Event ID 577 & 578 are filling Security Event Logs

T

timcapp

We have quite a few windows 2000 SP4 systems running that are
continually logging event ID 577 and 578 to the Security Event log . I
understand that a workaround to this is to turn off the privilege use
auditing policy, but this is not possible due to security requirements.
Is anyone aware of a workaround/patch to resolve this issue? It is
causing the event logs to grow to an unmanageable size.

Thanks
Tim
 
S

Steven L Umbach

Privilege use will generate a ton of events in the security log. Review your
policy to see if you can possibly audit only failures instead of success and
failure. If that is not possible you will need to increase the size of the
security logs substantially. I know of no other workaround. -- Steve
 
R

Roger Abell

Also, review the accounts that are generating the event messages.
Often it is not that the privilege is actually being used, but that the
user token is being adjusted to reflect the privilege is granted.
Perhaps accounts are over-allocated rights ?? or individuals
should be using less privileged accounts for "normal" activities.
 
T

timcapp

Thanks for the advice. We currently are only logging audit policy
failures. Our log is growing on some systems by 2-5 MB a day, and
almost all of it is is due to this message. The other problem is that
we need to review these logs weekly, and this message is making that a
very difficult and time consuming process.

Thanks again.

Tim
 
R

Roger Abell

Which privilege is it mentioning ? which should be seen
at the end of the event log message.
 
S

Steven L Umbach

Hi Wilson.

I understand your frustration. I wish I knew a specific solution but I
don't. To say that Windows auditing is quirky would be an understatement.
You might try posting in the forums at the link below for Windows auditing
and security. --- Steve

http://www.auditingwindows.com/cms/index.php
 

Ask a Question

Want to reply to this thread or ask your own question?

You'll need to choose a username for the site, which only take a couple of moments. After that, you can post your question and our members will help you out.

Ask a Question

Top