I am using the freeware version of Netwrix Auditor. It is used to monitor changes on a couple of our servers. One of these servers is old and only has 7GB of free space on the system drive. I have Windows auditing set up on a shared folder and have configured the System, Application and Security Event Logs to have a 60MB size limit. The log is archived when the limit is reached and I move the archived logs to a file server so that as much free space is available.
I noticed that the free space on the system drive had dropped and discovered the software had reconfigured the log properties. I changed this last week and reset it to 60MB/archive, but discovered that it has changed back.
Is there a way to configure the Auditor to use the existing configuration? Or, to change the way the Auditor collects data. I understand the 4GB limit is so that it does not miss events, but the hard limit is not suitable to all servers.
Any help please?