Send Knowledge Base Article
The article has been sent to your inbox successfully.
We never share your data
Reset collection history for Generic Events (Event Log Management)
KB1804 | Last review: Dec 19, 2013 | Netwrix Auditor for Windows Server | All Versions
|Question||How to reset the Generic Event (Event Log Management) collections in order to collect data that had been collected in the past.|
|Answer||In cases where Netwrix Auditor - Generic Events (Event Log Management) is not being used to archive event data but rather collect it "on demand" you must remove prior collection history for the server you are trying to collect from so that event logs are collected that were already collected in the past.
In order to do this please perform the following:
1) Navigate to the audit archive location (location specified under Settings -> Audit Archive) and drill down into the Logs folder. In this folder find the name of the Managed Object and inside that there is a folder for each of the computers the product is collecting from. Delete the folder for the computer in question.
Was this information helpful?