Monitoring Windows Event Logs With NagEventLog
Monitoring Windows Event Logs With NagEventLog
Monitoring Windows Event Logs With NagEventLog
With NagEventLog
The Industry Standard in IT Infrastructure Monitoring
Purpose
This document describes how to monitor Windows event logs using Nagios XI and the NagEventLog addon.
Target Audience
This document is intended for use by Nagios XI Administrators.
Prerequisites
You must have completed the following steps before you can monitor Windows event logs using this documentation:
Configure NSCA on the Nagios XI Server
You must have configured the NSCA agent on your Nagios XI server in order to monitor Windows event logs with NagEventLog.
Instructions for configuring NSCA can be found in a separate document titled Using NSCA With XI. This document can be found on
the Nagios Library (http://library.nagios.com) or can be downloaded directly at:
http://assets.nagios.com/downloads/nagiosxi/docs/Using_NSCA_With_XI.pdf
Install the Windows Event Log Monitoring Wizard
You must install the Windows Event Log Monitoring Wizard on your Nagios XI server. The wizard can be downloaded from:
http://assets.nagios.com/downloads/nagiosxi/wizards/windowseventlog.zip
Overview
In order to monitor Windows event logs using Nagios XI and the NagEventLog agent, you must complete the following:
1.
2.
3.
The following pages will take you through each of these steps.
US: 1-888-NAGIOS-1
Int'l: +1 651-204-9102
Fax: +1 651-204-9103
Web: www.nagios.com
Email: sales@nagios.com
Page 1
Copyright 2011 Nagios Enterprises, LLC
Revision 1.0 August, 2013
Read the program and license information and click Next to continue.
When prompted for the installation directory, click Next to accept the default
and continue.
US: 1-888-NAGIOS-1
Int'l: +1 651-204-9102
Fax: +1 651-204-9103
Web: www.nagios.com
Email: sales@nagios.com
Page 2
Copyright 2011 Nagios Enterprises, LLC
Revision 1.0 August, 2013
When prompted for the start menu folder name, click Next to accept the default
and continue.
The host name (as currently defined, or as you will define it in Nagios
XI) for the Windows machine you are installing the agent on in the
Host name for this computer field.
2.
3.
4.
The password that you have configured NSCA to use on the Nagios
XI server in the Nagios NSCA Server password field.
US: 1-888-NAGIOS-1
Int'l: +1 651-204-9102
Fax: +1 651-204-9103
Web: www.nagios.com
Email: sales@nagios.com
Page 3
Copyright 2011 Nagios Enterprises, LLC
Revision 1.0 August, 2013
US: 1-888-NAGIOS-1
Int'l: +1 651-204-9102
Fax: +1 651-204-9103
Web: www.nagios.com
Email: sales@nagios.com
Page 4
Copyright 2011 Nagios Enterprises, LLC
Revision 1.0 August, 2013
The NSCA Server Settings screen will appear. Make sure you selected the
same encryption method in the Encryption option as what is used to decrypt
data in the NSCA configuration on the Nagios XI server.
Important: If the NSCA password and/or encryption method do not match the
settings used by the NSCA agent on the Nagios XI server, event log monitoring
will not work!
Click OK to continue.
US: 1-888-NAGIOS-1
Int'l: +1 651-204-9102
Fax: +1 651-204-9103
Web: www.nagios.com
Email: sales@nagios.com
Page 5
Copyright 2011 Nagios Enterprises, LLC
Revision 1.0 August, 2013
Important: If you changed NSCA settings, you will have to restart the
NagiosEventLog service on the Windows machine.
You can do this by using the Computer Management console, or by issuing the
following commands from a command prompt:
net stop NagiosEventLog
net start NagiosEventLog
US: 1-888-NAGIOS-1
Int'l: +1 651-204-9102
Fax: +1 651-204-9103
Web: www.nagios.com
Email: sales@nagios.com
Page 6
Copyright 2011 Nagios Enterprises, LLC
Revision 1.0 August, 2013
2.
3. The service name (as defined in Nagios XI) that alerts for the filter will
be associated with.
The Host Name you specify in the wizard matches the Host Name you
specified in the NSCA Server Settings screen of the NagEventLog
agent.
2.
The Event Log Service Names you specify in the wizard match the
Service Names you specified when defining filters in the NagEventLog
agent.
US: 1-888-NAGIOS-1
Int'l: +1 651-204-9102
Fax: +1 651-204-9103
Web: www.nagios.com
Email: sales@nagios.com
Page 7
Copyright 2011 Nagios Enterprises, LLC
Revision 1.0 August, 2013
US: 1-888-NAGIOS-1
Int'l: +1 651-204-9102
Fax: +1 651-204-9103
Web: www.nagios.com
Email: sales@nagios.com
Page 8
Copyright 2011 Nagios Enterprises, LLC
Revision 1.0 August, 2013