Hello, friends. Sorry for the long absence.
Windows Event Logs are located in C:\Windows\System32\winevt\Logs.
And 'System>Windows Event Trace Logs' has different paths in winsys.ini:
FileKey1=%windir%\Logs|*.etl|RECURSE
FileKey2=%CommonAppData%\USOShared\Logs\User|*.ETL
lmacri, no, this setting doesn't affect Event Logs cleaning. And the setting for 24 hours is cleared in my config.
So, I always have only these 5 Event Logs cleared:
Application.evtx
HardwareEvents.evtx
Internet Explorer.evtx
Key Management Service.evtx
OAlerts.evtx
among 356 Event Logs in my C:\Windows\System32\winevt\Logs.
Could anybody confirm or deny such behavior on his computer?