-
-
Notifications
You must be signed in to change notification settings - Fork 221
Description
Baseline Info (please complete the following information):
- OS: [e.g. Windows] Windows
- Version: [e.g. 3.6] 3.6
Describe the bug
A clear and concise description of what the bug or error is.
I've been receiving more and more complaints about disk space issues being caused by our event logs not properly overwriting, per the 'Win - OIB - SC - Device Security - D - Audit and Event Logging - v3.1' policy settings.
According to the MS docs for the CSPs here https://learn.microsoft.com/en-gb/windows/client-management/mdm/policy-csp-admx-eventlog?WT.mc_id=Portal-fx#channel_log_retention_2
Old events may or may not be retained according to the "Backup log automatically when full" policy setting.
The baseline is only setting 'Control Event Log behavior when the log file reaches its maximum size' to disabled & 'Specify the maximum log file size (KB)', so my thinking was that 'Back up log automatically when full' also needs to be hard set to disabled. After updating a test policy to reflect this change, the scoped devices started behaving as expected.
Happy to accept if it's just me, though I couldn't find any other settings in the OIB, or auxiliary policies I have in my tenant that could be causing the settings on some devices to not behave as expected so resorted to reading the CSP doc. In addition, the affected devices span multiple device models with different drives and capacities, etc. which blew out my initial theory of perhaps just the heavier users on devices with smaller drives noticing the issue.
Expected behaviour
A clear and concise description of what you expected to happen.
Windows event logs overwriting when the configured maximum size of each log type is reached.