Member_2_6490404
asked on
Move Event Log in windows 2012
Ultimately I'm trying to have security logs written to a remote storage,
(\\<Server-Name>\<Drive-Le tter>\<Fil e_Name>).
For testing I'm trying to move the default log path from
%SystemRoot%\System32\Wine vt\Logs\Se curity.evt x to
C:\Security.evtx This however is failing. no errors in logs. I double checked the registry at HKEY_LOCAL_MACHINE\SYSTEM\ CurrentCon trolSet\Se rvices\Eve ntLog\Secu rity and the "File" Does point to C:\Security.evtx however logs are still written in the default %SystemRoot%\System32\Wine vt\Logs\Se curity.evt x. I double checked an no group policy is in place for this. Any suggestions on how to do this? I'm aware of wevtutil however I'd like to accomplish this using Event Viewer.
(\\<Server-Name>\<Drive-Le
For testing I'm trying to move the default log path from
%SystemRoot%\System32\Wine
C:\Security.evtx This however is failing. no errors in logs. I double checked the registry at HKEY_LOCAL_MACHINE\SYSTEM\
Create a robocopy script to export the event log to your folder, create a scheduled task to run the script weekly. I've used this method to ensure storage of 12 months logs
ASKER
Thanks. I was curious how to do this with windows native tools...within the eventvwr settings. The options to do so are there but I can't seem to get them to work. Wevtutil works great as well.
ASKER CERTIFIED SOLUTION
membership
This solution is only available to members.
To access this solution, you must be a member of Experts Exchange.