Configure event log settings in your domain
Event log size needs to be defined to prevent loss of audit data due to overwriting of events. To configure event log size and retention settings, follow the steps outlined below:
- Log in to any computer that has the GPMC with Domain Admin credentials. Open the GPMC, right-click ADAuditPlusMSPolicy, then select Edit.
- In the Group Policy Management Editor, select Computer Configuration → Policies → Windows Settings → Security Settings → Event Log.
- Navigate to the right pane and right-click on Retention method for security log. Select Properties → Overwrite events as needed.
- Navigate to the right pane, then right-click Maximum security log size and define the size as directed in the table below.
Role |
Operating System |
Size |
Windows server |
Windows Server 2003 |
512MB |
Windows server |
Windows Server 2008 and above |
4,096MB |
Don't see what you're looking for?
-
Visit our community
Post your questions in the forum.
-
Request additional resources
Send us your requirements.
-
Need implementation assistance?
Try onboarding