Link to home
Create AccountLog in
Avatar of Pau Lo
Pau Lo

asked on

Event logs XP

I know the data in the local event logs on an XP machine are determined by the admin. But where on the machine can you see what has been setup in terms of events to be logged in the local event logs? Is there an area where admin can pcik and choose what events to log and how long to keep them for? Where on the XP machine can this be configured/seen?
ASKER CERTIFIED SOLUTION
Avatar of MFlaig
MFlaig
Flag of Germany image

Link to home
membership
Create an account to see this answer
Signing up is free. No credit card required.
Create Account
SOLUTION
Link to home
membership
Create an account to see this answer
Signing up is free. No credit card required.
Create Account
Avatar of Pau Lo
Pau Lo

ASKER

So by default all events are logged? I cant really see from that link where you can see which events are logged and which arent....
SOLUTION
Link to home
membership
Create an account to see this answer
Signing up is free. No credit card required.
Create Account
Avatar of Pau Lo

ASKER

>>You can configure size within the Properties for a particular log

But an admin cant say only add these events to the log, ignore these they arent of any use... i.e. you cant pick what events go in a log and which dont?
Avatar of Pau Lo

ASKER

>>in the event viewer, right click the event registry you wants to modify and then click properties.


Done that, and then what? I see 2 tabs, one general, one filter. Neither show for all the various events which are logged and which arent.
By default, you need to enable the auditing policies for your machine.

gpedit.msc -> Computer Configuration -> Windows Settings -> Security Settings -> Local Policies -> Audit Policy -> ...

Right click on each audit option and click Properties and then the Explain tab. You can read into full detail what each one does.
No, you can't configre that.
Applications and system objects should be free to log anything.
Avatar of Pau Lo

ASKER

Is there anywhere to see where the actual log file is on the PC, i.e. which folder? For example I have an event log category called "Pointsec", I would be interested to know where that and "application", "security" etc live.
I don't have an XP machine readily available but see if you have an option to create a custom view or filter in the right window pane.
Avatar of Pau Lo

ASKER

hmm cant anything along those lines...
Avatar of Pau Lo

ASKER

Ah in log name on the general tab it gives a path, but for some reason for the pointsec one it doesnt show where it lives...
Avatar of Pau Lo

ASKER

Its in the same folders where the password hash files are.