You are on page 1of 5

Adjusting Event Log Size and Retention Settings https://helpcenter.netwrix.com/Configure_IT_Infrastructure/Windows_S...

1 of 5 03/Jun/2020, 9:46 PM
Adjusting Event Log Size and Retention Settings https://helpcenter.netwrix.com/Configure_IT_Infrastructure/Windows_S...

Adjusting Event Log Size and Retention


Settings

NOTE:

Manually
To configure the event log size and retention method

Start → Windows Administrative Tools Administrative


Tools → Event Viewer

Event Viewer tree → Windows Logs Security Properties

2 of 5 03/Jun/2020, 9:46 PM
Adjusting Event Log Size and Retention Settings https://helpcenter.netwrix.com/Configure_IT_Infrastructure/Windows_S...

Enable logging

Maximum log size

Do not overwrite events (Clear logs manually)


Overwrite events as needed (oldest events first)

NOTE: Maximum security log size


Group Policy Management
Computer Configuration → Policies → Windows Settings → Security Settings → Event Log

Windows Logs → Application

Windows Logs → System

Applications and Services Logs → Microsoft → Windows → TaskScheduler → Operational

NOTE:

Applications and Services Logs → Microsoft → Windows → DNS-Server → Audit

NOTE:

3 of 5 03/Jun/2020, 9:46 PM
Adjusting Event Log Size and Retention Settings https://helpcenter.netwrix.com/Configure_IT_Infrastructure/Windows_S...

Applications and Services Logs → AD FS →Admin

NOTE:

Using Group Policy

To configure settings for Application, System and Security event logs

Computer Configuration →
Policies → Administrative Templates → Windows Components → Event Log Service

Specify the maximum log file size

Overwrite as needed

To configure settings for other logs

HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\EventLog
\<log_name> HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\EventLog\Directory
Service

MaxSize

Computer → Preferences →
Windows Settings → Registry

Registry New → Registry Item

Properties General

4 of 5 03/Jun/2020, 9:46 PM
Adjusting Event Log Size and Retention Settings https://helpcenter.netwrix.com/Configure_IT_Infrastructure/Windows_S...

Action → Create

Hive → HKEY_LOCAL_MACHINE

Key Path MaxSize SYSTEM\CurrentControlSet\Services\EventLog\Directory


Service

MaxSize REG_DWORD

gpupdate /force

5 of 5 03/Jun/2020, 9:46 PM

You might also like