Welcome to Experts Exchange

Add your voice to the tech community where 5M+ people, just like you, are talking about what matters.

  • Help others & share knowledge
  • Earn cash & points
  • Learn & ask questions
Solved

Security log filling up

Posted on 2013-01-15
7
111 Views
Last Modified: 2015-06-23
My server 2008r2 security log is filling up with over 6000 5145 and 5156 events every 30 seconds. What is happening?
0
Comment
Question by:daveschultz7777
7 Comments
 
LVL 17

Expert Comment

by:Kent Dyer
ID: 38781209
If am reading this correctly, this is in the Event Viewer..

What does your Event Viewer show when you open these up?

That is where I would start.

HTH,

Kent
0
 

Author Comment

by:daveschultz7777
ID: 38781230
Closer examination of the log shows 3 users (out of 35) are creating all the 5145 events. The 5145 events (Detailed File share) are followed by 5156 events (Filtering Platform Connection).
I don't know if they are related to each other. I suspect some virus activity may be causing the 5145 events. I won't know until tomorrow when I can get onsite.
0
 
LVL 25

Expert Comment

by:Tony Giangreco
ID: 38781234
It looks like someone is accessing a network share continously and it's taking so much ram and processor that it's causing registry problems.

Are you being hit by an virus from inside? or possibly an app that is stuck in a loop?

http://www.ultimatewindowssecurity.com/securitylog/encyclopedia/event.aspx?eventid=5145
0
PRTG Network Monitor: Intuitive Network Monitoring

Network Monitoring is essential to ensure that computer systems and network devices are running. Use PRTG to monitor LANs, servers, websites, applications and devices, bandwidth, virtual environments, remote systems, IoT, and many more. PRTG is easy to set up & use.

 

Accepted Solution

by:
daveschultz7777 earned 0 total points
ID: 38787009
I found the computer causing the the problem. Removed it from the network and everything returned to normal. It had a virus and is being cleaned.
0
 

Expert Comment

by:lanzone
ID: 38835483
0
 
LVL 34

Expert Comment

by:Seth Simmons
ID: 40845593
This question has been classified as abandoned and is closed as part of the Cleanup Program. See the recommendation for more details.
0

Featured Post

Optimizing Cloud Backup for Low Bandwidth

With cloud storage prices going down a growing number of SMBs start to use it for backup storage. Unfortunately, business data volume rarely fits the average Internet speed. This article provides an overview of main Internet speed challenges and reveals backup best practices.

Question has a verified solution.

If you are experiencing a similar issue, please ask a related question

Suggested Solutions

I have been working as System Administrators since 2003. I recently started working as a FreeLancer and was amazed to find out that very few people are taking full advantage of their Windows Server Machines. Microsoft Windows Server comes with so…
This article explains how to install and use the NTBackup utility that comes with Windows Server.
This tutorial will walk an individual through the steps necessary to enable the VMware\Hyper-V licensed feature of Backup Exec 2012. In addition, how to add a VMware server and configure a backup job. The first step is to acquire the necessary licen…
To efficiently enable the rotation of USB drives for backups, storage pools need to be created. This way no matter which USB drive is installed, the backups will successfully write without any administrative intervention. Multiple USB devices need t…

856 members asked questions and received personalized solutions in the past 7 days.

Join the community of 500,000 technology professionals and ask your questions.

Join & Ask a Question