Solved

How to stop the Security Log being flooded with Event ID 577?

Posted on 2013-12-16
3
1,387 Views
Last Modified: 2013-12-31
I'm running Windows Server 2003 with a Cluster File Service.
The security log is being flooded with Failure Audit Event ID 577 entries.

Example:
When a user opens a folder on the network drive on this server it creates about 80 exact same log entries at once:

Event Type:      Failure Audit
Event Source:      Security
Event Category:      Privilege Use
Event ID:      577
Date:            16.12.2013
Time:            11:30:31
User:            DOMAIN\USER
Computer:      SERVERNAME
Description:
Privileged Service Called:
       Server:            Security
       Service:            -
       Primary User Name:      SERVERNAME$
       Primary Domain:      DOMAIN
       Primary Logon ID:      LOGONID
       Client User Name:      USER
       Client Domain:      DOMAIN
       Client Logon ID:      LOGONID
       Privileges:      SeBackupPrivilege

For more information, see Help and Support Center at http://go.microsoft.com/fwlink/events.asp.


The local policies are Setup as below and can't be changed as set by the Domain:
Security Option: Audit the use of Backup and Restore privilege - Enabled
Audit Policy: Audit privilege use - Success and Failure
0
Comment
Question by:da2loo
  • 2
3 Comments
 
LVL 14

Accepted Solution

by:
BlueCompute earned 500 total points
ID: 39721865
Audit Policy: Audit privilege use - Success and Failure

SO you've turned your auditing up too high and now you can't see the wood for the trees.  It's similar to the scenario described in this old KB: http://support.microsoft.com/kb/264769

You can't delete events from the security log, and you've indicated that you are unable to remove the auditing.  Therefore you cannot prevent your log filling up with these entries.
0
 

Author Comment

by:da2loo
ID: 39722670
I understand that the Security log will always keep filling up when having the audit privilege use policy enabled, however, the amount being logged seems odd. There's not even space for an entire day of security logs in the 400 MB log file.

One user opening one folder produces 80 event log entries with the exactly same information all at once, is this normal with these policies enabled?

Any idea what could cause all normal users accessing the files/folders on the server attempting to use SeBackupPrivilege in the first place?
0
 
LVL 14

Expert Comment

by:BlueCompute
ID: 39722698
0

Featured Post

How to run any project with ease

Manage projects of all sizes how you want. Great for personal to-do lists, project milestones, team priorities and launch plans.
- Combine task lists, docs, spreadsheets, and chat in one
- View and edit from mobile/offline
- Cut down on emails

Join & Write a Comment

Remote Apps is a feature in server 2008 which allows users to run applications off Remote Desktop Servers without having to log into them to run the applications.  The user can either have a desktop shortcut installed or go through the web portal to…
On July 14th 2015, Windows Server 2003 will become End of Support, leaving hundreds of thousands of servers around the world that still run this 12 year old operating system vulnerable and potentially out of compliance in many organisations around t…
In this video, we discuss why the need for additional vertical screen space has become more important in recent years, namely, due to the transition in the marketplace of 4x3 computer screens to 16x9 and 16x10 screens (so-called widescreen format). …
With the advent of Windows 10, Microsoft is pushing a Get Windows 10 icon into the notification area (system tray) of qualifying computers. There are many reasons for wanting to remove this icon. This two-part Experts Exchange video Micro Tutorial s…

757 members asked questions and received personalized solutions in the past 7 days.

Join the community of 500,000 technology professionals and ask your questions.

Join & Ask a Question

Need Help in Real-Time?

Connect with top rated Experts

23 Experts available now in Live!

Get 1:1 Help Now