A Windows event logging and collection baseline focused on finding balance between forensic value and optimising retention.