Do you know if you have the Enterprise Log Manager (ELM) as part of your solution? If so, this is where your raw logs will be stored (whereas the ESM stores parsed/normalized/correlated events). You can access them via the ESM in a couple of ways. First, from the ELM Archive tab for a specific event:
This tab will only be available if you are logging the events to the ELM. Second place is the Advanced ELM search:
Third place is from the ELM System Properties which allows the same searching as the Advanced ELM Search view with the addition of integrity checks.
Hopefully this answers your questions.
Thank you very much! I actually found method number 2 on my own maybe 20 minutes before you responded, and I appreciate the response and confirmation that this is the correct way to do it. The raw logs are displayed in a bit of jumbled fashion, but I don't care. The necessary information is present to meet out log retention policy, and I typically have to "pretty up and dumb down" the info when it's sent up to management anyway.
As for the other two methods, I was unaware of those. I appreciate your help Kara!