Installing & Configuring NXLog Agents: A Complete Guide to Service Setup
NXLog is a powerful log collection and processing tool that bridges the gap between raw event data and actionable insights. After exploring its evolution from open source to enterprise grade platform in the last blog, it’s time to dive deeper into installing and configuring NXLog agents the building blocks of a smart log pipeline.
1. Why NXLog Agents?
NXLog agents are lightweight, flexible and designed to work across diverse environments. Whether it’s Windows, Linux or Unix, these agents act as collectors and forwarders, ensuring logs flow securely and efficiently to your central hub.
Key benefits include:
📦 Cross-platform support (Windows, Linux, Unix, BSD)
🔐 Secure transport with TLS/SSL
⚡ Real-time log forwarding
🛠 Customizable processing with inputs, outputs and extensions
🔎 Compliance-ready logging for enterprise requirements
2. Pre-Requisites Before Installation
- Before setting up NXLog agents, ensure:
- Administrative privileges on target systems
- Correct binaries/packages for your OS
- Network connectivity to NXLog Manager/Server (if applicable)
- Firewall rules allowing communication between agent and server
3. Installing NXLog Agents
a) On Windows
- Download the Windows installer from the NXLog platform portal.

-
Run the installer with administrative rights.
-
Choose the installation path and components.

- Verify installation using:

Powershell Command :-
get-service nxlog

b) On Linux/Unix
- Verify OS distribution
Bash Command :-
cat /etc/os-release
- Download the correct package for your distribution.

3.Log in to the target server or machine and extract the contents of the archive (unless you are using the generic package):-
Bash Command :-
tar -xjf nxlog-<version>_<OS Variant>.tar.bz2

- Install using:
Bash Command :-
sudo rpm -ivh nxlog-6*.rpm # For RHEL

sudo dpkg -i nxlog-6*.deb # For Ubuntu/Debian

- Confirm installation with:
Bash Command :-
sudo systemctl status nxlog

4. Configuring NXLog Agents
NXLog’s power lies in its modular configuration system. The main configuration file is nxlog.conf.
- Nxlog.conf file of Windows:-

- Nxlog.conf file of Linux:-

This simple setup collects Windows Event Logs and forwards them to a central log server via TCP.
5. Running and Managing the Service
- Start service:
Bash Command :-
sudo systemctl start nxlog

- Enable on boot:
Bash Command :-
sudo systemctl enable nxlog

- View logs:
Bash Command :-
tail -f /var/log/nxlog/nxlog.log

On Windows:
Use services.msc to start/stop NXLog service.

Logs are typically stored in C:\Program Files\nxlog\data.
6. Testing the Setup
Verify agent is sending logs by checking NXLog Manager/Server.
Run test commands:
Bash Command :-
logger “NXLog test message”

Confirm logs appear in the central hub.
7. Best Practices
🔒 Always enable TLS/SSL for secure log transport.
📂 Use separate config files for inputs/outputs for better manageability.
⚙️ Monitor agent performance to avoid resource bottlenecks.
📊 Integrate with SIEM solutions for advanced threat detection.
Conclusion
NXLog agents are the cornerstone of efficient log collection. By installing and configuring them properly organizations can ensure a secure, reliable and scalable logging pipeline. Whether starting with the Community Edition or leveraging the full NXLog Platform, this setup empowers teams to transform log chaos into clarity.
👉 Stay tuned for the next blog, where we’ll explore advanced NXLog use…