Syslog-ng WEC (WEC) logging facilities are configured in the wec.yaml file located by default at /opt/syslog-ng/etc/wec.yaml.
1. Set log 'level' to 'debug' and optionally add a log file.
log:
level: "debug"
file: "/opt/syslog-ng/var/wec.log" # optional
2. Restart WEC for taking place the change.
Systemd-based systems:
systemctl restart syslog-ng-wec
SysV-based systems:
/etc/init.d/syslog-ng-wec restart
dev:
devdebug: true
{"EventSource":"trainingdc.training.local","BookmarkListsIndex":{"36142154-A862-5DF6-BF9D-3D7DCB327936":{"Bookmarks":{"":{"Channel":"","RecordID":0},"Application":{"Channel":"Application","RecordID":513840183}},"Current":"Application"}}}
Applications and Services Logs\Microsoft\Windows\Eventlog-ForwardingPlugin
Applications and Services Logs\Microsoft\Windows\Windows Remote Management
eventcreate /T ERROR /ID 11 /L APPLICATION /D "This is an application error!"
eventcreate /T WARNING /ID 12 /L SYSTEM /D "This is just a warning in the system log"
© 2024 One Identity LLC. ALL RIGHTS RESERVED. Terms of Use Privacy Cookie Preference Center