Configure Event Log Settings for Auditing

 

Event Log Setting Required for Workstations Auditing:

 

To audit Workstations: Use the Group Policy snap-in to configure "Event Log Settings" in the Group Policy object.

 

Configuring Event Log Settings for Auditing

  1. Log on to Windows with an account that has Administrator rights.

  2. Ensure that the Group Policy snap-in is installed.

  3. Open the GPMC (Group Policy Management Console).

  4. Edit the GPO that is applied on all selected Workstations (How to select Workstations) that require audit reporting.

  5. Click on the "Group Policy Object" and click on "Edit"

  6. This will direct you to "Group Policy Management Editor"

1. "Computer Configuration -> Windows Settings -> Security Settings -> Event Log-> Retention method for security log ->Overwrite events as needed"

2. "Computer Configuration -> Windows Settings -> Security Settings -> Event Log-> Maximum Security Log Size -> 256MB"

 
Copyright © 2020, ZOHO Corp. All Rights Reserved.
ManageEngine
Get download link