Skip to content
Control Event Log Behavior using Intune

Control Event Log Behavior using Intune

Written By Abhinav Rana
Last Updated July 4, 2023
Posted In Intune
SHARE

This post aims to explore and gain knowledge about how to Control Event Log Behavior Using Intune. Our objective is to Control Event Log Behavior when the log file reaches its maximum size by utilizing the Configuration Profiles available in Intune.

Control Event Log Behavior using Intune policy setting manages the behavior of the Event Log when the log file reaches its maximum size. Enabling this policy setting results in new events not being written to the log and getting lost when a log file reaches its maximum size.

Disabling or not configuring this policy setting allows new events to overwrite old events when a log file reaches its maximum size. Please note that the retention of old events depends on the configuration of the “Backup log automatically when full” policy setting.

It’s worth noting that the behavior of retaining old events when a log file is full may depend on the configuration of the “Backup log automatically when full” policy setting. This separate policy setting determines whether the log file is automatically backed up when it reaches its maximum size, allowing the retention of old events.

Patch My PC

By understanding and configuring this policy setting, you can control how the Event Log behaves when its log file reaches its maximum size, ensuring the appropriate handling of new events and managing the retention of old events based on your organization’s requirements.

Windows CSP Details ControlEventLogBehavior

Let’s go through Windows CSP Details for this Policy setting ControlEventLogBehavior. If you enable this policy setting, when a log file reaches its maximum size, new events will not be written to the log. This means that any new events generated after reaching the maximum size will be lost. It’s important to consider this potential data loss when enabling this policy.

If you disable or do not configure this policy setting, the default behavior is for new events to overwrite old events when a log file reaches its maximum size. This means that when the log file is full, new events will replace the oldest events in the log.

CSP URI – ./Device/Vendor/MSFT/Policy/Config/EventLogService/ControlEventLogBehavior

Control Event Log Behavior Using Intune Fig.1
Control Event Log Behavior Using Intune Fig.1

Control Event Log Behavior using Intune

To create Control Event Log Behavior Using Intune, follow the steps stated below:

  • Sign in to the Intune Admin Center portal https://intune.microsoft.com/.
  • Select Devices > Windows > Configuration profiles > Create a profile.

In Create Profile, Select Windows 10 and later in Platform, and Select Profile Type as Settings catalog. Click on Create button.

PlatformProfile Type
Windows 10 and laterSettings Catalog
Table1 – Control Event Log Behavior Using Intune
Control Event Log Behavior Using Intune Fig.2
Control Event Log Behavior Using Intune Fig.2

On the Basics tab pane, provide a name for the policy as “Control Event Log Behavior when the log file reaches its maximum size Policy.” Optionally, you can enter a description for the policy and then proceed by selecting “Next.”

Control Event Log Behavior Using Intune Fig.3
Control Event Log Behavior Using Intune Fig.3

Now in Configuration settings, click Add Settings to browse or search the catalog for the settings you want to configure.

Control Event Log Behavior Using Intune Fig.4
Control Event Log Behavior Using Intune Fig.4

In the Settings Picker windows, search by the keyword Control Event Log, among many, you will see Administrative Templates\Windows Components\Event Log Service\Application, and select this.

When you select the option as stated above, you will see only one setting, which is Control Event Log behavior when the log file reaches its maximum size. After selecting your setting, click the cross mark in the right-hand corner.

Control Event Log Behavior Using Intune Fig.5
Control Event Log Behavior Using Intune Fig.5

Now, in the Administrative Templates, Disabled the Control Event Log behavior when the log file reaches its maximum size, as shown below in the image.

Control Event Log Behavior Using Intune Fig.6
Control Event Log Behavior Using Intune Fig.6

Using Scope tags, you can assign a tag to filter the profile to specific IT groups. One can add scope tags (if required) and click Next to continue. Now in Assignments, in Included Groups, you need to click on Add Groups, choose Select Groups to include one or more groups, and click Next to continue.

Control Event Log Behavior Using Intune Fig.7
Control Event Log Behavior Using Intune Fig.7

In the Review + Create tab, you need to review your settings. After clicking on Create, your changes are saved, and the profile is assigned.

Control Event Log Behavior Using Intune Fig.8
Control Event Log Behavior Using Intune Fig.8

An automatic notification will be displayed in the top right-hand corner to indicate the successful creation of the Control Event Log behavior when the log file reaches its maximum size Policy.” Additionally, you can verify its presence by checking the Configuration Profiles list, where the policy will be clearly visible.

Your groups will receive your profile settings when the devices check in with the Intune service. The Policy applies to the device.

