Security Audit 560 Filling Security Log


i have following event literally thousands of times on exchange server:

winevtlog: security: audit_failure(560): security: system: nt authority: servername: object open:     object server: security     object type: key     object name: \registry\machine\software\microsoft\windows nt\currentversion\perflib     handle id: -     operation id: {0,3015636319}     process id: 4976     image file name: c:\windows\system32\wbem\wmiprvse.exe     primary user name: network service     primary domain: nt authority     primary logon id: (0x0,0x3e4)     client user name: servername$     client domain: domain     client logon id: (0x0,0x3e7)     accesses: %%1542     %%1543          privileges: -     restricted sid count: 0     access mask: 0x3000000   

my question 2 part based on information above; a) access viloation should concerned with? b) if not serious how should go @ least eliminating event?  thanks.

al

i have same question.  network service trying access wmiprvse.exe every second generates failure audit 560 in security log.  has know this.  can not find useful information anywhere.  error generated on windows server 2003 se sp2 exchange 6.5 server.  changing permissions, restarting services, modifying registry did not help.  2 can not ones experiencing this, put gray matter work , give clue.  thank you.


Windows Server  >  Security



Comments

Popular posts from this blog

some help on Event 540

WMI Repository 4GB limit - Win 2003 Ent Question

Event ID 1302 (error 1307) DFS replication service encountered an error while writing to the debug log file