D
deko
I've tried editing the registry keys at:
HKEY_LOCAL_MACHINE\System\CurrentControlSet\Services\Eventlog\
I modified this:
%SystemRoot%\system32\winevt\Logs\System.evtx
to this:
G:\EventLogs\System.evtx
But the systems still logs to:
%SystemRoot%\system32\winevt\Logs\System.evtx
I tried making the change a couple of times but no good.
I'm not using UAC and am logged in as Administrator (renamed)
Here's what I did:
1. set the Windows Event Log service to Disabled
2. rebooted
3. deleted %SystemRoot%\system32\winevt\Logs\System.evtx
4. verified that G:\EventLogs\ directory exists and that LOCAL SERVICE has
Full Control
5. edited the registry as indicated above
6. set the Windows Event Log service to Enabled
7. rebooted
If I look at the registry key value, it says 'G:\EventLogs\System.evtx', but
it doesn't have any effect - the system created a new System.evtx in
%SystemRoot%\system32\winevt\Logs\. Am I editing the right key? Why can't
I get Vista to log where I tell it to?
Thanks in advance.
HKEY_LOCAL_MACHINE\System\CurrentControlSet\Services\Eventlog\
I modified this:
%SystemRoot%\system32\winevt\Logs\System.evtx
to this:
G:\EventLogs\System.evtx
But the systems still logs to:
%SystemRoot%\system32\winevt\Logs\System.evtx
I tried making the change a couple of times but no good.
I'm not using UAC and am logged in as Administrator (renamed)
Here's what I did:
1. set the Windows Event Log service to Disabled
2. rebooted
3. deleted %SystemRoot%\system32\winevt\Logs\System.evtx
4. verified that G:\EventLogs\ directory exists and that LOCAL SERVICE has
Full Control
5. edited the registry as indicated above
6. set the Windows Event Log service to Enabled
7. rebooted
If I look at the registry key value, it says 'G:\EventLogs\System.evtx', but
it doesn't have any effect - the system created a new System.evtx in
%SystemRoot%\system32\winevt\Logs\. Am I editing the right key? Why can't
I get Vista to log where I tell it to?
Thanks in advance.