Configuring event log settings

Event log size needs to be defined to prevent loss of audit data due to overwriting of events. 

  •  Open the GPMC and, based on your setup, right-click Default Domain Controllers Policy or ADAuditPlusMSPolicy or ADAuditPlusWSPolicy, then select Edit. 


 

To enable FIM onRight-click
Domain controllerDefault Domain Controllers Policy GPO
Windows serverADAuditPlusMSPolicy GPO
WorkstationADAuditPlusWSPolicy GPO


 

  • Navigate to Computer Configuration > Policies > Windows Settings > Security Settings > Event Log.
  • Set Retention method for security log to Overwrite events as needed.
  • Configure the Maximum security log size as defined below. Ensure that the security log can hold a minimum of 12 hours’ worth of data.


 

RoleOperating systemSize
Domain controller Windows Server 2003512 MB
Domain controller Windows Server 2008 and above1,024 MB
Member serverWindows Server 2003512 MB
Member serverWindows Server 2008 and above4,096 MB
WorkstationWindows 10, 8, 7, Vista, and XP512 MB


Configure security log size and retention settings

我们的客户