drop system evtx csv or registry · MaxSize Retention · 1104 log full · 104 clear · retention window · csv export · runs locally
HKLM\EventLog MaxSize/Retention · Security 1104/1105 · System 104
drop system/security evtx csv or eventlog .reg export