Ask the Expert

Change the default location for the Event Viewer's log files

Is there a straightforward way to redirect the Event Viewer files from the Windows\System32\config folder to an alternate logical partition or network share? My platform is Windows XP Professional SP2.

Requires Free Membership to View

There is indeed a way to change the default location for the Event Viewer's log files in Windows 2000, 2003 and XP. Note that you need to be logged in with an account that has administrative privileges to do this.

1. Open REGEDIT (or another Registry editor program) and navigate to the key: HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\Eventlog

2. Open the subkey that contains the event log you want to move. On most machines, you'll be able to choose between Application, Security and System.

3. Each key contains a value named File (type REG_EXPAND_SZ), which contains the pathname and filename to the log file. By default this is %SystemRoot%\system32\config\.Evt. You can provide a new pathname and filename here, but you should use the .EVT file extension.

4. Close the Registry and restart the computer.

This was first published in November 2005

There are Comments. Add yours.

TIP: Want to include a code block in your comment? Use <pre> or <code> tags around the desired text. Ex: <code>insert code</code>

REGISTER or login:

Forgot Password?
By submitting you agree to receive email from TechTarget and its partners. If you reside outside of the United States, you consent to having your personal data transferred to and processed in the United States. Privacy
Sort by: OldestNewest

Forgot Password?

No problem! Submit your e-mail address below. We'll send you an email containing your password.

Your password has been sent to: