Does anyone know of a way to Dump/Clear and Event Log from the command line? I would prefer to dump it in the default .evt format for the Event Logs. This way I can setup DumpEvt to massage the data for import into a database.
We are required to keep the security log indefinitely for audit trail purposes. (It's a nightmare that I would rather not be doing, but FDA and ISO. . .)
Currently, I have to manually go into the event logs and do a clear, answer yes to the save question, and then save the .evt file to a location on the respective server. However, given that I can't overwrite the logs, but MUST retain them, I need to be able to automatically empty the logs on a regular basis, lest, being human, I forget to do it myself.
Any ideas?
We are required to keep the security log indefinitely for audit trail purposes. (It's a nightmare that I would rather not be doing, but FDA and ISO. . .)
Currently, I have to manually go into the event logs and do a clear, answer yes to the save question, and then save the .evt file to a location on the respective server. However, given that I can't overwrite the logs, but MUST retain them, I need to be able to automatically empty the logs on a regular basis, lest, being human, I forget to do it myself.
Any ideas?