Skip to main content

Windows Server Auditing Registry Keys

Review the basic registry keys that you may need to configure for monitoring Windows Server with Netwrix Auditor. Navigate to Start → Run and type "regedit".

Registry key (REG_DWORD type)Description / Value
HKEY_LOCAL_MACHINE\SOFTWARE\WOW6432Node\Netwrix Auditor\Windows Server Change Reporter
CleanAutoBackupLogsDefines the retention period for the security log backups:
  • 0—The product never deletes backups from domain controllers
  • [X]—The product deletes backups after [X] hours
ProcessBackupLogsDefines whether to process security log backups:
  • 0—No
  • 1—Yes Even if you set this key to "0", the product doesn't delete the security log backups regardless of the CleanAutoBackupLogs key value.

Event Log

Review the basic registry keys that you may need to configure for monitoring event logs with Netwrix Auditor. Navigate to Start → Run and type "regedit".

Registry key (REG_DWORD type)Description / Value
HKEY_LOCAL_MACHINE\SOFTWARE\WOW6432NODE\Netwrix Auditor\Event Log Manager<monitoring plan name>\Database Settings
ConnectionTimeoutDefines SQL database connection timeout (in seconds).
BatchTimeOutDefines batch writing timeout (in seconds).
DeadLockErrorCountDefines the number of write attempts to a SQL database.
HKEY_LOCAL_MACHINE\SOFTWARE\WOW6432NODE\Netwrix Auditor\Event Log Manager
CleanAutoBackupLogsDefines the retention period for the security log backups:
  • 0—The product never deletes backups from domain controllers
  • [X]—The product deletes backups after [X] hours
ProcessBackupLogsDefines whether to process security log backups:
  • 0—No
  • 1—Yes Even if you set this key to "0", the product doesn't delete the security log backups regardless of the CleanAutoBackupLogs key value.
WriteAgentsToApplicationLogDefines whether to write the events produced by the Netwrix Auditor Event Log Compression Service to the Application Log of a monitored machine:
  • 0—Disabled
  • 1—Enabled
WriteToApplicationLogDefines whether to write events produced by Netwrix Auditor to the Application Log of the machine where the product is installed:
  • 0—No
  • 1—Yes