Niveau d’enregistrement des événements
Vérifié avec Windows 11 25H2 — mis à jour le 30 juillet 2026
Pris en charge sur : Windows Server 2003, Windows XP et Windows 2000 uniquement
Chemin dans la console GPO
Configuration ordinateur\Modèles d'administration\Réseau\Fichiers hors connexion Description
Détermine les événements que la fonctionnalité Fichiers hors connexion enregistre dans le journal des événements. La fonctionnalité Fichiers hors connexion enregistre les événements dans le journal d’application de l’Observateur d’événements lorsque des erreurs sont détectées. Par défaut, la fonctionnalité Fichier hors connexion n’enregistre un événement que si le cache du stockage des fichiers hors connexion est endommagé. Vous pouvez toutefois utiliser ce paramètre pour spécifier les événements supplémentaires que vous voulez que la fonctionnalité Fichiers hors connexion enregistre. Pour utiliser ce paramètre, dans la zone « Entrée », sélectionnez le numéro correspondant aux événements que vous voulez que le système enregistre. Les niveaux sont cumulatifs, c’est-à-dire que chaque niveau inclut les événements de tous les niveaux précédents. « 0 » enregistre une erreur quand le cache du stockage hors connexion est endommagé. « 1 » enregistre en plus un événement quand le serveur qui héberge le fichier hors connexion est déconnecté du réseau. « 2 » enregistre en plus des événements quand l’ordinateur local est connecté et déconnecté du réseau. « 3 » enregistre en plus un événement quand le serveur qui héberge le fichier hors connexion est reconnecté au réseau. Remarque : ce paramètre apparaît dans les dossiers Configuration ordinateur et Configuration utilisateur. Si les deux paramètres sont configurés, le paramètre dans Configuration ordinateur est prioritaire sur le paramètre dans Configuration utilisateur.
Registre
Software\Policies\Microsoft\Windows\NetCache MDM / Intune (CSP)
./Device/Vendor/MSFT/Policy/Config/ADMX_OfflineFiles/Pol_EventLoggingLevel_2 Documentation Microsoft Learn Données de correspondance : Microsoft Learn (CC BY 4.0)
Générateur d'exports
BETAConfigurez l'état, la portée et les options, puis générez les sorties .reg, PowerShell, Intune et SCCM — ou ajoutez le paramètre à une collection multi-paramètres.
Ces exports écrivent le registre — ce n'est pas une GPO managée. ⓘ
Fichier .reg
Windows Registry Editor Version 5.00
; Exported from gporais.com
; Policy: Niveau d’enregistrement des événements
; State: Enabled
; Supported on: Windows Server 2003, Windows XP et Windows 2000 uniquement
[HKEY_LOCAL_MACHINE\Software\Policies\Microsoft\Windows\NetCache]
"EventLoggingLevel"=dword:00000000 Autres formats (PowerShell, Intune, SCCM)
PowerShell
# Exported from gporais.com
# Policy: Niveau d’enregistrement des événements
# State: Enabled
# Supported on: Windows Server 2003, Windows XP et Windows 2000 uniquement
$path = 'HKLM:\Software\Policies\Microsoft\Windows\NetCache'
New-Item -Path $path -Force | Out-Null
Set-ItemProperty -Path $path -Name 'EventLoggingLevel' -Value 0 -Type DWord Intune XML
OMA-URI: ./Device/Vendor/MSFT/Policy/Config/ADMX_OfflineFiles/Pol_EventLoggingLevel_2
Data type: String
Value:
<enabled/>
<data id="Lbl_EventLoggingLevelSpin" value="0"/> Intune Remediation
# === Detection script ===
# Exported from gporais.com
# Policy: Niveau d’enregistrement des événements
# State: Enabled
# Supported on: Windows Server 2003, Windows XP et Windows 2000 uniquement
function Test-RegistryValue {
param(
[Parameter(Mandatory = $true)][string]$Path,
[Parameter(Mandatory = $true)][string]$Name,
