AlienVault® USM Anywhere™

Forward NXLog Messages Directly to the USM Anywhere Sensor

The simplest method to receive NXLog messages is to install NXLog Community Edition (CE) on each Windows host and configure it to forward messages to the USM Anywhere Sensor.

To install NXLog and create your configuration file

  1. Download the newest stable NXLog Community Edition.
  2. Make a backup copy of the original C:\Program Files (x86)\nxlog\conf\nxlog.conf file and give it another name.
  3. In the configuration file generator section of this page, select the plugins you are using, the protocol, and enter the IP address of your sensor.
  4. Click Create File to generate the new nxlog.config file and save it to C:\Program Files (x86)\nxlog\conf\nxlog.conf.
  5. Open Windows Services and restart the NXLog service.
  6. Open USM Anywhere and verify that you are receiving NXLog events.

Configuration File Generator

To generate your NXLog configuration file, select the additional plugins, if any, that will be collecting NXLogs, select the protocol, and enter your IP address.

Note: File paths in the nxlog.conf file are set to their default locations. If you have any custom file paths for your plugins, you can open the .conf file in a text editor and change the paths manually.


* Plugins with an asterisk require additional configuration, as detailed in the Enable Logging in Vendor Software section at the bottom of this page.


IP Address:

Manual File Creation

If you are unable to create the nxlog.conf file using the process above, or if you wish to edit it manually, you can use the manual process instead.

Enable Logging in Vendor Software

Some of the vendor plugins need to be configured to enable logging so that USM Anywhere can receive the logs. If you are using any of the plugins below, follow the described integration process to initiate system logging for the plugin.