Application and services log collection
EventLog Analyzer supports the collection of application and services logs from the Event Viewer. For example, to successfully collect PowerShell logs from Windows, you have to add a key inside the registry of the respective client machine from which you want to collect logs. You can do this by following these steps:
- Find and open regedit.msc.
- Navigate to HKEY_LOCAL_MACHINE > SYSTEM > CurrentControlSet > Services > EventLog.
- Create a new key called Windows PowerShell.
- Restart the EventLog Analyzer service after adding the key in the registry of the client machine.
EventLog Analyzer provides out-of-the-box reports for specific keys. You can refer to this
guide to set up these reports. For other keys, logs can still be collected with basic parsing capabilities. EventLog Analyzer can be configured to deliver custom reports for them.
New to ADSelfService Plus?
Related Articles
FAQs- Log Collection
1. How many devices can be audited in EventLog Analyzer? Answer: You are limited to audit the devices based on the license procured and there is no upper limit for purchasing the license. A single instance of EventLog Analyzer can handle log flow ...
Enabling historic log collection in EventLog Analyzer
EventLog Analyzer collects all the logs present in the Windows Event Viewer (i.e., Windows Logs > Application, Security, System) when the historic log collection option is enabled. To enable historic log collection, follow the steps below: Navigate ...
How to configure log collection filters in EventLog Analyzer/Log360
Objective EventLog Analyzer offers log filtering capabilities, so that you can filter/remove/exclude unwanted events being collected or collect only the logs you actually need, by avoiding noisy events being collected. Filters let you include or ...
How to Perform Scheduled Import Log Collection in EventLog Analyzer
Objective EventLog Analyzer supports scheduled log imports from both remote paths and S3 buckets. You can enable scheduled log collection to have the application read data from the same file at regular intervals, or configure a file naming convention ...
How to Perform Scheduled Import Log Collection in EventLog Analyzer
Objective EventLog Analyzer supports scheduled log imports from both remote paths and S3 buckets. You can enable scheduled log collection to have the application read data from the same file at regular intervals, or configure a file naming convention ...