Windows Vista Tips

Windows Vista Tips > Newsgroups > Windows Vista General Discussion > How to change location of Vista Event Log file?

Reply
Thread Tools Display Modes

How to change location of Vista Event Log file?

 
 
deko
Guest
Posts: n/a

 
      01-30-2008
I've tried editing the registry keys at:

HKEY_LOCAL_MACHINE\System\CurrentControlSet\Servic es\Eventlog\

I modified this:

%SystemRoot%\system32\winevt\Logs\System.evtx

to this:

G:\EventLogs\System.evtx

But the systems still logs to:

%SystemRoot%\system32\winevt\Logs\System.evtx

I tried making the change a couple of times but no good.

I'm not using UAC and am logged in as Administrator (renamed)

Here's what I did:

1. set the Windows Event Log service to Disabled
2. rebooted
3. deleted %SystemRoot%\system32\winevt\Logs\System.evtx
4. verified that G:\EventLogs\ directory exists and that LOCAL SERVICE has
Full Control
5. edited the registry as indicated above
6. set the Windows Event Log service to Enabled
7. rebooted

If I look at the registry key value, it says 'G:\EventLogs\System.evtx', but
it doesn't have any effect - the system created a new System.evtx in
%SystemRoot%\system32\winevt\Logs\. Am I editing the right key? Why can't
I get Vista to log where I tell it to?

Thanks in advance.

 
Reply With Quote
 
 
 
 
AlexB
Guest
Posts: n/a

 
      01-31-2008
Wow, why in the world would you do it?

Install a new Vista on G: and you will have an event log in there.

Vista does not take such c*rap easily. You are trying to make it think
differently. It is a system prerogative to determine as to where to keep an
event log.

What is the idea beyond that?


"deko" <> wrote in message
news:aeGdnQH8V-...
> I've tried editing the registry keys at:
>
> HKEY_LOCAL_MACHINE\System\CurrentControlSet\Servic es\Eventlog\
>
> I modified this:
>
> %SystemRoot%\system32\winevt\Logs\System.evtx
>
> to this:
>
> G:\EventLogs\System.evtx
>
> But the systems still logs to:
>
> %SystemRoot%\system32\winevt\Logs\System.evtx
>
> I tried making the change a couple of times but no good.
>
> I'm not using UAC and am logged in as Administrator (renamed)
>
> Here's what I did:
>
> 1. set the Windows Event Log service to Disabled
> 2. rebooted
> 3. deleted %SystemRoot%\system32\winevt\Logs\System.evtx
> 4. verified that G:\EventLogs\ directory exists and that LOCAL SERVICE has
> Full Control
> 5. edited the registry as indicated above
> 6. set the Windows Event Log service to Enabled
> 7. rebooted
>
> If I look at the registry key value, it says 'G:\EventLogs\System.evtx',
> but it doesn't have any effect - the system created a new System.evtx in
> %SystemRoot%\system32\winevt\Logs\. Am I editing the right key? Why
> can't I get Vista to log where I tell it to?
>
> Thanks in advance.
>


 
Reply With Quote
 
deko
Guest
Posts: n/a

 
      01-31-2008
> Wow, why in the world would you do it?
>
> Install a new Vista on G: and you will have an event log in there.
>
> Vista does not take such c*rap easily. You are trying to make it think
> differently. It is a system prerogative to determine as to where to keep
> an event log.
>
> What is the idea beyond that?


I don't mean to be snide, but you should really think before you post.

There are many reasons why people store log files in different places. And
to say it's a 'system prerogative' where to log shows how much real world
experience you have.

There's a mskb article http://support.microsoft.com/kb/315417 that
explains how to do exactly what I did with the registry. What's tricky in
Vista is the property sheets for the individual logs do not appear to be
editable. The Log Path field is the same default gray as the form
background. But if you click on the path, you can change it. So the
ability to define a location for event logs is a built-in feature in Vista.
No registry editing needed.

 
Reply With Quote
 
AlexB
Guest
Posts: n/a

 
      01-31-2008
Well, you are obviously of a much better class than I initially assumed but
it is still unclear to me why you want to do it. You say: there are many
reasons but what?

If you want to monitor event logs programmatically on the run it is NOT a
way to go. There are classes in .NET that can do it easily and with enormous
degree of control in terms of filtering, etc.

Also, I am surprised you are quoting Win2K workaround and you are trying to
apply it to Vista. I do not respect such an approach.

WinSer2003 is an yesterday's news also. Now it is WinSer2008.

"deko" <> wrote in message
news:. ..
>> Wow, why in the world would you do it?
>>
>> Install a new Vista on G: and you will have an event log in there.
>>
>> Vista does not take such c*rap easily. You are trying to make it think
>> differently. It is a system prerogative to determine as to where to keep
>> an event log.
>>
>> What is the idea beyond that?

>
> I don't mean to be snide, but you should really think before you post.
>
> There are many reasons why people store log files in different places.
> And to say it's a 'system prerogative' where to log shows how much real
> world experience you have.
>
> There's a mskb article http://support.microsoft.com/kb/315417 that
> explains how to do exactly what I did with the registry. What's tricky in
> Vista is the property sheets for the individual logs do not appear to be
> editable. The Log Path field is the same default gray as the form
> background. But if you click on the path, you can change it. So the
> ability to define a location for event logs is a built-in feature in
> Vista. No registry editing needed.
>


 
Reply With Quote
 
 
 
Reply

Thread Tools
Display Modes

Posting Rules
You may not post new threads
You may not post replies
You may not post attachments
You may not edit your posts

BB code is On
Smilies are On
[IMG] code is On
HTML code is Off
Trackbacks are On
Pingbacks are On
Refbacks are Off


Similar Threads
Thread Thread Starter Forum Replies Last Post
Please, allow to change C:\Users[\xxx] location Fred Windows Vista General Discussion 8 04-03-2008 06:20 PM
How to change the location of the storage file Tony Windows Vista Mail 1 11-23-2007 12:31 AM
Is it possible to change the hibernation file location to D: Blue Fish Windows Vista General Discussion 2 11-05-2007 03:07 AM
ow to change storage location recovery1 Windows Vista Mail 1 10-16-2007 01:33 PM
Change location of Users folder Gav Windows Vista Installation 3 06-08-2006 04:42 PM



1 2 3 4 5 6 7 8 9 10 11 12 13 14 15 16 17 18 19 20 21 22 23 24 25 26 27 28 29 30 31 32 33 34 35 36 37 38 39 40 41 42 43 44 45 46 47 48 49 50 51 52 53 54 55 56 57 58 59