Autologger\EventLog中EnableLevel的工作机制及过滤事件的配置验证问询
Hey Jeff, great question—let's walk through this step by step to confirm if your configuration will work, and clear up any confusion around how EnableLevel operates.
First off: Yes, setting EnableLevel=dword:00000002 will exactly do what you want—filter out Warning events, and only keep Critical and Error-level events in your target System Log.
Here's the breakdown of how this works, based on Microsoft's official definitions for the EnableLevel values:
| Value (Hex) | Decimal Value | Level Name | Meaning |
|---|---|---|---|
| 00000001 | 1 | TRACE_LEVEL_CRITICAL | Abnormal exit or termination events (most severe) |
| 00000002 | 2 | TRACE_LEVEL_ERROR | Severe error events |
| 00000003 | 3 | TRACE_LEVEL_WARNING | Warning events like resource allocation failures |
| 00000004 | 4 | TRACE_LEVEL_INFORMATION | Non-error informational events |
| 00000005 | 5 | TRACE_LEVEL_VERBOSE | Detailed diagnostic events (most granular, least critical) |
When you set EnableLevel to 00000002 (decimal 2), the Autologger will only capture events with a level less than or equal to 2. That means Critical (1) and Error (2) events get logged, while Warning (3), Information (4), and Verbose (5) events are excluded—perfect for your use case.
I totally get your frustration about verifying this, since the Warning events you're targeting are random and infrequent. A couple of quick ways to test the configuration:
- Manually trigger an Error-level event (for example, disable a critical system service and restart it—Windows will almost always log an Error event for this) and confirm it shows up in your log.
- Back up your current registry key first, then apply the
EnableLevel=2 change. Over time, compare the volume and type of events logged against your baseline (when it was set to 0, logging everything) to spot the absence of Warning events.
Just to confirm, your example registry configuration is correct:
[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\WMI\Autologger\EventLog-System\{1c95126e-7eea-49a9-a3fe-a378b03ddb4d}] "EnableLevel"=dword:00000002 ; Default = 0, everything is logged
As long as you're modifying the correct Autologger key for your target System Log, this setting will take effect as expected.
备注:内容来源于stack exchange,提问作者Jeff

