Knowledge Base

How to Enable User Environment Event Logging in Windows 2000

PSS ID Number: 186454

Article Last Modified on 5/12/2003


The information in this article applies to:


This article was previously published under Q186454
IMPORTANT: This article contains information about modifying the registry. Before you modify the registry, make sure to back it up and make sure that you understand how to restore the registry if a problem occurs. For information about how to back up, restore, and edit the registry, click the following article number to view the article in the Microsoft Knowledge Base:

256986 Description of the Microsoft Windows Registry

SUMMARY

This article describes how to enable the user environment event logging features available in Windows 2000.

MORE INFORMATION

WARNING: If you use Registry Editor incorrectly, you may cause serious problems that may require you to reinstall your operating system. Microsoft cannot guarantee that you can solve problems that result from using Registry Editor incorrectly. Use Registry Editor at your own risk.

You can log environment events using either Normal or Verbose mode. Information from either of these modes is stored in the Windows NT event log so that an administrator can view events either locally or remotely using Event Viewer.

To enable all forms of user environment event logging using Verbose mode without having to add a registry value for each component individually, add the following value to the registry:
   Registry Path: HKEY_LOCAL_MACHINE\Software\Microsoft\Windows NT
                  \CurrentVersion\Diagnostics

   Value Name   : RunDiagnosticLoggingGlobal
   Value Type   : REG_DWORD
   Value Data   : 1
				
NOTE: The Diagnostics key is not present by default. You need to add it and leave the Class key empty.

To enable verbose event logging for group policies only, add the following value to the Registry:
   Registry Path: HKEY_LOCAL_MACHINE\Software\Microsoft\Windows NT\ 
                  CurrentVersion\Diagnostics

   Value Name   : RunDiagnosticLoggingGroupPolicy
   Value Type   : REG_DWORD
   Value Data   : 1
				
To enable verbose event logging for application deployment only, add the following value to the Registry:
   Registry Path: HKEY_LOCAL_MACHINE\Software\Microsoft\Windows NT\ 
                  CurrentVersion\Diagnostics

   Value Name   : RunDiagnosticLoggingApplicationDeployment
   Value Type   : REG_DWORD
   Value Data   : 1
				

Additional query words: 5.00 system policy profile domain logs logged userenv logging

Keywords: kbenv kbhowto KB186454
Technology: kbwin2000Pro kbwin2000ProSearch kbwin2000Search kbwin2000Serv kbwin2000ServSearch