Event log policies

PRAKASH Ayush 0 Reputation points
2025-03-18T14:22:14.4+00:00

Hello all, Kindly explain how to use the AuditLogRetentionPeriod and RetentionDays as shown in the attached link

https://learn.microsoft.com/en-us/openspecs/windows_protocols/ms-gpsb/0b9673a7-ce0a-49b4-912b-591efdb37cdfUser's image

Windows for business | Windows Client for IT Pros | User experience | Other
0 comments No comments
{count} votes

1 answer

Sort by: Most helpful
  1. Anonymous
    2025-03-20T07:18:50.3+00:00

    Hello,

    Thank you for posting in Microsoft Q&A.

    Based on the description, I understand your question is related to event log.

    AuditLogRetentionPeriod:

    0: Overwrite events as needed. This means that when the log reaches its maximum size, the oldest events will be overwritten by new events.

    1: Overwrite events as specified by the RetentionDays entry. This means that events will be retained for a specific number of days before being overwritten.

    2: Never overwrite events. This means that events will not be overwritten, and the log must be cleared manually when it reaches its maximum size.

    RetentionDays: the number of days that events in the System, Security, and Application logs must be retained before being overwritten.

    Have a nice day.

    Best Regards,

    Molly

    ============================================

    If the Answer is helpful, please click "Accept Answer" and upvote it


Your answer

Answers can be marked as Accepted Answers by the question author, which helps users to know the answer solved the author's problem.