Solved

How do I view older Windows Security Logs? Seems like the logs only show from 1/11/15, but I need to view logs before that date.

Posted on 2015-01-12
6
119 Views
Last Modified: 2015-01-20
How do I view older Windows Security Logs? Seems like the logs only show from 1/11/15, but I need to view logs before that date.
0
Comment
Question by:joukiejouk
[X]
Welcome to Experts Exchange

Add your voice to the tech community where 5M+ people just like you are talking about what matters.

  • Help others & share knowledge
  • Earn cash & points
  • Learn & ask questions
6 Comments
 
LVL 14

Accepted Solution

by:
dmwynne earned 300 total points
ID: 40545216
The logs may be set to be overwritten.

Open Event Viewer, go to one of the logs (application, security, system etc), right click, properties, what is the max log size and is it set to overwrite?
0
 

Author Comment

by:joukiejouk
ID: 40545234
Max size is 20 MB. It was set to overwrite. How can I restore any log prior to that date?
0
 
LVL 14

Expert Comment

by:dmwynne
ID: 40545314
You need to restore a backup otherwise I think you are out of luck.
0
Use Case: Protecting a Hybrid Cloud Infrastructure

Microsoft Azure is rapidly becoming the norm in dynamic IT environments. This document describes the challenges that organizations face when protecting data in a hybrid cloud IT environment and presents a use case to demonstrate how Acronis Backup protects all data.

 

Author Comment

by:joukiejouk
ID: 40545681
Thanks. I am trying to collect the log from a remote system to forward to my security team. What is the best approach to do this? Currently I am using event viewer MMC and connecting to the remote computer, and doing a saved log file as, but it is hosing my computer.
0
 
LVL 54

Assisted Solution

by:McKnife
McKnife earned 200 total points
ID: 40545700
You can copy the security logfile from C:\Windows\System32\winevt\Logs, the name is security.evtx.
0
 
LVL 3

Expert Comment

by:Bahloul
ID: 40545998
Hi,

 the default log size is 20 MB when the file getting full it removes from the old log so you must increase the log file size to gain more history but this wont fix your issue you may see the below log for log size recommendation :-

http://support.microsoft.com/kb/957662

Bahloul.
0

Featured Post

Industry Leaders: We Want Your Opinion!

We value your feedback.

Take our survey and automatically be enter to win anyone of the following:
Yeti Cooler, Amazon eGift Card, and Movie eGift Card!

Question has a verified solution.

If you are experiencing a similar issue, please ask a related question

SHARE your personal details only on a NEED to basis. Take CHARGE and SECURE your IDENTITY. How do I then PROTECT myself and stay in charge of my own Personal details (and) - MY own WAY...
OfficeMate Freezes on login or does not load after login credentials are input.
This video Micro Tutorial explains how to clone a hard drive using a commercial software product for Windows systems called Casper from Future Systems Solutions (FSS). Cloning makes an exact, complete copy of one hard disk drive (HDD) onto another d…
The Task Scheduler is a powerful tool that is built into Windows. It allows you to schedule tasks (actions) on a recurring basis, such as hourly, daily, weekly, monthly, at log on, at startup, on idle, etc. This video Micro Tutorial is a brief intro…

730 members asked questions and received personalized solutions in the past 7 days.

Join the community of 500,000 technology professionals and ask your questions.

Join & Ask a Question