Skip to content

[Bug] - Disk space issues caused by event log settings #131

@bennyocb1291

Description

@bennyocb1291

Baseline Info (please complete the following information):

  • OS: [e.g. Windows] Windows
  • Version: [e.g. 3.6] 3.6

Describe the bug
A clear and concise description of what the bug or error is.

I've been receiving more and more complaints about disk space issues being caused by our event logs not properly overwriting, per the 'Win - OIB - SC - Device Security - D - Audit and Event Logging - v3.1' policy settings.

According to the MS docs for the CSPs here https://learn.microsoft.com/en-gb/windows/client-management/mdm/policy-csp-admx-eventlog?WT.mc_id=Portal-fx#channel_log_retention_2

Old events may or may not be retained according to the "Backup log automatically when full" policy setting.

The baseline is only setting 'Control Event Log behavior when the log file reaches its maximum size' to disabled & 'Specify the maximum log file size (KB)', so my thinking was that 'Back up log automatically when full' also needs to be hard set to disabled. After updating a test policy to reflect this change, the scoped devices started behaving as expected.

Happy to accept if it's just me, though I couldn't find any other settings in the OIB, or auxiliary policies I have in my tenant that could be causing the settings on some devices to not behave as expected so resorted to reading the CSP doc. In addition, the affected devices span multiple device models with different drives and capacities, etc. which blew out my initial theory of perhaps just the heavier users on devices with smaller drives noticing the issue.

Expected behaviour
A clear and concise description of what you expected to happen.

Windows event logs overwriting when the configured maximum size of each log type is reached.

Metadata

Metadata

Assignees

No one assigned

    Labels

    No labels
    No labels

    Projects

    No projects

    Milestone

    No milestone

    Relationships

    None yet

    Development

    No branches or pull requests

    Issue actions