The Import Logs feature enables you to import the Evt / Evtx files. You can import the log file once or set a schedule with the share file path for a periodic event import (filetype .evtx format is supported in Windows Vista, 2008 and later). Once the event is imported, under the 'Reports' tab you can select a 'Custom Period' for the corresponding report and view audit reports for them. You can choose to archive the imported logs periodically by entering the number of days after which the archive should run.
To configure import logs
Imported Logs History
View the imported Evt / Evtx logs with duration details of logs data and current status. For an immediate import, click on Run now.
Archiving Imported logs
Here you can archive the imported logs periodically. To archive, enter the number of days after which the archive should run.
Restoring Archived Events
To restore archived data for a range:
Once the event data is restored from the archive folder to the working DB. Under the ´Reports´ tab select a ´Custom Period´ for the corresponding report and view audit reports for them.
Restored archive data older than 2 days (48 hours) in the database will be automatically re-archived.
|