Home Linux & Systems Cybersecurity Cloud & DevOps Networks & Infrastructure SIEM & Monitoring DFIR & Threat Intel Development & Other All categories Projects About Tools

Installing and configuring RSYSLOG on Windows

Leer en espanol
Installing and configuring RSYSLOG on Windows

Table of contents

RSyslog allows you not only to configure the logs locally, where we will collect them and with what priority, but also to accept remote connections in order to receive logs from other computers and be able to centralize all these logging operations.

We access the website of RSYSLOG and we download the software:

http://www.rsyslog.com/windows-agent/windows-agent-download/

Once executed, the installation wizard opens.

Win graylog00001

We accept the license.

Win graylog00002

Following.

Win graylog00003

Following,

Win graylog00004

Following.

Win graylog00005

We proceed to install the software.

Win graylog00006 Win graylog00007

We finish the installation.

Win graylog00008

After completing the installation we access the directory C:\Program Files (x86)\RSyslog\Agent and we press on RSyslogConfigClient 

Win graylog00009

The configuration wizard opens: we go to:  Rule Sets > ForwardSyslog > Actions > RSyslog

In our case, we are going to use the RSYSLOG client for a graylog server, which we have configured for port 514 UDP:

Once everything is configured, press the save button and start the service.

800px Win graylog00010 1

All the best

:wq!

Comments