Solved

Event Log Full!

Posted on 2006-10-31
13
294 Views
Last Modified: 2012-06-27
Hi,

We have been told that we must capture all login information on all AD servers. To do this I increaseed the size of the log to 1.5GB and changed the overwrite option to overwrite anything that is older than 21 days.

The problem we have is that the event log gets to 380MB (or thereabouts) and says it is full. This happens on all servers.

The server OS is Windows 2003 SP1.

Any help will be much appreciated.

Thanks,

Jamie
0
Comment
Question by:neverfailit
  • 8
  • 5
13 Comments
 
LVL 51

Expert Comment

by:Netman66
ID: 17845951
0
 

Author Comment

by:neverfailit
ID: 17846115
Thanks for getting back to me.

The first article seems to be the probvlem that we are having. I have been in touch with Microsoft for the hotfix and they say that the hotfix is only available for W2K Servers.
0
 
LVL 51

Accepted Solution

by:
Netman66 earned 125 total points
ID: 17846171
Interesting...maybe they should change the "Applies To" section then!

Can you add any of those keys to the registry to see if the mechanism is already built in?

0
Enterprise Mobility and BYOD For Dummies

Like “For Dummies” books, you can read this in whatever order you choose and learn about mobility and BYOD; and how to put a competitive mobile infrastructure in place. Developed for SMBs and large enterprises alike, you will find helpful use cases, planning, and implementation.

 
LVL 51

Expert Comment

by:Netman66
ID: 17846192
Have you attempted to Save the logs then clear them since you increased the size?  Article 2 discusses this.

0
 

Author Comment

by:neverfailit
ID: 17846208
I will try the reg keys option and let yuou know.

I have cleared the logs multiple times and nothing changes.

Thanks again,

Jamie
0
 

Author Comment

by:neverfailit
ID: 17846878
The registry change seems to have worked. The log file reached its limit of 385,152KB and the system then backed up the archive and cleared it out too. This is a good work around for me but it still doesn't explain why I have my max log file size set to 1,499,968KB and Windows decides to only let it reach 385,152KB. I suppose I could try and write a script that would delete any files that are over 21 days old so that we don't run out of disk space. I'll accept this answer so you can get the points but if you have any info why the log file will not reach my desired limit then please let me know.

Thanks again for your help,

Jamie
0
 
LVL 51

Expert Comment

by:Netman66
ID: 17846921
I'm still investigating this.  I seem to recall a TechNet article, but it may only be Partner Level.  I'll let you know.

NM
0
 

Author Comment

by:neverfailit
ID: 17846929
Thanks.
0
 
LVL 51

Expert Comment

by:Netman66
ID: 17846976
It looks like the first article I posted is the one I was thinking of.

I found out that your size must be a multiple of 64:

"However, it must be a multiple of 64"

Taken directly out of this article:

http://www.microsoft.com/technet/security/topics/serversecurity/tcg/tcgch06n.mspx

Perhaps, it's just that simple??

Let me know.
0
 
LVL 51

Expert Comment

by:Netman66
ID: 17846988
or...

maybe there is a GPO that has been set somewhere that defines your upper limit to 385 MB.

You can run a GPRESULT on the server to see what policies are being applied to the Computer then open them in GPMC.msc to see what settings are configured.

0
 

Author Comment

by:neverfailit
ID: 17847001
I have specified the file size by GPO and it is set to 1,499,968KB. This is definitely being pushed out to all DCs. The file size is definitely a multiple of 64.

I think it is probably just a limitation due to the file being a memory mapped file. I'll work out a script and work around it.

Thanks again.
0
 
LVL 51

Expert Comment

by:Netman66
ID: 17847011
Sorry about the flurry of posts - I just read that link I sent you last.  It explains quite clearly what's going on.

All the processes of Services.exe (including evenlog.dll) cannot consume more memory than is physically available.  Therefore, your 3 logs set to 1.5GB assumes that at least 4.5GB of RAM be available just for them (not taking anything else that runs under Services.exe).

Apparently, you're lucky as MS confirms that all 3 logs should total no more than 300MB in practice.  So you hit 385 per log which tells me you have a fair bit of RAM in that server already.

0
 
LVL 51

Expert Comment

by:Netman66
ID: 17847023
I think you understand it correctly.  Actually, it's something I've touched on, but until now never fully researched.  This question should be a good resource for others.

Glad to help - and finally get some answers myself!

0

Featured Post

Three Reasons Why Backup is Strategic

Backup is strategic to your business because your data is strategic to your business. Without backup, your business will fail. This white paper explains why it is vital for you to design and immediately execute a backup strategy to protect 100 percent of your data.

Question has a verified solution.

If you are experiencing a similar issue, please ask a related question

The HP utility "HP Lights-Out Online Configuration Utility for Windows Server 2003/2008" could be of great use when it comes to remotely configure a HP servers ILO WITHOUT rebooting the server. We would only need to create and run scripts using thi…
On July 14th 2015, Windows Server 2003 will become End of Support, leaving hundreds of thousands of servers around the world that still run this 12 year old operating system vulnerable and potentially out of compliance in many organisations around t…
Microsoft Active Directory, the widely used IT infrastructure, is known for its high risk of credential theft. The best way to test your Active Directory’s vulnerabilities to pass-the-ticket, pass-the-hash, privilege escalation, and malware attacks …

789 members asked questions and received personalized solutions in the past 7 days.

Join the community of 500,000 technology professionals and ask your questions.

Join & Ask a Question