Security Audit 560 Filling Security Log
i have following event literally thousands of times on exchange server:
winevtlog: security: audit_failure(560): security: system: nt authority: servername: object open: object server: security object type: key object name: \registry\machine\software\microsoft\windows nt\currentversion\perflib handle id: - operation id: {0,3015636319} process id: 4976 image file name: c:\windows\system32\wbem\wmiprvse.exe primary user name: network service primary domain: nt authority primary logon id: (0x0,0x3e4) client user name: servername$ client domain: domain client logon id: (0x0,0x3e7) accesses: %%1542 %%1543 privileges: - restricted sid count: 0 access mask: 0x3000000
my question 2 part based on information above; a) access viloation should concerned with? b) if not serious how should go @ least eliminating event? thanks.
al
Windows Server > Security
Comments
Post a Comment