Can Ntbackup and 2008 backup, backup and restore windows event logs?

Hi,

Could someone show me official Microsoft documentation that shows whether or not Windows 2003 ntbackup (or 2008 backup) is able to backup and restore Windows event log files.

I know that if you try and backup the .evt files directly (C:\WINDOWS\system32\config) that ntbackup will silently skip out those files. By 'silently' I mean the backup will show as being 100% successful, and no event logs will be backed up, or reported as not being able to be backed up.

The contents of system state is described here:
http://technet.microsoft.com/en-us/library/cc785306%28WS.10%29.aspx

I have not investigated 2008 backup capabilities, but if you happen to know event log backup on 2008 that would be useful.

*Note* I know that there are WMI scripts to backup eventlogs. This is not what I am asking. I am asking whether the built in backup software can do it.

Thank you for your time.


LVL 3
harrowcAsked:
Who is Participating?
I wear a lot of hats...

"The solutions and answers provided on Experts Exchange have been extremely helpful to me over the last few years. I wear a lot of hats - Developer, Database Administrator, Help Desk, etc., so I know a lot of things but not a lot about one thing. Experts Exchange gives me answers from people who do know a lot about one thing, in a easy to use platform." -Todd S.

cj52973Commented:
That's expected behavior if you run the process with a non-administrative account.
To backup the EVT logs the user (or worker process) needs to have Admin rights to the machine.
0
harrowcAuthor Commented:
You are incorrect.
Even admins cannot backup these files.
Try it for yourself.

0
harrowcAuthor Commented:
To test the 2003 backup side of things I performed the following steps:

1. On 2003 DC, backed up system state using ntbackup.
2. Cleared event logs.
3. Rebooted into Active Directory Restore mode
4. Used ntbackup to restore the system state
5. Rebooted into normal mode
6. Event viewer showed no events older than when I cleared the event logs in step 2.

This practical experiment answers one of my questions:

Does 2003 system state backup, backup the Windows event logs?
Answer: No.

Does anyone know if 2008 is the same?

0

Experts Exchange Solution brought to you by

Your issues matter to us.

Facing a tech roadblock? Get the help and guidance you need from experienced professionals who care. Ask your question anytime, anywhere, with no hassle.

Start your 7-day free trial
It's more than this solution.Get answers and train to solve all your tech problems - anytime, anywhere.Try it for free Edge Out The Competitionfor your dream job with proven skills and certifications.Get started today Stand Outas the employee with proven skills.Start learning today for free Move Your Career Forwardwith certification training in the latest technologies.Start your trial today
Windows Server 2003

From novice to tech pro — start learning today.

Question has a verified solution.

Are you are experiencing a similar issue? Get a personalized answer when you ask a related question.

Have a better answer? Share it in a comment.