Administration Guide

How to configure Windows Event Log collection

Windows Event Log collection is disabled by default for each Site. A Site Administrator can enable it for subsequent Windows audits.

Admin Center > Settings > Audit settings > General

When collection is disabled, you can also open this setting from a Windows computer: select Details > Software > Event logs, then select Open audit settings.

Prerequisites

  • You are signed in as a Site Administrator.

Steps

  1. Navigate to Admin Center > Settings > Audit settings.
  2. On the General tab, under Windows Event Logs, enable Collect Windows Event Logs during audits.

The setting applies only to the current Site. During each subsequent Windows audit, AlloyScan collects up to 200 Critical and Error events from the System and Application logs. Events can be no more than 15 days old when collected and are retained for 30 days.

Verify collection

  1. Run an audit for a Windows computer or wait for its next scheduled audit.
  2. Open the computer from Inventory > Windows computers.
  3. Select Details > Software > Event logs.

The grid shows any matching events collected during the audit. If no matching events were collected, it shows No Event Logs have been collected.

Disable collection

Return to Admin Center > Settings > Audit settings > General and turn off Collect Windows Event Logs during audits. The change applies to subsequent audits. Previously collected events remain subject to the 30-day retention period.