Solved

Event messages

Posted on 2013-11-13
6
1,163 Views
Last Modified: 2013-11-20
Receiving a "ton" of annoying (looks like related event messages) on a Backup server: Windows 2008R2 / Backup Exec 2012 (RAM - 16GB, Swap File - 25GB)

#1

Event ID:1  
The backing-file for the real-time session "Eventlog-Security" has reached its
maximum size. As a result, new events will not be logged to this session until
space becomes available. This error is often caused by starting a trace session in
real-time mode without having any real-time consumers.

#2

EventTracker Alert - 11/12/13, 23:04:37
Alert Name: Audit event records discarded

Event Time: 2013-11-12 23:03:24.
Type: AuditOK.
Computer: BACKUP
Source: Microsoft-Windows-Security-Auditing
EvtID: 4612
User: N/A\N/A
Descr: Internal resources allocated for the queuing of audit messages have been exhausted, leading to the loss of some audits.

Number of audit messages discarded:      12623

This event is generated when audit queues are filled and events must be discarded.  This most commonly occurs when security events are being generated faster than they are being written to disk, or when the auditing system loses connectivity to the event log, such as when the event log service is stopped.


How to eliminate it?

Thank you
0
Comment
Question by:cohhelp
  • 3
  • 3
6 Comments
 
LVL 12

Expert Comment

by:Sommerblink
ID: 39645896
You have too much auditing enabled on your filesystem. So much in fact that even Windows can't keep up with it when your backup process is underway.

What is audited is located under the Advanced Security settings for the folder, drive, whathaveyou. It behaves in the same way that NTFS permissions do.

In order to see what is being audited, you will need to go to the folder or drive in question, right click on it, go to properties. Then go to the Security tab, then click on the Advanced button at the bottom. Then click on the Auditing tab and check what is audited there.

Seems like you have a lot of Success auditing going on based on the limited info in the event log. Perhaps you need to refine what is audited so that not so much noise is generated.
0
 

Author Comment

by:cohhelp
ID: 39645935
Rechecked all drives, nothing is set for audit.
0
 
LVL 12

Expert Comment

by:Sommerblink
ID: 39645963
Can you go through your Security log and see what is at least making it to the security log there and then double-check those files for their auditing behavior.

It is also possible that the logs are being shipped to that computer from another computer.
0
PRTG Network Monitor: Intuitive Network Monitoring

Network Monitoring is essential to ensure that computer systems and network devices are running. Use PRTG to monitor LANs, servers, websites, applications and devices, bandwidth, virtual environments, remote systems, IoT, and many more. PRTG is easy to set up & use.

 

Author Comment

by:cohhelp
ID: 39655043
we were expecting step-by-step "fix", but ... got just general concepts
0
 
LVL 12

Accepted Solution

by:
Sommerblink earned 500 total points
ID: 39660169
Of course. This is how things are solved, on a case-by-case basis.

There is no one-webpage-fixes-all for your case. If that were so, you could simply use google to solve the problem.
0
 

Author Closing Comment

by:cohhelp
ID: 39662906
none
0

Featured Post

Problems using Powershell and Active Directory?

Managing Active Directory does not always have to be complicated.  If you are spending more time trying instead of doing, then it's time to look at something else. For nearly 20 years, AD admins around the world have used one tool for day-to-day AD management: Hyena. Discover why

Question has a verified solution.

If you are experiencing a similar issue, please ask a related question

Suggested Solutions

Title # Comments Views Activity
Determine if SQL is installed in Server 2008 R2 4 77
windows 10 versions 3 33
Inactive computer in domain 7 58
Group Policy Mapped Drives - Work Offline? 7 23
Normally after a failure of Domain Controller, when promoting new DC the DC is renamed, we will discuss the options in Dcpromo to re-create the DC with the same name. Scenario: You are a small IT shop with two Domain Controllers (Domain Contr…
New Windows 7 Installations take days for Windows-Updates to show up and install. This can easily be fixed. I have finally decided to write an article because this seems to get asked several times a day lately. This Article and the Links apply to…
This tutorial will give a an overview on how to deploy remote agents in Backup Exec 2012 to new servers. Click on the Backup Exec button in the upper left corner. From here, are global settings for the application such as connecting to a remote Back…
This tutorial will walk an individual through setting the global and backup job media overwrite and protection periods in Backup Exec 2012. Log onto the Backup Exec Central Administration Server. Examine the services. If all or most of them are stop…

786 members asked questions and received personalized solutions in the past 7 days.

Join the community of 500,000 technology professionals and ask your questions.

Join & Ask a Question