Solved

Event messages

Posted on 2013-11-13
6
1,128 Views
Last Modified: 2013-11-20
Receiving a "ton" of annoying (looks like related event messages) on a Backup server: Windows 2008R2 / Backup Exec 2012 (RAM - 16GB, Swap File - 25GB)

#1

Event ID:1  
The backing-file for the real-time session "Eventlog-Security" has reached its
maximum size. As a result, new events will not be logged to this session until
space becomes available. This error is often caused by starting a trace session in
real-time mode without having any real-time consumers.

#2

EventTracker Alert - 11/12/13, 23:04:37
Alert Name: Audit event records discarded

Event Time: 2013-11-12 23:03:24.
Type: AuditOK.
Computer: BACKUP
Source: Microsoft-Windows-Security-Auditing
EvtID: 4612
User: N/A\N/A
Descr: Internal resources allocated for the queuing of audit messages have been exhausted, leading to the loss of some audits.

Number of audit messages discarded:      12623

This event is generated when audit queues are filled and events must be discarded.  This most commonly occurs when security events are being generated faster than they are being written to disk, or when the auditing system loses connectivity to the event log, such as when the event log service is stopped.


How to eliminate it?

Thank you
0
Comment
Question by:cohhelp
  • 3
  • 3
6 Comments
 
LVL 12

Expert Comment

by:Sommerblink
ID: 39645896
You have too much auditing enabled on your filesystem. So much in fact that even Windows can't keep up with it when your backup process is underway.

What is audited is located under the Advanced Security settings for the folder, drive, whathaveyou. It behaves in the same way that NTFS permissions do.

In order to see what is being audited, you will need to go to the folder or drive in question, right click on it, go to properties. Then go to the Security tab, then click on the Advanced button at the bottom. Then click on the Auditing tab and check what is audited there.

Seems like you have a lot of Success auditing going on based on the limited info in the event log. Perhaps you need to refine what is audited so that not so much noise is generated.
0
 

Author Comment

by:cohhelp
ID: 39645935
Rechecked all drives, nothing is set for audit.
0
 
LVL 12

Expert Comment

by:Sommerblink
ID: 39645963
Can you go through your Security log and see what is at least making it to the security log there and then double-check those files for their auditing behavior.

It is also possible that the logs are being shipped to that computer from another computer.
0
Maximize Your Threat Intelligence Reporting

Reporting is one of the most important and least talked about aspects of a world-class threat intelligence program. Here’s how to do it right.

 

Author Comment

by:cohhelp
ID: 39655043
we were expecting step-by-step "fix", but ... got just general concepts
0
 
LVL 12

Accepted Solution

by:
Sommerblink earned 500 total points
ID: 39660169
Of course. This is how things are solved, on a case-by-case basis.

There is no one-webpage-fixes-all for your case. If that were so, you could simply use google to solve the problem.
0
 

Author Closing Comment

by:cohhelp
ID: 39662906
none
0

Featured Post

Want to promote your upcoming event?

Are you going to an event? Are you going to be exhibiting at a tradeshow? Talking at a conference? Using a promotional banner in your email signature ensures that your organization’s most important contacts stay in the know and can potentially spread the word about the event.

Join & Write a Comment

Normally after a failure of Domain Controller, when promoting new DC the DC is renamed, we will discuss the options in Dcpromo to re-create the DC with the same name. Scenario: You are a small IT shop with two Domain Controllers (Domain Contr…
I was asked if I could set up a fax machine so that incoming faxes were delivered to people's Exchange inboxes and so that they could send faxes from their desktops without needing to print the document first.  I knew it was possible but I had no id…
This tutorial will show how to push an installation of Backup Exec to an additional server in both 2012 and 2014 versions of the software. Click on the Backup Exec button in the upper left corner. From here, select Installation and Licensing, then I…
This tutorial will walk an individual through the steps necessary to install and configure the Windows Server Backup Utility. Directly connect an external storage device such as a USB drive, or CD\DVD burner: If the device is a USB drive, ensure i…

706 members asked questions and received personalized solutions in the past 7 days.

Join the community of 500,000 technology professionals and ask your questions.

Join & Ask a Question

Need Help in Real-Time?

Connect with top rated Experts

16 Experts available now in Live!

Get 1:1 Help Now