1. Type gpedit.msc in the Start Search box and hit Enter.
2. Click Continue when the UAC prompt appears.
3. Navigate to the following policy location:
Computer Configuration\Administrative Templates\Windows Components\Event Log Service
4. Look under Application, Security, Setup or System to configure settings for the log desired.
5. Enable the following policy setting:
Retain old events
If you enable this setting, any new events written to a log that is full are discarded instead of overwriting old events. As a result, if you want to consider using this setting you should also back up your event logs when they become full--this is covered in my next tip.
Mitch Tulloch, MVP