您好,登錄后才能下訂單哦!
windows 2012
Evtsys_4.5.1_64-Bit-LP
1、下載軟件安裝包
下載地址: (科學上網,支持谷歌)
https://code.google.com/archive/p/eventlog-to-syslog/downloads
2、copy到windows制定目錄下:如 c:\ELK ,解壓軟件包
-->解壓生成64-BIT-LP文件夾,子文件
evtsys 運行程序
Readme.pdf 指導手冊
shasum 校驗
3、運行-->cmd-->執行查看命令
c:\ELK\64-Bit-LP>evtsys.exe ?
Version: 4.5.1 (64-bit)
Usage: evtsys.exe -i|-u|-d [-h host[;host2;...]] [-f facility] [-p port] [-t tag] [-s minutes] [-q bool] [-l level] [-n] [-a]
-i Install service ** 安裝服務**
-u Uninstall service **卸載服務**
-d Debug: run as console program
-a Use our IP address (or fqdn) in the syslog message
-h hosts Name of log host(s), separated by a **syslog服務器**
-f facility Facility level of syslog message
-l level Minimum level to send to syslog 0=All/Verbose, 1=Critical, 2=Error, 3=Warning, 4=Info **收集日志等級**
-n (**Win9x/Server 2003 Only**) Include only those events specifiedin the config file
-p port Port number of syslogd **服務器端口**
-q bool Query the Dhcp server to obtain the syslog/port to log to (0/1 = disable/enable)
-t tag Include tag as program field in syslog message
-s minutes Optional interval between status messages. 0 = Disabled
4、安裝evtsys.exe程序
cmd下執行:
c:\ELK\64-Bit-LP>evtsys.exe -i -h x.x.x.x -p 514 -l 1,2,3
Command completed successfully
a.默認的把該機器上所有的日志傳送到日志服務器
b.如果只指定日志類型 -l 1,2,3 0=All/Verbose, 1=Critical, 2=Error, 3=Warning, 4=Info 是全部 如果有多個 中間用逗號隔開
c.用下面指令 evtsys.exe -i -h 172.31.32.3 -p 514 -l 1,2,3
5、啟動evtsys服務
cmd下執行:
c:\ELK\64-Bit-LP>net start evtsys
Eventlog to Syslog 服務已經啟動成功。
注:運行--輸入services.msc --檢測Eventlog to Syslog是否自動啟動
6、卸載evtsys服務c:\ELK\64-Bit-LP>evtsys.exe -u -h x.x.x.x -p 514 -l 1,2,3
免責聲明:本站發布的內容(圖片、視頻和文字)以原創、轉載和分享為主,文章觀點不代表本網站立場,如果涉及侵權請聯系站長郵箱:is@yisu.com進行舉報,并提供相關證據,一經查實,將立刻刪除涉嫌侵權內容。