5.12 Windows System Logs

Windows logs record system events on client machines for later review. By default, Windows system logs are not recorded and must be enabled via Policy → Log Settings.

Administrators require the permission Tools → Accounts → Function Permissions → Logs → Windows System Logs to view client Windows logs.

Select Logs → Windows System Logs to view policy logs, which include:

Attribute Description
Type The type of system log: Application, Security, or System.
Source The event source of the system log; fuzzy search is not supported.
Record Count Number of records in the log.
Event ID The event ID of the log; fuzzy search is not supported.
Level Log level: Critical, Warning, Detailed, Error, or Information.
Keyword Log keywords.
Task Category Task category of the log; fuzzy search is not supported.
Details Detailed description of the log entry.

Notes:

  • After enabling the policy, only logs from the past 5 days are available in Windows system logs.
  • The Keyword field only displays Audit Success, Audit Failure, or Classic; other values will appear empty.