Integrations - Logpoint Agent (Standalone)
6.7.9957 (latest)
Integrations - Logpoint Agent (Standalone)
Version:
6.7.9957 (latest)
×
Page Contents
Table of Content
Table of Content
¶
Logpoint Agent (Standalone)
Choosing the Right Agent
Logpoint Agent (Standalone)
Logpoint Agent (Centralized)
AgentX
Getting Help
Getting Started
Installation Location
Configuration File Location
Agent Log Location
Initial Configuration Requirements
Starting the Agent
Install and Deploy
Method 1: Interactive Installation
Method 2: Unattended Installation with msiexec
Method 3: Group Policy Deployment
Supported Modules
1. Extension Modules (xm_*)
2. Input Modules (im_*)
3. Output Modules (om_*)
4. Processor Modules (pm_*)
Configure
Configuration Options
Simple Configuration
Overview
Simple Configuration Setup
Advanced Configuration
Overview
Advanced Configuration Setup
Selecting a Specific Event ID
Debugging Configuration
Simple Configuration File
Advanced Configuration File
Collect Data
Windows Event Log Collection
What’s Collected
What You’ll See
Noise Reduction (Advanced Configuration Only)
Configuration Parameters
DHCP Log Collection
Prerequisites
What’s Collected
Parsed Fields
What You’ll See
When to Use This
DNS Debug Log Collection
Prerequisites
What’s Collected
Data Validation
What You’ll See
When to Use This
Registry Monitoring (File Integrity Monitoring)
What’s Monitored
Registry Areas Monitored
Work with Collected Data
Understanding Normalization Tags
Searching in Logpoint
Finding Windows Events
Finding Specific Event IDs
Finding Registry Changes
Finding DHCP Events
Finding DNS Events
Data Format
Windows Event Logs
DHCP Logs
DNS Logs
Registry Events
Monitoring and Troubleshooting
Checking Agent Health
View Agent Logs
Check Agent Service Status
Verify Agent is Running
Verifying Data Flow
On the Agent (Windows)
Using Local File Output for Testing
On Logpoint Server (Linux)
In Logpoint SIEM
Common Issues and Solutions
No Data Appearing in Logpoint
Configuration File Syntax Errors
Registry Access Denied Errors
Agent Log Growing Too Large
Registry Events Not Appearing
DNS Logs Not Collecting
DHCP Logs Not Collecting
Adjusting Log Levels
Changing to DEBUG (for troubleshooting)
Restart After Changes
Performance Monitoring
Check Agent Resource Usage
Monitor Log File Size
Best Practices
Configuration Selection
Use Simple Configuration when:
Use Advanced Configuration when:
Deployment Strategy
Security Considerations
Performance Optimization
Customization Guidelines
Adding Event ID Filters
Adding Registry Paths
Adding Registry Exclusions
Maintenance
Troubleshooting Workflow
Quick References
Service Commands
File Locations
Network Requirements
Configuration Templates
Simple Configuration
Advanced Configuration
Data Verification Searches
Key Configuration Parameters
Additional Resources
NXLog Documentation
Common Configuration Patterns
Helpful?
Yes
No
We are glad this guide helped.
Please don't include any personal information in your comment
Contact Support
×
Navigation
next
Logpoint Agent (Standalone) latest documentation
»