Windows 10: Excessive Security Log Events - Event ID 5379 - Windows 10

Discus and support Excessive Security Log Events - Event ID 5379 - Windows 10 in Windows 10 BSOD Crashes and Debugging to solve the problem; I have been experiencing Windows Application crashes on my 3 month old Windows 10 install. While troubleshooting, I noticed that there 50+ security... Discussion in 'Windows 10 BSOD Crashes and Debugging' started by digitalJE5U5, Apr 26, 2020.

  1. Excessive Security Log Events - Event ID 5379 - Windows 10


    I have been experiencing Windows Application crashes on my 3 month old Windows 10 install. While troubleshooting, I noticed that there 50+ security events each minute in the Event Viewer under Windows Logs > Security.


    Is this normal?


    The majority are Audit Success Messages with the Event ID 5379. There are approximately 50 of these identical messages every minute. Thanks for any insight on this.


    See below for typical Message:


    Credential Manager credentials were read.


    Subject:

    Security ID: DESKTOP\*****

    Account Name: *****

    Account Domain: DESKTOP

    Logon ID: 0x354889

    Read Operation: Enumerate Credentials



    This event occurs when a user performs a read operation on stored credentials in Credential Manager.

    :)
     
    digitalJE5U5, Apr 26, 2020
    #1
  2. Techie_DD Win User

    Windows 10 workstation Security log filling with Event ID 4703

    My Windows 10 workstation's Security Event Log is filled with informational Event ID 4703 (like 20/second).

    It's an Audit Success on Authorization Policy Change category.

    Pretty much all are about the javaw.exe process & SeSecurityPrivilege. But also a few of them list svchost.exe as the process & a whole list of privileges.

    I can't find anything on the Net about event 4703.

    Sometimes it lists the privilege as Disabled (as below), and some are Enabled. Back & forth, multiple events per second.

    Does anyone have any idea what/why this is, or anyone else experiencing it?

    Here are the details of the event (edited for privacy)...

    Task Category: Authorization Policy Change

    Level: Information

    Keywords: Audit Success

    User: N/A

    Computer: xxxxx.yyyy.com

    Description:

    A user right was adjusted.

    Subject:

    Security ID: SYSTEM

    Account Name: XXXXXX

    Account Domain: YYYYYYYY

    Logon ID: 0x3E7

    Target Account:

    Security ID: SYSTEM

    Account Name: XXXXXXX

    Account Domain: YYYYYYYYY

    Logon ID: 0x3E7

    Process Information:

    Process ID: 0xb24

    Process Name: C:\Windows\SysWOW64\ContegoSPOP\jre1.7.0_65\bin\javaw.exe

    Enabled Privileges:

    -

    Disabled Privileges:

    SeSecurityPrivilege
     
    Techie_DD, Apr 26, 2020
    #2
  3. Event ID 7036 not showing in Windows Event Log on Win10

    It looks like 7036 event is missing from Windows desktop OS (starting from 8).
    However you can monitor process termination:

    1. Enable Audit Policy to audit process tracking:

    1. Check for event 4689 in Security Event Log

    Alternatively you may try this solution.

    But in this case, you will get event 4546 not only when the service starts or stops, but whenever something is trying to access it (e.g. when Services applet is open).
     
    Michael Karsyan, Apr 26, 2020
    #3
  4. Excessive Security Log Events - Event ID 5379 - Windows 10

    Event viewer error with event id 10016

    Hello,

    Thank you for posting your query on Microsoft Community forum.

    I understand that you are getting an error “DistributedCOM 10016” in the event viewer logs.

    • Do you face any issues on the computer?
    • Have you made any recent changes to the computer?
    This problem may occur if either of the following conditions is true:

    • A program with the class ID (CLSID) that appears in the message tries to start the COM component by using the DCOM infrastructure. However, the user does not have the required permissions to start the COM component.

    • The Network Service account does not have the correct permissions.

    Event logs are special files that record significant events on your computer, such as when a user logs on to the computer or when a program encounters an error. Whenever these types of events occur, Windows records the event in
    an event log that you can read by using Event Viewer. Advanced users might find the details in event logs helpful when troubleshooting problems with Windows and other programs.

    If you do not have any issues with app or any other program I would suggest you to ignore it.

    Keep us posted if you face any issues related to Windows in future. We will be glad to help you.
     
