Ask the Community
Groups
Event Log collection has drastically increased per day after a fresh build and copying over the data - Connect IT Community | Kaseya
<main> <article class="userContent"> <p><strong>Symptom</strong></p> <p>As part of an upgrade or change to new hardware you've built a new server and installed Kaseya then copied the files from the old server to the new one and Restored the database. Post the change you're database is growing fast.</p> <p> </p> <p><strong>Further investigation</strong></p> <p>After further investigation you've noticed that the even't logs collected <strong>per day </strong>has drastically increased.This can be found by comparing the size of the event log tables per day "ntEventLog20150109,ntEventLog20150110..."</p> <p>-Note This is not to be confused with the server <strong>retaining</strong> the event logs longer than it should.</p> <p> </p> <p><strong>Problem</strong></p> <p>By default Kaseya no longer excludes some events from being brought back to the server. This means if you perform a fresh install and don't copy over your existing exceptions the server will now start collecting more event log information then it previous was, resulting in a great SQL db size. </p> <p> </p> <p><strong>Resolution</strong></p> <p>Copy the exceptions from your previous build. They can be found here.</p> <p>C:\Kaseya\WebPages\ManagedFiles\VSAHiddenFiles\ evLogBlkList.xml</p> <p>C:\Kaseya\WebPages\ManagedFiles\VSAHiddenFiles\ evLogBlkListEx.xml</p> <p>If you don't have access to your previous server this if the 6.3 default exceptions for evLogBlkList.xml</p> <p><?xml version="1.0" encoding="ISO-8859-1" ?><br><EventLogBlackList version="1.0" OverflowTime="3600" OverflowCount="1000"><br> <EventLog Name="Application" ID="796450521"><br> <Def Information="1" Source="HHCTRL" EventID="1903" /><br> </EventLog><br> <EventLog Name="Security" ID="1664713117"><br> <Def AuditSuccess="1" Source="Security" /><br> <Def AuditSuccess="1" Source="Microsoft Windows security audit%" /><br> </EventLog><br> <EventLog Name="System" ID="1380569194"><br> <Def Warning="1" Source="%SpoolerWin32%" EventID="4" /><br> </EventLog><br></EventLogBlackList></p> <p><img src="/attachments/token/6FiNbgZtkOCshI8gw5YSaQROg/?name=2-1.JPG" alt="2-1.JPG" width="500" class="embedImage-img importedEmbed-img"></img></p> <p> </p> <p><strong>Affected versions</strong></p> <p>6.5,7,8,+</p> </article> </main>