20. Backing up Event Logs


Save Event Log As File

To save current event log into event log file, select File -> Save Event Log (backup) from the main menu. To backup unopened event log, browse for the log in the computers tree, click right mouse button on it and select Save Log As from the drop-down menu.
By default Windows Event Log service doesn't allow backups across the network. It means that if you need to backup System log on \\Server, you can only backup it to \\Server.
When you backup event logs with Event Log Explorer, you can save logs to any computer across the net. In this case Event Log Explorer will backup event log locally to Windows\Temp folder, and move the backup file to the target computer.

Automatic Event Log Backup

Event Log Explorer helps you to automatically back up event logs. To do so, open Event Log Properties dialog (File->Log Properties for the current event log) and enable option: Backup log automatically. When this option is enabled and the event log size reaches Maximum log size value, Windows Event Log service will automatically save the log into Windows\System32\winevt\Logs and clear the log. The name of the backup file is a concatenation of the log file name and the date and time (in coordinated universal time, or UTC). The name has this format:
You must make sure to move or delete the backup log files from the System volume. If you do not, the volume may become full.
You can find extra information about auto auto-archiving at Microsoft's website