Comodo Help
Find the desired product help
Xcitium NxSIEM

Xcitium NxSIEM

Admin Guide 1.4

English

Print Help Download Help
Customer Asset Management > Configuring Nxlog And Rsyslog Servers To Send Logs To NxSIEM Server
  • Introduction To Comodo NxSIEM
    • Logging-in To The Administrative Console
  • The Main Interface
  • The Dashboard
  • Customer Asset Management
    • Adding Customers
    • Adding Assets For Monitoring
      • Hard Assets
      • Soft Assets
    • Downloading And Installing The NxSIEM Agent On Endpoints
    • Configuring Nxlog And Rsyslog Servers To Send Logs To NxSIEM Server
    • Editing Customers
  • Log Collection Agents And Policies
    • Collection Agents
      • Downloading NxSIEM Windows And Linux Agents
      • Managing Agents
      • Agentless Log Collection
    • Log Collection Policies
      • Audit Events Policy
      • Flat File Policy
      • Remote Log Collection Policy
      • Syslog Policy
      • Configuring Log Collection Policies
  • Query Management
    • Configuring Event Queries
    • Configuring Custom Dashboards
  • Managing Rules
  • Incidents And Cases
    • Managing Incidents
    • Managing Cases
  • Live Lists
    • Managing Live Lists
    • Managing Live List Content
  • Managing Reports
  • Administration
    • Viewing Log Collection Summaries
    • Managing Users
    • Viewing License And Subscription Details And Configuring NxSIEM Platform URL
  • Appendix 1 – Field Groups And Event Items Description
  • Appendix 2 - Configuring Endpoints To Forward Logs To NxSIEM Server
  • About Comodo Security Solutions

Configuring Nxlog and Rsyslog Servers to Send Logs to NxSIEM Server


Comodo NxSIEM features agent-less log collection from Windows/Linux endpoints connected to customers' networks, through the use of Nxlog and Rsyslog utilities. This is useful for customers who do not wish to install agents on their endpoints. The NXLOG utility (Windows endpoints) and the RSYSLOG utility (Linux endpoints) need to be configured to send logs to the NxSIEM server.


Comodo NxSIEM provides ready-made configuration script files for each customers /network/zone which can be downloaded from the respective 'Customer Details' page. Once connected, the NxSIEM server will be able to receive and store logs from the customer's endpoints.


The following sections explain more about:

  • Configuring NXLOG Utility
  • Configuring RSYSLOG Utility

Configuring NXLOG Utility


Administrators can download a specific customer's NXLOG configuration file from the administrative console and use this to configure the NXLOG utilities installed on Windows endpoints connected to the customer's network.


To download the NXLOG Configuration File

  • Open the 'Asset Management' interface by clicking the 'Menu' button, then 'Assets' > 'Asset Management'.
  • Select the customer from the left hand side pane.

The 'Customer Details' pane will open at the right.

  • Click 'Manage' at the bottom left of the right pane and choose the 'Hard Assets' tab.
  • Choose the network/zone you wish to configure from the right hand side pane and click the button in the row of the network/zone.

The authentication token, the authentication key and the download buttons for the NXLOG and RSYSLOG configuration script files for the selected network/zone will be displayed at the bottom of the right pane.

  • Click the NXLOG Configuration File Download button as shown in the figure and save the file.





  • Replace the NXLOG configuration file at the location C:Program Files (x86)nxlogconfnxlog.conf in the endpoints with the downloaded configuration file.

All settings in the configuration file are pre-configured and will instruct the NXLOG utility to send logs to the NxSIEM server. The NxSIEM server will receive and store the logs under the respective customer/network for monitoring and incident reporting.

Configuring RSYSLOG Utility


Administrators can download a pre-configured RSYSLOG configuration script, generated specifically for each customer/network, from the administrative console. This script will configure RSYSLOG utilities installed on Linux endpoints in customer networks to send logs to the NxSIEM server.


To download the RSYSLOG Configuration File

  • Open the 'Asset Management' interface by clicking the 'Menu' button, then 'Assets' > 'Asset Management'.
  • Select a customer from the left hand pane.

The 'Customer Details' pane will open at the right.

  • Click 'Manage' at the bottom left of the right pane and choose the 'Hard Assets' tab.
  • Choose the network/zone whose endpoints are to be configured, from the right hand side pane and click the button in the row of the network/zone.

The authentication token, the authentication key and the download buttons for the NXLOG and RSYSLOG configuration script files for the selected network/zone will be displayed at the bottom of the right pane.

  • Click the RSYSLOG Configuration File Download button as shown below and save the file.



  • Run the script file on all required endpoints.
The script will configure the RSYSLOG utility to send logs to NxSIEM server. The NxSIEM server will receive and store the logs under the respective customer/network for monitoring and incident reporting.

Alternatively, you can download the script file for configuring the RSYSLOG utility from 'Agents' > 'Collection Agents' > 'Agentless Collection' interface, manually enter the parameters for the customer network to be monitored and run the script at the endpoints. Refer to the section Agentless Log Collection for more details.


Our Products
  • Free Antivirus
  • Free Internet Security
  • Website Malware Removal
  • Free Anti-Malware
  • Anti-Spam (Free Trial)
  • Windows Antivirus
  • Antivirus for Windows 7
  • Antivirus for Windows 8
  • Antivirus for Windows 10
  • Antivirus for MAC
  • Antivirus for Linux
  • Free Endpoint Security
  • Free ModSecurity
  • Free RMM
  • Free Website Malware Scanner
  • Free Device Manager for Android
  • Free Demo
  • Network Security
  • Endpoint Protection
  • Antivirus for Android
  • Comodo Antivirus
  • Wordpress Security
Cheap CDN
  • Bootstrap CDN
  • Semantic UI CDN
  • Jquery CDN
  • CDN Plans
  • CDN
  • Free CDN
Enterprise
  • Patch Management Software
  • Patch Manager
  • Service Desk
  • Website Down
  • Endpoint Protection Solutions
  • Website Security Check
  • Remote Monitoring and Management
  • Website Security
  • Device Manager
  • ITSM
  • CRM
  • MSP
  • Android Device Manager
  • MDR Services
  • Managed IT Support Services
  • Free EDR
Free SSL Certificate
Support Partners Terms and Conditions Privacy Policy

© Comodo Group, Inc. 2025. All rights reserved.