To everyone running build 10.X or greater of ELA, there is a potentially monumental bug introduced with version 10 (and perhaps earlier, but I have no proof of anything before 10.X). There is a bug in the sysevtcol.exe where it frequently fails to retrieve logs from both system and security logs. In my environment this amounted to thousands upon thousands of missed logs every day This is obviously a critical failure for anyone needing complete security and system logs. I have been working with Manage Engine over the last two months to resolve the issue, and they provided a patch to address this today. I also learned that while a new build will be made available to existing customers in the next few days, this WILL NOT include this critical patch. I encourage everyone who reads these forums to contact manage engine and get this critical fix. If you don't believe me, feel free to double check your logs. Compare your security or system logs collected in ELA to the actual windows event log. I did this for a period of a week and I did not find a single period of time in which 100% of security or system logs were collected for any host.
EDIT: Accidentally said application instead of system logs.