Event log retention

by Mitch Tulloch [Published on 26 May 2006 / Last Updated on 26 May 2006]

How to configure event log retention in Windows Vista.

Windows Vista now lets you configure event logging settings more than ever before using Group Policy. One of the new settings you can configure is event log retention. By default, when an event log such as the Application log becomes full, oldest events are overwritten by newer ones. You can prevent this from happening by configuring local Group Policy as follows:

1. Type gpedit.msc in the Start Search box and hit Enter.

2. Click Continue when the UAC prompt appears.

3. Navigate to the following policy location:

Computer Configuration\Administrative Templates\Windows Components\Event Log Service

4. Look under Application, Security, Setup or System to configure settings for the log desired.

5. Enable the following policy setting:

Retain old events

If you enable this setting, any new events written to a log that is full are discarded instead of overwriting old events. As a result, if you want to consider using this setting you should also back up your event logs when they become full--this is covered in my next tip.

Mitch Tulloch, MVP

See Also

The Author — Mitch Tulloch

Mitch Tulloch is a well-known expert on Windows Server administration and cloud computing technologies. He has published over a thousand articles on information technology topics and has written, contributed to or been series editor for over 50 books.

Featured Links