In addition to viewing the details about previously defined jobs, use the Purge and Archive page to define and schedule new jobs, and edit, disable/enable or delete existing jobs.
Before scheduling a job, ensure that you have reviewed the best practice information in Planning your jobs.
2 |
Click Add to open the Purge and Archive wizard. |
All events: Select this option to purge all events from the database that are older than the specified time.
Only selected events: Select this option to purge only selected events, based on specific criteria, from the database that are older than the specified time.
Use the criteria tabs to define the events to be deleted:
Who - purge events generated by a specific user, computer, group, or service account.
What - purge events based on subsystem, event class, object class, severity or results.
Where - purge events captured by a specific agent, domain or site.
Origin - purge events originating from a specific workstation or server.
See Purge selected records for a description of the criteria options.
6 |
Select Archive events if you want to create an archive database. A yearly archive database will be created beginning on the first day of the selected month. For example, if you select Jan, the database will contain events for 12 months beginning on January 1. |
If you have also selected to purge events based on specific criteria, any events that remain will be moved to the archive database.
9 |
Click Finish to save the job and exit the wizard. |
2 |
Click Edit to open the Purge and Archive wizard. |
4 |
Click Finish to save your selections and exit the wizard. |
When a job is disabled, that particular database cleanup job will not take place until it is re-enabled.
Use the criteria tabs in the Purge and Archive wizard to define what specific records are to be deleted from the database. These tabs are enabled when you choose the Purge | Only selected events option.
Use the Who tab when you want to purge or archive events generated by specific users, computers, groups, or service accounts. By default (when the Who tab is empty), change events generated by all users, computers, groups, and service accounts will be deleted from the database or archived.
When multiple ‘who’ criteria is specified on this tab, Change Auditor uses the ‘OR’ operator to evaluate change events, purging or archiving events for activity performed by any of the users, computers, groups, or service accounts listed on this tab.
Repeat this step to include each additional directory object.
|
NOTE: Use Add with Events (instead of Add) to select users, computers, groups, or service accounts that already have an event associated with it in the database. Use this to purge events tied to users who have been removed from Active Directory. |
Change Auditor now purges or archives events generated by the users, computers, groups, or service accounts listed on the Who tab.
|
NOTE: If you used Add With Events instead, click Add Wildcard Expression on the Add Users, Computer, or Groups dialog. |
|
NOTE: When using the Group option, the Group Membership Expansion option on the Coordinator Configuration page (on the Administration Tasks tab) must be set to Expand all groups. |
4 |
Click OK to close the dialog and add the wildcard expression to the Who tab. |
Change Auditor now searches for and purges or archives change events generated by the users that are members of the groups whose name matches the specified wildcard expression.
Use the What tab to specify the what criteria to be used to determine whether an event is to be purged from the database. By default (when the What tab is empty), all events regardless of the subsystem, event class, object class, severity, or results will be purged or archived.
When multiple ‘what’ criteria is specified on this tab, Change Auditor uses the ‘AND’ operator to evaluate an event, purging only those events that meet all the specified criteria. However, when multiple subsystems (such as Active Directory, ADAM, and Exchange) are specified, Change Auditor uses the ‘OR’ operator to evaluate these entities, purging or archiving events that meet any of the specified subsystem criteria. This also applies when multiple event classes are specified. That is, when multiple event classes are specified, Change Auditor uses the ‘OR’ operator purging or archiving any of the specified events.
2 |
Open the What tab, expand Add (or Add With Events) and select the appropriate option. When you select an option, an additional dialog appears allowing you to enter specific criteria: |
4 |
Click OK to save your selection and close the dialog. |
Change Auditor now searches for and purges or archives change events that match the criteria listed on the What tab.
Use the Where tab to purge events captured by specific agents, domains, or sites. By default (when the Where tab is empty), events captured by all agents will be purged or archived.
When multiple ‘where’ criteria is added to this tab, Change Auditor uses the ‘OR’ operator to evaluate events, purging or archiving events that were captured by any of the specified agents, domains or sites.
Once you have located an agent, domain or site, select it and click Add to add it to the selection list at the bottom of the dialog.
Repeat this step to include each additional agent, domain or site.
4 |
Click OK to save your selection and close the dialog. |
|
NOTE: Use Add With Events (instead of Add) to select agents, domains, or sites that already have an event associated with it in the database. |
Change Auditor now searches for and purges or archives change events captured by the agents, domains, or sites listed on the Where tab.
|
NOTE: If you used Add With Events instead, click Add Wildcard Expression on the Add Agents, Domains, Sites dialog. |
4 |
Click OK to close the dialog and add the wildcard expression to the Where tab. |
Change Auditor now searches for and purges or archives change events captured by the agent(s), domains or sites whose name matches the specified wildcard expression.
3 |
Click OK to close the dialog and add the server type to the ‘Where’ list. |
When this purge job runs, Change Auditor searches for and purges events generated on the specified domains, sites, or agents for the specified server type.
Use the Origin tab to purge events originating from a specific workstation or server. By default, (when the Origin tab is empty) events will be purged regardless of the workstation or server from which they originated.
When multiple ‘origin’ criteria is specified on this tab, Change Auditor uses the ‘OR’ operator to evaluate events, purging or archiving events originating from any of the specified workstations or servers.
4 |
Click OK to close the dialog and add the wildcard expression to the Origin tab. |
The Add Origin dialog appears populated with originating workstations/servers that have an event associated with it in the Change Auditor database.
|
NOTE: Use Add Wildcard Expression to enter a wildcard expression to include workstations/servers from this list based on their NetBIOS name or IP address. |
4 |
Click OK to close the dialog and add the selected workstations to the Origin tab. |
Change Auditor now searches for and purges or archives change events originating from the selected workstations/servers.