    Rakesh Narayanaswamy, Apr 26, 2020
    #4
Thema:

Excessive Security Log Events - Event ID 5379 - Windows 10

Loading...
  1. Excessive Security Log Events - Event ID 5379 - Windows 10 - Similar Threads - Excessive Security Log

  2. I am getting excessive User Account Management Event ID 5379 on startup

    in Windows 10 Gaming
    I am getting excessive User Account Management Event ID 5379 on startup: This causes all user activity to be prevented on start-up. This takes minutes to clear before user programs will run.No viruses or disk activity problems found. But disc activity sometimes exceeds 100%!Event log finds excessive continuous Event ID 5379.Log is as follow and...
  3. I am getting excessive User Account Management Event ID 5379 on startup

    in Windows 10 Software and Apps
    I am getting excessive User Account Management Event ID 5379 on startup: This causes all user activity to be prevented on start-up. This takes minutes to clear before user programs will run.No viruses or disk activity problems found. But disc activity sometimes exceeds 100%!Event log finds excessive continuous Event ID 5379.Log is as follow and...
  4. I am getting excessive User Account Management Event ID 5379 on startup

    in Windows 10 BSOD Crashes and Debugging
    I am getting excessive User Account Management Event ID 5379 on startup: This causes all user activity to be prevented on start-up. This takes minutes to clear before user programs will run.No viruses or disk activity problems found. But disc activity sometimes exceeds 100%!Event log finds excessive continuous Event ID 5379.Log is as follow and...
  5. Mouse disconnects when event id 5379 appears in event viewer

    in Windows 10 Ask Insider
    Mouse disconnects when event id 5379 appears in event viewer: I've had this issue for about a month and have been able to see a popup of event id 5379 in event viewer at the exact timestamp of when the mouse disconnects. Sometimes there is like 40 of the id 5379 spammed in a row and my mouse is frozen for like 3 sec. Been unable to play...
  6. Excessive "Audit Success" log events for event ID 5061 and 5058

    in Windows 10 Gaming
    Excessive "Audit Success" log events for event ID 5061 and 5058: I'm getting these 2 event IDs logged every 5 seconds in my Security log on Windows 11 Pro.This seems excessive. Also unsure why this is happening like clockwork, regardless what I'm doing on my laptop.Anyone else seeing this? Wondering whether I can/need to update my Audit...
  7. Excessive "Audit Success" log events for event ID 5061 and 5058

    in Windows 10 Software and Apps
    Excessive "Audit Success" log events for event ID 5061 and 5058: I'm getting these 2 event IDs logged every 5 seconds in my Security log on Windows 11 Pro.This seems excessive. Also unsure why this is happening like clockwork, regardless what I'm doing on my laptop.Anyone else seeing this? Wondering whether I can/need to update my Audit...
  8. Event Log > Security Event ID 5156 and 5158 filling it up

    in Windows 10 Gaming
    Event Log > Security Event ID 5156 and 5158 filling it up: I am trying to use a Powershell scanner in PDQ Inventory which runs a PS1 and enter the returning data into the asset that scans the Security log for log on and log off events. The script then enters the data into that asset which allows us to see who has been using it and...
  9. Event Log > Security Event ID 5156 and 5158 filling it up

    in Windows 10 Software and Apps
    Event Log > Security Event ID 5156 and 5158 filling it up: I am trying to use a Powershell scanner in PDQ Inventory which runs a PS1 and enter the returning data into the asset that scans the Security log for log on and log off events. The script then enters the data into that asset which allows us to see who has been using it and...
  10. Event Log > Security Event ID 5156 and 5158 filling it up

    in Windows 10 Customization
    Event Log > Security Event ID 5156 and 5158 filling it up: I am trying to use a Powershell scanner in PDQ Inventory which runs a PS1 and enter the returning data into the asset that scans the Security log for log on and log off events. The script then enters the data into that asset which allows us to see who has been using it and...

Users found this page by searching for:

  1. Win10 security log

    ,
  2. windows 10 event 5379

    ,
  3. audit success yoo many 5379

    ,
  4. event id 5379 flood,
  5. windows event 5379 target name,
  6. Event ID 5379 Enumerate Credentials,
  7. event viewere has hundfrrds of events,
  8. windows 10 login event iD 5379