Windows NPS + NXlog to Palo Alto User-ID

[et_pb_section admin_label=”section”] [et_pb_row admin_label=”row”] [et_pb_column type=”4_4″][et_pb_text admin_label=”Text”]NXlog configuration file Configure Palo Alto to accept User-ID Syslog Device -> Setup -> Interfaces -> Management or if you have network profile Network -> Interface Mgmt. Add syslog filter profile. Device -> User identification -> Click gear on the right side of “Palo Alto Networks User-ID Agent Setup” … [Read more…]

Windows NPS + NXlog to Graylog

Saving Windows NPS logs to any folder Downloading NXlog Community Edition from here¬†https://nxlog.co/products/nxlog-community-edition/download Changing NXlog config file at C:\Program Files (x86)\nxlog\conf\nslog.conf #NoFreeOnExit TRUE define ROOT C:\Program Files (x86)\nxlog define CERTDIR %ROOT%\\cert define CONFDIR %ROOT%\\conf define LOGDIR %ROOT%\\data define LOGFILE %ROOT%\\logs\\nxlog.log LogFile %LOGFILE% Moduledir %ROOT%\\modules CacheDir %ROOT%\\data Pidfile %ROOT%\\data\nxlog.pid SpoolDir %ROOT%\\data <Extension _fileop> Module xm_fileop # … [Read more…]

Windows connectivity check script

Wrote really simple¬†Windows CMD script that checks connectivity to any server or Internet. Change “google.com” to your application IP address or domain name. @ECHO OFF ECHO Checking connection to the application… SET Connected=false FOR /F “usebackq tokens=1” %%A IN (`PING google.com`) DO ( REM Check the current line for the indication of a successful connection. … [Read more…]