Configuration#
Use this section to configure how rsyslog Windows Agent collects Windows events, processes them through rules, and forwards the results.
If you are new to the product, start with Getting Started for the first
working setup and return here for the detailed configuration pages.
In this manual, input is the clearest plain-language concept for anything that collects or receives events, while service remains the operational term for the configured rsyslog Windows Agent object.
Recommended setup path#
Define input services under Services and bind each service to a ruleset.
Build processing under Filter Conditions.
Add forwarding or internal processing under Actions.
Verify end-to-end delivery with a simple forwarding action before refining the filters.