1. Open REGEDIT (or another Registry editor program) and navigate to the key: HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\Eventlog
2. Open the subkey that contains the event log you want to move. On most machines, you'll be able to choose between Application, Security and System.
3. Each key contains a value named File (type REG_EXPAND_SZ), which contains the pathname and filename to the log file. By default this is %SystemRoot%\system32\config\ 4. Close the Registry and restart the computer.
4. Close the Registry and restart the computer.
This was first published in November 2005