Partial log collection or no logs are collected due to flooding of events in Event Viewer | EventLog Analyzer troubleshooting

Partial log collection or no logs are collected due to flooding of events in Event Viewer | EventLog Analyzer troubleshooting

Issue description

When high log flow is observed, Event Viewer may flood out, leading to partial or no logs being collected.

Possible cause

A high number of events being generated in a production environment server might exhaust or exceed the Event Viewer size. This may lead to events getting overwritten or EventLog Analyzer not being able to collect logs present in the Event Viewer due to scheduled log collection.

Prerequisites

  • Need admin access to the server to update Event Viewer settings.
  • Need log source configuration modification access for EventLog Analyzer.

Resolution

Case 1: Increase Event Viewer size to withstand at least 15 minutes of events for scheduled log collection.

Step 1: Increase the size of the Event Viewer Log folder to hold more events. This will increase the time of events existing in the Event Viewer.
Step 2: Open Event Viewer for the respective Windows device and right-click the log type > Properties. Increase the Event Viewer value.
Step 3: Review the time difference between the first and last message and set the Maximum log size (KB) accordingly.

Case 2: Set real-time log collection to collect the logs.

Step 1: Navigate to Settings > Log source configuration > Devices  > Windows.
Step 2: Under the Actions column, click the Update icon for the respective device and set the Log Collection Mode to Realtime.
Step 3: Click Update.

Tips

  • Set up Event Viewer to hold events based on log collection schedule.
  • Review the configuration made in Audit Policies to ensure required events are being recorded and to avoid noisy events.

How to reach support

If the issue persists, please contact support.
Support Channels:
Toll-Free (US): +1 844 649 7766
Request Support PortalSupport :: EventLog Analyzer
 
 

                  New to ADSelfService Plus?