Configuring Security Event Log Size and Retention Settings


Security event log size and retention settings can be configured in each computer or configured via a GPO to all target computers.

Local Configuration

  1. Open Run (Start -> Run), type eventvwr.msc
  2. Right click "Security" log(Event Viewer -> Windows Logs -> Security log) and select "Properties"
  3. Configure "Maximum log size" as defined below in the table
  4. Configure "When maximum event log size is reached" retention method for security log to “Overwrite Events As Needed”
GPO Configuration
  1. Open GPMC
  2. Edit the corresponding GPO (FIM on DomainControllers, FIM on Member Servers)
  3. Navigate to Computer Configuration → Policies →  Windows Settings → Security Settings →  Event Log
  4. Configure "Maximum security log" size as defined below
  5. Configure "Retention method for security log" to “Overwrite Events As Needed”
Recommended Security Log Size

Role
OS of the target computer
Log size(MB)
Domain Controller
Windows Server 2003
307
Domain Controller
Windows Server 2008 and above
1048
File Server
Windows Server 2003
307
File Server
Windows Server 2008 and above
4194
Member Server
Windows Server 2003
307
Member Server
Windows Server 2008 and above
1048
Workstation
Window XP
307
Workstation
Windows Vista and above
1048

Note: Ensure security event log holds minimum of 12hrs of data.
Copyright © 2019, ZOHO Corp. All Rights Reserved.
ManageEngine
Get download link