Solved

Security Event Log Size 2012 R2

Posted on 2016-11-02
4
28 Views
Last Modified: 2016-11-21
There is conflicting information regarding the size of the security event log. Some articles mention that the file is always loaded into memory in full, others say that the way the event log is loaded into memory has changed and that setting a larger size is no longer an issue.

Let's say, that for example I have a 4GB event log, will the full file be loaded into RAM? OS version is Windows Server 2012 R2.
0
Comment
Question by:albatros99
[X]
Welcome to Experts Exchange

Add your voice to the tech community where 5M+ people just like you are talking about what matters.

  • Help others & share knowledge
  • Earn cash & points
  • Learn & ask questions
  • 2
  • 2
4 Comments
 
LVL 55

Assisted Solution

by:McKnife
McKnife earned 500 total points
ID: 41871159
I would simply make a test to find out. Use a script that uses eventcreate.exe in a loop to fill up the log and at the same time, open task manager and watch your RAM consumption.
0
 
LVL 3

Accepted Solution

by:
albatros99 earned 0 total points
ID: 41872420
A 3.2 GB security log shows up in RamMap with 842'542 KB Total and 593'240 KB standby. Clearly it uses more memory but it doesn't load the whole file. I was just hoping this new behaviour would be documented somewhere.
0
 
LVL 55

Expert Comment

by:McKnife
ID: 41872433
Hm - when does it show up, right after a restart or after it has been loaded to memory after using eventvwr?
0
 
LVL 3

Author Closing Comment

by:albatros99
ID: 41895646
Solution discovered by testing.
0

Featured Post

Is your NGFW recommended by NSS Labs?

Ours is! NSS Labs Next Generation Firewall Test gives the WatchGuard Firebox M4600 a "Recommended" rating! Curious where your NGFW landed on the  Security Value Map? See the map and download the full report today!

Question has a verified solution.

If you are experiencing a similar issue, please ask a related question

In this blog we highlight approaches to managed security as a service.  We also look into ConnectWise’s value in aiding MSPs’ security management and indicate why critical alerting is a necessary integration.
Make the most of your online learning experience.
In this Micro Tutorial viewers will learn how to use Boot Corrector from Paragon Rescue Kit Free to identify and fix the boot problems of Windows 7/8/2012R2 etc. As an example is used Windows 2012R2 which lost its active partition flag (often happen…
The Email Laundry PDF encryption service allows companies to send confidential encrypted  emails to anybody. The PDF document can also contain attachments that are embedded in the encrypted PDF. The password is randomly generated by The Email Laundr…

688 members asked questions and received personalized solutions in the past 7 days.

Join the community of 500,000 technology professionals and ask your questions.

Join & Ask a Question