Skip to content

Explain native provider archival permissions and error 267 - #147

Merged
PrzemyslawKlys merged 1 commit into
masterfrom
docs/archive-resource-permissions
Oct 5, 2026
Merged

PrzemyslawKlys merged 1 commit into
masterfrom
docs/archive-resource-permissions

Conversation

@PrzemyslawKlys

Copy link
Copy Markdown
Member

Provider-resource archival can report Windows error 267 under an unelevated token even when the EVTX export itself succeeds. The same export and EventViewerX archive API succeed after elevation on the affected workstation.

The guide explains how to check the file and parent directory, retry Update-EVXLogArchive from an elevated terminal, and use wevtutil against an isolated copy to distinguish native Windows behavior from archive staging. This gives operators a practical diagnostic path before changing provider registration, permissions, or the Event Log service.

Validation: direct wevtutil and managed EventLogArchive.ArchiveResources comparisons retained the two-record export and produced its MTA companion after elevation. No service or system configuration changes were required.

@PrzemyslawKlys
PrzemyslawKlys merged commit 27db031 into master Oct 5, 2026
14 checks passed
@PrzemyslawKlys
PrzemyslawKlys deleted the docs/archive-resource-permissions branch October 5, 2026 10:51
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant