Scanning non-error events

When Lansweeper scans a Windows computer, it retrieves the events found in the Windows Logs section of the computer's Event Viewer. It's important to note however that, to keep your database as small as possible, only error events are scanned by default. Looking at the screenshot below for instance, the first 3 events will be scanned by default, but the 4th and 5th event will not. Additional event types (warning, information, success audit or failure audit) can be manually enabled for scanning, if required.

Windows Logs in Event Viewer

To enable scanning of additional (non-error) event types, do the following:

  1. Browse to the following section of the web console: Configuration\Server Options. If you have multiple scanning servers, there will be a separate configuration tab for each server.
    Server Options menu
  2. Tick the checkboxes of the event types you would like to enable, in the Eventlog scanning section of the page.
    enabling scanning of non-error events
    Enabling additional event types can greatly increase the size of your database over time and negatively impact performance. It is recommended that you leave as many event types disabled as possible.
    For performance reasons, our LsPush scanning agent only scans error events, regardless of which event types you enable in your Server Options.
  3. Lower the Delete eventlog entries after XX days setting as much as possible, in the History Cleanup Options section of the page, to prevent exponential growth of your database.
    deleting event log entries after XX days
  4. View scanned events through dashboard widgets, reports or in the Event log tab of individual Windows computer webpages. Examples of event log widgets are Event Filter and Event Summary. A sample report that lists all scanned events that occurred in the last 7 days can be found here in our report center. Event log data is stored in the tblNtlog database tables.
    event log data on Windows computer webpages

Related Articles