SharePoint 2016, Sharepoint 2013, Sharepoint 2010, Windows Server 2012, Sql Server 2012,2014,IIS, Active Directory,User Profile Service, Managed MetaData Service, Search Service, Topology, Web Application, IIS, Site collection, List, Library, PowerShell, office web app, Windows Authentication, NTLM, Kerberos, Saml, ADFS, Active Directory Import, MIM, SharePoint 2016 Central Admin – Monitoring – Configure diagnostic logging – SharePoint

SharePoint 2016 Central Admin – Monitoring – Configure diagnostic logging

When you click on the Configure diagnostic logging Link, you will be landed on diagnostic logging
page. This page will let you configure the diagnostic loggings (AKA ULS logs) for SharePoint farm.

Configure diagnostic logging
page’s direct link: /_admin/metrics.aspx

Logging is the key component of any application; a strong logging system helps both developers and administrators to troubleshoot the issues and fix them. Like other products from Microsoft, SharePoint also has strong logging systems which are called Unified Logging Service. In SharePoint, every event written into the Logs has an associated ID called Correlation ID. Many time this correlation id displayed in the error which makes administrator’s life easy to trace the error detail in the ULS log.

Microsoft improves the logging systems with every new release of SharePoint. In SharePoint, ULS is centralized logging location for system administrators and developers to look for detail about the issue. Regularly monitoring of the ULS logs provides the overall health of SharePoint, potential errors, and performance issues. ULS logs exist on every server in the SharePoint farm, it recorded all the all activity related to SharePoint.

After the SharePoint installation, Diagnostic logging configured with default settings which include the logging level, logs location, and a number of days of storage. It is highly recommended to change the default settings of the ULS logs after the initial configuration. There couple of settings which you have to configure.

Event Throttling

Events reports at two places, one is in standard windows Event Logs and second is trace logs which are also called ULS. The administrator can control the what severity level of an event report into the Event Log and trace log. The administrator can control it for a specific category or for all category. We should be careful when deciding the logging level to report if I verbose logging set then it will consume the disk space quickly.

Default setting gives you enough information to troubleshoot the issue but If you are in a situation where you need to enable the extra logging level then you can configure and once you identify the issue or fix it then reset it to default.

The default settings for all categories are as follows:

  • Event Log: Information
  • Trace Log: Medium Level

Following level are available to select.

  • Event Logs: None, Critical, Error, Warning, Information, Verbose
  • Trace Log: None, Unexpected, Monitorable, High, Medium, Verbose, VerboseEx

Logs Driver Location: It is very much important to change the default location of ULS logs, By default location of the ULS logs is “C:\program file\Common Files\Microsoft Shared\Web Server Extensions\15\LOGS“, which system drive. In a case, if verbose logging level enabled then it can quickly use all the storage on the drive which put the OS in risk and impact the performance of SharePoint. It is highly recommended to move the logs file to other than system drives. It is also recommended to use the high-speed connection to log drives, otherwise you may see some performance issue.

Event Log Flood Protection: If this option is enabled then it will prevent to writing many repetitive events in the logs. If an event occurs 5 times in 2 minutes then it will surpass the same event for next 2 minutes, it logged the summary of the event along with a number of times it repeats. It is highly recommended to enable this option.

Retention Period: This option will give you control on the number of days to store logs file. By default, it is set to 14 days but you can set it to as per your requirement. When logs file to reach its number of days restriction then it will remove old log files from the drive.

Restrict Disk Space: Disk space usage is set to unlimited. Logs files quickly consume the space on the disk, so sometimes it is better to restrict the overall size of the log file. When disk reaches the to its restriction then it will remove the old logs file. By default, this option is disabled, to provide an extra layer of protection.

Configure Diagnostic Logging.

In this section, we will configure the diagnostic logging for Access Service category (Critical for Event Log and Unexpected for trace log), also change the trace path logs to D:\logs and restriction for trace log disk usage.

  • Login to Central admin with account member of farm administrator group.
  • In the Event Throttling, check the Access Service category.
  • From Event Select
    • Critical for Event Log
    • Unexpected for trace log

  • Make Sure the Event Log Flood protection check box is checked
  • In Trace log section
    • Path: enter D:\logs
    • Number of Days to Store Log Files: Enter 10
    • Enable the Trace log disk space usage
    • enter the 1000 GB for maximum storage space for trace logs

    • Click OK.
    • Wait for configuration as This Shouldn’t take long

This will be configured the diagnostic logging settings.

If you enabled the higher logging level after troubleshooting, you have set it back to default.

  • You have to Select the Reset to the Default value for both Event and Trace log.
  • Leave all other settings as is and Click ok.

Note: to view the ULS logs in easily readable format, use the free ULS viewer tools which are available free from Microsoft. Download it from here:

You may also like...

Leave a Reply

Your email address will not be published. Required fields are marked *