Requires Free Membership to View
1. Open REGEDIT (or another Registry editor program) and navigate to the key: HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\Eventlog
2. Open the subkey that contains the event log you want to move. On most machines, you'll be able to choose between Application, Security and System.
3. Each key contains a value named File (type REG_EXPAND_SZ), which contains the pathname and filename to the log file. By default this is %SystemRoot%\system32\config\ 4. Close the Registry and restart the computer.
This was first published in November 2005
Enterprise Server Strategies for the CIO
Join the conversationComment
Share
Comments
Results
Contribute to the conversation