windows security logging

Howell

Storage? I am Storage!
Joined
Feb 24, 2003
Messages
4,740
Location
Chattanooga, TN
Does anyone have a solution for windows security logging?

Requirements:
I'd like to keep 6 months worth of basic security events for 2 domain controllers and do it for minimal cost.

Hurdles:
The maximum log file size on server 2003 is 4G.
"Event Viewer logs are memory mapped files. The maximum size of an event log is constrained by the amount of physical memory in the local computer and by the virtual memory that is available to the event log process. Increasing the log size beyond the amount of virtual memory that is available to Event Viewer does not increase the number of log entries that are maintained." <shudder>


Any ideas?
 

BingBangBop

Storage is cool
Joined
Nov 15, 2009
Messages
667
Save the logs in pieces. You can save logs, import saved logs, and you can clear logs whenever you want. So you are no longer constrained by size. The limit becomes how many pieces (how often you save/clear them).
 

Howell

Storage? I am Storage!
Joined
Feb 24, 2003
Messages
4,740
Location
Chattanooga, TN
I can not figure out how to implement David's suggestion with the 2003 native tools. Only various ways to guide overwriting seem to exist.

BBB, unless I'm missing something your process seems very manual. It does solve the file size problem however.
 
Top