[object]$Expected,
[ValidateSet('String', 'DWord', 'MultiString')][string]$Kind = 'String',
[switch]$Absent
)
try {
$item = Get-ItemProperty -LiteralPath $Path -Name $Name -ErrorAction Stop
} catch {
return $Absent.IsPresent
}
if ($Absent.IsPresent) { return $false }
$actual = $item.$Name
if ($Kind -eq 'DWord') { return ([int64]$actual) -eq ([int64]$Expected) }
if ($Kind -eq 'MultiString') {
$actualValues = @($actual)
$expectedValues = @($Expected)
if ($actualValues.Count -ne $expectedValues.Count) { return $false }
for ($i = 0; $i -lt $expectedValues.Count; $i++) {
if ([string]$actualValues[$i] -ne [string]$expectedValues[$i]) { return $false }
}
return $true
}
return [string]$actual -eq [string]$Expected
}
$checks = @(
(Test-RegistryValue -Path 'HKLM:\Software\Policies\Microsoft\Windows\NetCache' -Name 'EventLoggingLevel' -Expected 0 -Kind DWord)
)
if ($checks -notcontains $false) {
Write-Output 'Compliant'
exit 0
}
Write-Output 'Non-compliant'
exit 1
# === Remediation script ===
# Exported from gporais.com
# Policy: Niveau d’enregistrement des événements
# State: Enabled
# Supported on: Windows Server 2003, Windows XP et Windows 2000 uniquement
$path = 'HKLM:\Software\Policies\Microsoft\Windows\NetCache'
New-Item -Path $path -Force | Out-Null
Set-ItemProperty -Path $path -Name 'EventLoggingLevel' -Value 0 -Type DWord Scripts SCCM
# Exported from gporais.com
# Policy: Niveau d’enregistrement des événements
# State: Enabled
# Supported on: Windows Server 2003, Windows XP et Windows 2000 uniquement
# SCCM Configuration Item guidance:
# Create a Configuration Item of type "Setting: Script".
# Discovery script: use the Detection script below.
# Remediation script: use the Remediation script below.
# Compliance rule: the Discovery script output equals 'Compliant'.
# === Detection script ===
# Exported from gporais.com
# Policy: Niveau d’enregistrement des événements
# State: Enabled
# Supported on: Windows Server 2003, Windows XP et Windows 2000 uniquement
function Test-RegistryValue {
param(
[Parameter(Mandatory = $true)][string]$Path,
[Parameter(Mandatory = $true)][string]$Name,
[object]$Expected,
[ValidateSet('String', 'DWord', 'MultiString')][string]$Kind = 'String',
[switch]$Absent
)
try {
$item = Get-ItemProperty -LiteralPath $Path -Name $Name -ErrorAction Stop
} catch {
return $Absent.IsPresent
}
if ($Absent.IsPresent) { return $false }
$actual = $item.$Name
if ($Kind -eq 'DWord') { return ([int64]$actual) -eq ([int64]$Expected) }
if ($Kind -eq 'MultiString') {
$actualValues = @($actual)
$expectedValues = @($Expected)
if ($actualValues.Count -ne $expectedValues.Count) { return $false }
for ($i = 0; $i -lt $expectedValues.Count; $i++) {
if ([string]$actualValues[$i] -ne [string]$expectedValues[$i]) { return $false }
}
return $true
}
return [string]$actual -eq [string]$Expected
}
$checks = @(
(Test-RegistryValue -Path 'HKLM:\Software\Policies\Microsoft\Windows\NetCache' -Name 'EventLoggingLevel' -Expected 0 -Kind DWord)
)
if ($checks -notcontains $false) {
Write-Output 'Compliant'
exit 0
}
Write-Output 'Non-compliant'
exit 1
# === Remediation script ===
# Exported from gporais.com
# Policy: Niveau d’enregistrement des événements
# State: Enabled
# Supported on: Windows Server 2003, Windows XP et Windows 2000 uniquement
$path = 'HKLM:\Software\Policies\Microsoft\Windows\NetCache'
New-Item -Path $path -Force | Out-Null
Set-ItemProperty -Path $path -Name 'EventLoggingLevel' -Value 0 -Type DWord Vous construisez une collection multi-paramètres ? Ajoutez ce paramètre et générez des exports combinés (.reg, PowerShell, GPO).