When Lansweeper scans a Windows computer, it retrieves the events found in the Windows Logs section of the computer's Event Viewer. However, it's important to note that, to keep your database as small as possible, only error events are scanned by default. Looking at the screenshot below for instance, the first 3 events will be scanned by default, but the 4th and 5th event will not. Additional event types (warning, information, success audit or failure audit) can be manually enabled for scanning, if required.
To enable scanning of additional (non-error) event types, do the following:
- Browse to the following section of the web console: Configuration\Server Options. If you have multiple scanning servers, there will be a separate configuration tab for each server.
- Tick the checkboxes of the event types you would like to enable, in the Eventlog scanning section of the page.Enabling additional event types can greatly increase the size of your database over time and negatively impact performance. It is recommended that you leave as many event types disabled as possible.For performance reasons, our LsAgent and LsPush scanning agents only scan error events, regardless of which event types you enable in your Server Options.
- Lower the Delete eventlog entries after XX days setting as much as possible, in the History Cleanup Options section of the page, to prevent exponential growth of your database.
- Wait for your scanning schedules to trigger or manually rescan your Windows computers, e.g. with the Rescan buttons found in asset overviews.
- View scanned events through dashboard widgets, reports or in the Event log tab of individual Windows computer webpages. Examples of event log widgets are Event Filter and Event Summary. A sample report that lists all scanned events that occurred in the last 7 days can be found here in our report center. Event log data is stored in the tblNtlog database tables.