The log files processed by EventLog Analyzer are archived periodically for internal, forensic, and compliance audits. The interval and retention period is configurable. The archive file can be encrypted and time-stamped to make it secure and tamper-proof.
Archived Files page lists all the archived files in a table with the devices for which the files were archived, start time of archiving, the time at which archived, size of the archived file, the status of the file, and action on the file. If the number of archived files is more and if manual viewing and selection is not possible, use the search archived files (search icon) to filter the required files in the list.
How to delete archived files?
1a. Select the archived file(s) by selecting the respective check box(es).
1b. Delete the archived file(s) using the Delete link.
How to generate report from the archived files?
1. Check the status of the archived file. If it is ‘Not Loaded’, click the ‘Load & Search’ action to load the file to the database and search the logs.
2. If the status of the file is ‘Loaded’, click the ‘Search’ link to search the logs in the file. If you want to drop the file from the database, click the ‘Drop DB’ link.
Configure the archive interval, retention period, option to encrypt, time-stamp of the archive files, location to save the archive files and location to save the index files in this screen.
Note: The Archive and Database storage are asynchronus operations. These operations are unrelated.
Ensure that archiving is enabled. By default it is enabled. Deselect the check box to disable archiving.
The logs are written to flat files at the specified time period. Choose the required time interval. The default value is 12 Hours.
The flat files are compressed (20:1 ratio) and zip files are created at the specified time period. Choose the required time interval. The default value is 4 days.
To secure the archive files, enable encryption of the files. By default, it will be disabled.
To timestamp the archive files before they are stored, enable time-stamping of the files. By default, it will be disabled.
To make sure that the archived files are not tampered with, enable archive integrity. By default, it will be disabled.
Select the log retention period. The default value is Forever.
The default archive storage location is displayed and to change the location as required, use the Edit link.
Save the settings and close the window. For instant archiving, click the Zip now button.
Note: If you wish to set a dynamic key for encrypting the archive files, follow these steps:
1. Go to the archive location. By default, files are archived at <EventLog Analyzer Home>\archive. Create a file EncryptedKey.enc.
2. Open the file using a text editor and enter the dynamic key as text. The key should be exactly 16 characters in length.
3. Restart the EventLog Analyzer service.
If you wish to import the files archived using the above dynamic key in another installation of EventLog Analyzer, follow these steps first:
1. Paste the EncryptedKey.enc file in the installed product archive location.
2. Restart the product.
3. Import the required archive files.