Ad Widget

Collapse

Windows Event Logs

Collapse
X
 
  • Time
  • Show
Clear All
new posts
  • JonathanKreis
    Junior Member
    • Jun 2023
    • 3

    #1

    Windows Event Logs

    Hello guys,

    I have tried to integrate Windows Events into Zabbix and tried a lot of instructions. Unfortunately it still does not work. I send you my attempt. Maybe you will find the error.
    I create an advanced item. The item reads the Windows event logs and looks for a specific windows event ID 4625 which is also known as 'failed logon'.

    The item type is: Zabbix Agent (Active)
    The key is: eventlog[Security,,,,4625,,skip]
    The type of information is: Log
    The duration to keep the data and the frequency of checking for the item is: 1 minute.

    I then tried to log on to my Windows laptop and generate some failed logins.
    Thank you very much for your help!​
  • alizy76
    Junior Member
    • Aug 2023
    • 3

    #2
    Originally posted by JonathanKreis
    Hello guys,

    I have tried to integrate Windows Events into Zabbix and tried a lot of instructions. Unfortunately it still does not work. I send you my attempt. Maybe you will find the error.
    I create an advanced item. The item reads the Windows event logs and looks for a specific windows event ID 4625 which is also known as 'failed logon'.

    The item type is: Zabbix Agent (Active)
    The key is: eventlog[Security,,,,4625,,skip]
    The type of information is: Log
    The duration to keep the data and the frequency of checking for the item is: 1 minute.

    I then tried to log on to my Windows laptop and generate some failed logins.
    Thank you very much for your help!​
    Hello,

    Thank you for providing the details of your integration attempt. It seems like you're on the right track with creating an advanced item to read Windows event logs for specific event IDs.

    However, there might be a small issue with your item key. The correct syntax for the item key should be:
    phpCopy code
    eventlog[<Log Name>,<Search String>,<Event Type>,<Event ID>,<Source>,<Severity>]
    In your case, for failed logons with event ID 4625 in the Security log, the item key should be:
    cssCopy code
    eventlog[Security,,,,4625,]
    Please make sure you have the correct log name (in this case, "Security") and event ID (4625). Also, ensure that the Zabbix agent is running on the target Windows machine and that the Zabbix server can communicate with the agent.

    If you've already corrected the item key and are still experiencing issues, you might want to check the Zabbix agent logs and the Windows Event Viewer for any error messages that could provide more insight into the problem.

    I hope this helps resolve the issue. Feel free to reach out if you have any further questions or need additional assistance.

    Comment

    • cyber
      Senior Member
      Zabbix Certified SpecialistZabbix Certified Professional
      • Dec 2006
      • 4807

      #3
      Don't give false advice.. it is
      Code:
      eventlog[name,<regexp>,<severity>,<source>,<eventid>,<maxlines>,<mode>]
      and topic starter has everything correctly.

      Comment

      • JonathanKreis
        Junior Member
        • Jun 2023
        • 3

        #4
        Thank you very much for your help. I will try it!!!

        Comment

        • vijayk
          Senior Member
          • May 2023
          • 305

          #5
          Originally posted by JonathanKreis
          Hello guys,

          I have tried to integrate Windows Events into Zabbix and tried a lot of instructions. Unfortunately it still does not work. I send you my attempt. Maybe you will find the error.
          I create an advanced item. The item reads the Windows event logs and looks for a specific windows event ID 4625 which is also known as 'failed logon'.

          The item type is: Zabbix Agent (Active)
          The key is: eventlog[Security,,,,4625,,skip]
          The type of information is: Log
          The duration to keep the data and the frequency of checking for the item is: 1 minute.

          I then tried to log on to my Windows laptop and generate some failed logins.
          Thank you very much for your help!​
          Hi,

          Below is my Item created and its working fine. Make sure you have entered the ServerActive=Zabbix_Server_IP in zabbix_agentd.config file in Agent System.

          Click image for larger version

Name:	image.png
Views:	5253
Size:	29.2 KB
ID:	469200

          Comment


          • JonathanKreis
            JonathanKreis commented
            Editing a comment
            I have tried what you said to me. Thank you very much. Sadly it still doesn't work. I will send you the following picture. Maybe you see my error:
        • JonathanKreis
          Junior Member
          • Jun 2023
          • 3

          #6
          Click image for larger version

Name:	MicrosoftTeams-image.png
Views:	5178
Size:	185.7 KB
ID:	469237 Maybe you can find the error
          Last edited by JonathanKreis; 22-08-2023, 15:31.

          Comment

          • vijayk
            Senior Member
            • May 2023
            • 305

            #7
            Which version do you have? Is 192.168.0.137 your Zabbix Server IP?

            Comment


            • JonathanKreis
              JonathanKreis commented
              Editing a comment
              Yes, 192.168.0.137 is my zabbix server IP.
              I have installed this to versions of zabbix agents on different hosts: 6.0.1.2400 and 6.4.0.2400
          • cyber
            Senior Member
            Zabbix Certified SpecialistZabbix Certified Professional
            • Dec 2006
            • 4807

            #8
            Is that pic from agent config on that windows host? Why does it have "Hostname=Zabbix server" there? Change to correct hostname. And hopefully you have that host defined properly in Zabbix also...

            Comment

            Working...