THE SAFEHOUSE / JOURNAL

Installing & Configuring NXLog Agents: A Complete Guide to Service Setup

17 February 2026· 3 min read

Installing & Configuring NXLog Agents: A Complete Guide to Service Setup

NXLog is a powerful log collection and processing tool that bridges the gap between raw event data and actionable insights. After exploring its evolution from open source to enterprise grade platform in the last blog, it’s time to dive deeper into installing and configuring NXLog agents the building blocks of a smart log pipeline.

1. Why NXLog Agents?

NXLog agents are lightweight, flexible and designed to work across diverse environments. Whether it’s Windows, Linux or Unix, these agents act as collectors and forwarders, ensuring logs flow securely and efficiently to your central hub.

Key benefits include:

📦 Cross-platform support (Windows, Linux, Unix, BSD)

🔐 Secure transport with TLS/SSL

⚡ Real-time log forwarding

🛠 Customizable processing with inputs, outputs and extensions

🔎 Compliance-ready logging for enterprise requirements

2. Pre-Requisites Before Installation

3. Installing NXLog Agents

a) On Windows

  1. Download the Windows installer from the NXLog platform portal.

Platform View for package Download Download Location in Windows

  1. Run the installer with administrative rights.

  2. Choose the installation path and components.

Installation Path

  1. Verify installation using:

Verification Step

Powershell Command :-

get-service nxlog

Mentioned Command Output

b) On Linux/Unix

  1. Verify OS distribution

Bash Command :-

cat /etc/os-release

  1. Download the correct package for your distribution.

Debian Product Download Action RHEL Product Download Action Ubuntu Product Download Action

3.Log in to the target server or machine and extract the contents of the archive (unless you are using the generic package):-

Bash Command :-

tar -xjf nxlog-<version>_<OS Variant>.tar.bz2

Mentioned Command Output

  1. Install using:

Bash Command :-

sudo rpm -ivh nxlog-6*.rpm # For RHEL

Mentioned Command Output

sudo dpkg -i nxlog-6*.deb # For Ubuntu/Debian

Mentioned Command Output

  1. Confirm installation with:

Bash Command :-

sudo systemctl status nxlog

Mentioned Command Output

4. Configuring NXLog Agents

NXLog’s power lies in its modular configuration system. The main configuration file is nxlog.conf.

.Conf File View

.conf File View

This simple setup collects Windows Event Logs and forwards them to a central log server via TCP.

5. Running and Managing the Service

Bash Command :-

sudo systemctl start nxlog

Mentioned Command Output

Bash Command :-

sudo systemctl enable nxlog

Mentioned Command Output

Bash Command :-

tail -f /var/log/nxlog/nxlog.log

Mentioned Command Output

On Windows:

Use services.msc to start/stop NXLog service.

RUN Program Output Services Details form Windows

Logs are typically stored in C:\Program Files\nxlog\data.

6. Testing the Setup

Verify agent is sending logs by checking NXLog Manager/Server.

Run test commands:

Bash Command :-

logger “NXLog test message”

Mentioned Command Output

Confirm logs appear in the central hub.

7. Best Practices

🔒 Always enable TLS/SSL for secure log transport.

📂 Use separate config files for inputs/outputs for better manageability.

⚙️ Monitor agent performance to avoid resource bottlenecks.

📊 Integrate with SIEM solutions for advanced threat detection.

Conclusion

NXLog agents are the cornerstone of efficient log collection. By installing and configuring them properly organizations can ensure a secure, reliable and scalable logging pipeline. Whether starting with the Community Edition or leveraging the full NXLog Platform, this setup empowers teams to transform log chaos into clarity.

👉 Stay tuned for the next blog, where we’ll explore advanced NXLog use…

Related reading