<?xml version="1.0" encoding="UTF-8" ?>
<?xml-stylesheet type="text/xsl" href="http://blogs.msdn.com/utility/FeedStylesheets/rss.xsl" media="screen"?><rss version="2.0" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:slash="http://purl.org/rss/1.0/modules/slash/" xmlns:wfw="http://wellformedweb.org/CommentAPI/"><channel><title>Tip of the Day: Moving Event Viewer logs to an unprotected volume</title><link>http://blogs.msdn.com/embedded/archive/2008/08/25/tip-of-the-day-moving-event-viewer-logs-to-an-unprotected-volume.aspx</link><description>This tip is applicable to Enhanced Write Filter (EWF-RAM) users. To move Event Viewer logs to a volume unprotected by EWF, modify the following three registry keys as shown in the following example. The example uses drive D as the unprotected volume.</description><dc:language>en-US</dc:language><generator>CommunityServer 2.1 SP1 (Build: 61025.2)</generator><item><title>What is happening at Microsoft?</title><link>http://blogs.msdn.com/embedded/archive/2008/08/25/tip-of-the-day-moving-event-viewer-logs-to-an-unprotected-volume.aspx#8917166</link><pubDate>Mon, 01 Sep 2008 20:47:22 GMT</pubDate><guid isPermaLink="false">91d46819-8472-40ad-a661-2c78acb4018c:8917166</guid><dc:creator>Architecture &amp; Stuff</dc:creator><description>&lt;p&gt;I don't ordinarily just copy stuff that someone else sends me into my blog, but this is an exception.&amp;amp;#160;&lt;/p&gt;
</description></item></channel></rss>