        • 4807

        #4
        Do you get item created but nothing arrives or you have problem with creating an item?

        Comment

        • GlobalVision
          Junior Member
          • Feb 2022
          • 11

          #5
          This is my item

          Click image for larger version

Name:	Immagine 2022-02-16 124910.png
Views:	225
Size:	26.1 KB
ID:	439774


          But so far nothing has been received

          Comment

          • GlobalVision
            Junior Member
            • Feb 2022
            • 11

            #6
            I tried to delete and recreate it exactly as it was and now it works...
            I don't know why ?!?!


            1000 thanks for your help !!!

            Comment

            • GlobalVision
              Junior Member
              • Feb 2022
              • 11

              #7
              Sorry but after my last post I'm not receiving anything but in my PC's Event Log there are new records

              Nothing is changed and I can't understand why is not working again.

              What do you need to understand what I'm doing wrong ?

              Many thanks again

              Comment

              • guille.rodriguez
                Senior Member
                • Jun 2022
                • 114

                #8
                Check if Zabbix Agent is working on machine(agent service is running?), sometimes a few change in agent.conf may (some typo) makes service fail at start

                Check if firewall is allowing the trafic (tcp10050 from server to agent, tcp10051 from agent to server)
                Last edited by guille.rodriguez; 19-02-2023, 10:06.

                Comment

                Working...