Solved

Event Log Full!

Posted on 2006-10-31
13
291 Views
Last Modified: 2012-06-27
Hi,

We have been told that we must capture all login information on all AD servers. To do this I increaseed the size of the log to 1.5GB and changed the overwrite option to overwrite anything that is older than 21 days.

The problem we have is that the event log gets to 380MB (or thereabouts) and says it is full. This happens on all servers.

The server OS is Windows 2003 SP1.

Any help will be much appreciated.

Thanks,

Jamie
0
Comment
Question by:neverfailit
  • 8
  • 5
13 Comments
 
LVL 51

Expert Comment

by:Netman66
ID: 17845951
0
 

Author Comment

by:neverfailit
ID: 17846115
Thanks for getting back to me.

The first article seems to be the probvlem that we are having. I have been in touch with Microsoft for the hotfix and they say that the hotfix is only available for W2K Servers.
0
 
LVL 51

Accepted Solution

by:
Netman66 earned 125 total points
ID: 17846171
Interesting...maybe they should change the "Applies To" section then!

Can you add any of those keys to the registry to see if the mechanism is already built in?

0
 
LVL 51

Expert Comment

by:Netman66
ID: 17846192
Have you attempted to Save the logs then clear them since you increased the size?  Article 2 discusses this.

0
 

Author Comment

by:neverfailit
ID: 17846208
I will try the reg keys option and let yuou know.

I have cleared the logs multiple times and nothing changes.

Thanks again,

Jamie
0
 

Author Comment

by:neverfailit
ID: 17846878
The registry change seems to have worked. The log file reached its limit of 385,152KB and the system then backed up the archive and cleared it out too. This is a good work around for me but it still doesn't explain why I have my max log file size set to 1,499,968KB and Windows decides to only let it reach 385,152KB. I suppose I could try and write a script that would delete any files that are over 21 days old so that we don't run out of disk space. I'll accept this answer so you can get the points but if you have any info why the log file will not reach my desired limit then please let me know.

Thanks again for your help,

Jamie
0
How your wiki can always stay up-to-date

Quip doubles as a “living” wiki and a project management tool that evolves with your organization. As you finish projects in Quip, the work remains, easily accessible to all team members, new and old.
- Increase transparency
- Onboard new hires faster
- Access from mobile/offline

 
LVL 51

Expert Comment

by:Netman66
ID: 17846921
I'm still investigating this.  I seem to recall a TechNet article, but it may only be Partner Level.  I'll let you know.

NM
0
 

Author Comment

by:neverfailit
ID: 17846929
Thanks.
0
 
LVL 51

Expert Comment

by:Netman66
ID: 17846976
It looks like the first article I posted is the one I was thinking of.

I found out that your size must be a multiple of 64:

"However, it must be a multiple of 64"

Taken directly out of this article:

http://www.microsoft.com/technet/security/topics/serversecurity/tcg/tcgch06n.mspx

Perhaps, it's just that simple??

Let me know.
0
 
LVL 51

Expert Comment

by:Netman66
ID: 17846988
or...

maybe there is a GPO that has been set somewhere that defines your upper limit to 385 MB.

You can run a GPRESULT on the server to see what policies are being applied to the Computer then open them in GPMC.msc to see what settings are configured.

0
 

Author Comment

by:neverfailit
ID: 17847001
I have specified the file size by GPO and it is set to 1,499,968KB. This is definitely being pushed out to all DCs. The file size is definitely a multiple of 64.

I think it is probably just a limitation due to the file being a memory mapped file. I'll work out a script and work around it.

Thanks again.
0
 
LVL 51

Expert Comment

by:Netman66
ID: 17847011
Sorry about the flurry of posts - I just read that link I sent you last.  It explains quite clearly what's going on.

All the processes of Services.exe (including evenlog.dll) cannot consume more memory than is physically available.  Therefore, your 3 logs set to 1.5GB assumes that at least 4.5GB of RAM be available just for them (not taking anything else that runs under Services.exe).

Apparently, you're lucky as MS confirms that all 3 logs should total no more than 300MB in practice.  So you hit 385 per log which tells me you have a fair bit of RAM in that server already.

0
 
LVL 51

Expert Comment

by:Netman66
ID: 17847023
I think you understand it correctly.  Actually, it's something I've touched on, but until now never fully researched.  This question should be a good resource for others.

Glad to help - and finally get some answers myself!

0

Featured Post

How your wiki can always stay up-to-date

Quip doubles as a “living” wiki and a project management tool that evolves with your organization. As you finish projects in Quip, the work remains, easily accessible to all team members, new and old.
- Increase transparency
- Onboard new hires faster
- Access from mobile/offline

Join & Write a Comment

Suggested Solutions

I guess it is not common knowledge to most Wintel engineers/administrators: If you have an SNMP-based monitoring system in your environment (and it's common to have SNMP or Syslog) it's reasonably easy to enable monitoring of the Windows Event logs,…
Recently, I had the need to build a standalone system to run a point-of-sale system. I’m running this on a low-voltage Atom processor, so I wanted a light-weight operating system, but still needed Windows. I chose to use Microsoft Windows Server 200…
This video discusses moving either the default database or any database to a new volume.
When you create an app prototype with Adobe XD, you can insert system screens -- sharing or Control Center, for example -- with just a few clicks. This video shows you how. You can take the full course on Experts Exchange at http://bit.ly/XDcourse.

757 members asked questions and received personalized solutions in the past 7 days.

Join the community of 500,000 technology professionals and ask your questions.

Join & Ask a Question

Need Help in Real-Time?

Connect with top rated Experts

21 Experts available now in Live!

Get 1:1 Help Now