Intune Report for Control Event Log Behavior Policy

From Intune Portal, you can view the Intune settings catalog profile report, which provides an overview of device configuration policies and deployment status.

To monitor the assignment of the policy, you must choose the appropriate policy from the list of Configuration Profiles. You can check the device and user check-in status to see if the policy has been successfully applied. If you wish to view more information, you can click on “View Report” to see additional details.

Control Event Log Behavior Using Intune Fig.9
Control Event Log Behavior Using Intune Fig.9

Intune MDM Event Log

To ascertain the successful application of String or integer policies on Windows 10 or 11 devices using Intune, event IDs 813 and 814 can be utilized. By analyzing these event IDs, you can identify both the policy’s application status and the specific value associated with the applied policy on those devices. For this specific policy, the value is a string and is associated with event ID 814.

To confirm this, you can check the Event log path – Applications and Services Logs – Microsoft – Windows – Devicemanagement-Enterprise-Diagnostics-Provider – Admin.

MDM PolicyManager: Set policy string, Policy: (ControlEventLogBehavior), Area: (EventLogService), EnrollmentID requesting merge: (E874113F-6CF1-4718-8730-0553BDF7C4AC), Current User: (Device), String: (<disabled/>), Enrollment Type: (0x6), Scope: (0x0).

Control Event Log Behavior Using Intune Fig.10
Control Event Log Behavior Using Intune Fig.10

Upon examining the above-mentioned log in the Event Viewer, you will discover crucial details such as the Area and Enrollment ID. These pieces of information are instrumental in identifying the registry path. To find the relevant information, kindly refer to the table provided below:

AreaPolicyStringScopedEvent ID
EventLogServiceControlEventLogBehaviorDisabledDevice814
Table2 – Control Event Log Behavior Using Intune

The information provided in the above table for Control Event Log Behavior Using Intune can be utilized to access the registry settings storing group policy configurations on a target computer. By running “REGEDIT.exe” on the target computer, you can navigate to the specific registry path where these settings are stored.

  • Computer\HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\PolicyManager\providers\E874113F-6CF1-4718-8730-0553BDF7C4AC\default\Device\EventLogService

When you navigate to the above path in the Registry Editor, you will find the registry key with the name ControlEventLogBehavior. Refer to the table and image below.

Registry NameValue
ControlEventLogBehaviorDisabled
Table3 – Control Event Log Behavior Using Intune
Control Event Log Behavior Using Intune Fig.11
Control Event Log Behavior Using Intune Fig.11

Author

Abhinav Rana is working as an SCCM Admin. He loves to help the community by sharing his knowledge. He is a B.Tech graduate in Information Technology.

Discussion

Join the discussion

Your email address will not be published. Required fields are marked *

Related guides

Intune

Simplify Windows Devices to Run Only the Required Applications using Intune

Key Takeaways Hey, let’s learn about Simplify Windows Devices to Run Only the Required Applications using Intune. This policy lets administrators replace the default windows shell with a custom or lightweight shell. it improves performance by using system resources and is useful for devices that run a dedicated application. If the policy is disabled or […]

AC Anoop C Nair 8 min read
Intune

Enhance macOS Compliance with Custom Security and Compliance Checks to Improve Device Security using Microsoft Intune

Key Takeaways In this post we are discussing about Enhance macOS Compliance with Custom Security and Compliance Checks to Improve Device Security using Microsoft Intune. Microsoft has announced the general availability of Custom Compliance Settings for macOS in Microsoft Intune. The feature helps organizations strengthen security controls while supporting many types of macOS management scenarios. […]

AC Anoop C Nair 4 min read
Intune

Manage Samsung Galaxy Firmware Versions to Improve Security and Compliance using Microsoft Intune

Key Takeaways In this post we are discussing Manage Samsung Galaxy Firmware Versions to Improve Security and Compliance using Microsoft Intune. Microsoft Intune has received a new update that expands firmware management capabilities for Samsung Galaxy devices through Firmware Versionsintegration. This enhancement gives IT administrators more control over firmware and operating system updates, helping them […]

AC Anoop C Nair 4 min read
Intune

MS Intune Adds Windows Registry Data Collection to Device Inventory for Single Values All Key Values and Subkeys

Key Takeaways Microsoft Intune 2607 introduces Windows Registry Data collection in Device Inventory, allowing IT admins to verify actual device configurations without relying on custom discovery or remediation scripts. Using the Properties Catalog, admins can collect registry information through Single Value, All Values Under a Key (Non-Recursive), or Same Value Across Subkeys. MS Intune Adds […]

AC Anoop C Nair 5 min read