18.9.26.3.1 Ensure 'Setup: Control Event Log behavior when the log file reaches its maximum size' is set to 'Disabled'

Information

This policy setting controls Event Log behavior when the log file reaches its maximum size.

The recommended state for this setting is: 'Disabled'.

Note: Old events may or may not be retained according to the _Backup log automatically when full_ policy setting.

Rationale:
If new events are not recorded it may be difficult or impossible to determine the root cause of system problems or the unauthorized activities of malicious users.

Solution

To establish the recommended configuration via GP, set the following UI path to 'Disabled':


Computer Configuration\Policies\Administrative Templates\Windows Components\Event Log Service\Setup\Control Event Log behavior when the log file reaches its maximum size


Note: This Group Policy path is provided by the Group Policy template 'EventLog.admx/adml' that is included with all versions of the Microsoft Windows Administrative Templates.

'Note #2:' In older Microsoft Windows Administrative Templates, this setting was initially named _Retain old events_, but it was renamed starting with the Windows 8.0 & Server 2012 (non-R2) Administrative Templates.

Impact:
None - this is the default behavior.

See Also

https://workbench.cisecurity.org/files/1929

Item Details

Category: AUDIT AND ACCOUNTABILITY

References: 800-53|AU-11

Plugin: Windows

Control ID: 01f1841cb6dacf3671fa488f85c2f84b948d565e4990b9db9280639df1f5e63b