This policy setting controls the location of the log file. The location of the file must be writable by the Event Log service and should only be accessible to administrators.
If you enable this policy setting, the Event Log uses the path specified in this policy setting.
If you disable or do not configure this policy setting, the Event Log uses the system32 or system64 subdirectory.
Registry Hive | HKEY_LOCAL_MACHINE |
Registry Path | Software\Policies\Microsoft\Windows\EventLog\Security |
Value Name | File |
Value Type | REG_SZ |
Default Value |