{"id":19788339,"url":"https://github.com/graylog2/graylog-guide-windows-eventlog","last_synced_at":"2026-02-04T21:36:20.742Z","repository":{"id":137547666,"uuid":"47119317","full_name":"Graylog2/graylog-guide-windows-eventlog","owner":"Graylog2","description":"How to send Windows EventLogs into Graylog","archived":false,"fork":false,"pushed_at":"2019-03-28T17:06:01.000Z","size":6,"stargazers_count":19,"open_issues_count":0,"forks_count":6,"subscribers_count":10,"default_branch":"master","last_synced_at":"2025-07-20T16:27:46.616Z","etag":null,"topics":[],"latest_commit_sha":null,"homepage":null,"language":null,"has_issues":true,"has_wiki":null,"has_pages":null,"mirror_url":null,"source_name":null,"license":"apache-2.0","status":null,"scm":"git","pull_requests_enabled":true,"icon_url":"https://github.com/Graylog2.png","metadata":{"files":{"readme":"README.md","changelog":null,"contributing":null,"funding":null,"license":"LICENSE","code_of_conduct":null,"threat_model":null,"audit":null,"citation":null,"codeowners":null,"security":null,"support":null,"governance":null,"roadmap":null,"authors":null,"dei":null,"publiccode":null,"codemeta":null}},"created_at":"2015-11-30T13:13:09.000Z","updated_at":"2025-04-15T13:26:07.000Z","dependencies_parsed_at":null,"dependency_job_id":"000d3fc3-0ce2-44c8-a6cb-fda06e33cb45","html_url":"https://github.com/Graylog2/graylog-guide-windows-eventlog","commit_stats":null,"previous_names":[],"tags_count":0,"template":false,"template_full_name":null,"purl":"pkg:github/Graylog2/graylog-guide-windows-eventlog","repository_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/Graylog2%2Fgraylog-guide-windows-eventlog","tags_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/Graylog2%2Fgraylog-guide-windows-eventlog/tags","releases_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/Graylog2%2Fgraylog-guide-windows-eventlog/releases","manifests_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/Graylog2%2Fgraylog-guide-windows-eventlog/manifests","owner_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/owners/Graylog2","download_url":"https://codeload.github.com/Graylog2/graylog-guide-windows-eventlog/tar.gz/refs/heads/master","sbom_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/Graylog2%2Fgraylog-guide-windows-eventlog/sbom","scorecard":null,"host":{"name":"GitHub","url":"https://github.com","kind":"github","repositories_count":286080680,"owners_count":29096441,"icon_url":"https://github.com/github.png","version":null,"created_at":"2022-05-30T11:31:42.601Z","updated_at":"2026-02-04T21:05:08.033Z","status":"ssl_error","status_checked_at":"2026-02-04T21:04:53.031Z","response_time":62,"last_error":"SSL_read: unexpected eof while reading","robots_txt_status":"success","robots_txt_updated_at":"2025-07-24T06:49:26.215Z","robots_txt_url":"https://github.com/robots.txt","online":false,"can_crawl_api":true,"host_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub","repositories_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories","repository_names_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repository_names","owners_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/owners"}},"keywords":[],"created_at":"2024-11-12T06:26:55.947Z","updated_at":"2026-02-04T21:36:20.735Z","avatar_url":"https://github.com/Graylog2.png","language":null,"funding_links":[],"categories":[],"sub_categories":[],"readme":"# This guide has been archived.\n\nThe information in this guide is very old and likely no longer applicable to current versions of Graylog.\nPlease take that into account when reading the following content.\n\n## How to send Windows EventLogs into Graylog\n\nWindows cannot forward EventLog via the network to a central place like Graylog. You'll have to run an agent that can talk to Graylog. Good news is that there are two officially recommended agents:\n\n### Graylog Sidecar\n\nThe [Graylog Collector Sidecar](https://github.com/Graylog2/collector-sidecar) is a supervisor process for 3rd party log collectors like NXLog or beats. The Sidecar program is able to fetch configurations from a Graylog server and render them as a valid configuration file for various log collectors. You can think of it like a centralized configuration management system for your log collectors.\n\nPlease [read the official documentation](http://docs.graylog.org/en/latest/pages/sidecar.html) to learn how to use the Graylog Collector Sidecar.\n\n### nxlog\n\nThe [NXLog Community Edition](http://nxlog.org/products/nxlog-community-edition) is suitable to forward Windows EventLog to Graylog natively. Please refer to their official documentation for more information.\n\n### Graylog Collector (deprecated)\n\nThe Graylog Collector is a lightweight Java application that allows you to forward data from log files to a Graylog cluster. The collector can read local log files and also Windows Events natively, it then can forward the log messages over the network using the [GELF](https://www.graylog.org/resources/gelf/) format.\n\nPlease [read the official documentation](http://docs.graylog.org/en/latest/pages/collector.html#graylog-collector) to learn how to use the Graylog Collector to forward Windows EventLog.\n","project_url":"https://awesome.ecosyste.ms/api/v1/projects/github.com%2Fgraylog2%2Fgraylog-guide-windows-eventlog","html_url":"https://awesome.ecosyste.ms/projects/github.com%2Fgraylog2%2Fgraylog-guide-windows-eventlog","lists_url":"https://awesome.ecosyste.ms/api/v1/projects/github.com%2Fgraylog2%2Fgraylog-guide-windows-eventlog/lists"}