Windows 10: WinRM Security - Event Logs

Discus and support WinRM Security - Event Logs in Windows 10 Software and Apps to solve the problem; Hi, could someone please take a look at the logs attached and tell me if it's possible to tell by the logs if anyone might have used WinRM on my... Discussion in 'Windows 10 Software and Apps' started by RooYu, Jan 6, 2023.

  1. RooYu Win User

    WinRM Security - Event Logs


    Hi, could someone please take a look at the logs attached and tell me if it's possible to tell by the logs if anyone might have used WinRM on my machine to gain unauthorized access? I use Windows 11 and I never set up WinRM to begin with. Thank you so much in advance.

    :)
     
    RooYu, Jan 6, 2023
    #1

  2. What's WinRM?

    Thank you very much for your response Ed.

    Is there any way to find out what could be the culprit of these entries? They seem to occur almost daily at random times.

    There are 4 events which keep repeating over and over again:


    Event 145: WSMan operation Enumeration started with resourceUri http://schemas.microsoft.com/wbem/ws...onfig/listener
    Event 254: Activity Transfer
    Event 161: The client cannot connect to the destination specified in the request. Verify that the service on the destination is running and is accepting requests. Consult the logs and documentation for the WS-Management service running on the destination, most commonly IIS or WinRM. If the destination is the WinRM service, run the following command on the destination to analyze and configure the WinRM service: "winrm quickconfig".
    Event 142: WSMan operation Enumeration failed, error code 2150858770
     
    ayylmao212, Jan 6, 2023
    #2
  3. VicImp Win User
    Unable to configure WinRM on domain user

    Hi everyone,

    I'm unable to configure WinRM on a domain computer. I have a simple domain with

    1) Windows server 2012

    2) A client running Windows 7

    If I try to run WinRM on the local Administrator, everything works fine, but if I switch to a domain user, than problems occured.

    For example, if i run winrm quickconfig in powershell as the domain Administrator, then I get:

    WinRM already is set up to receive requests on this machine.

    WSManFault

    Message = WinRM cannot process the request. The following error occured while using Negotiate authentication: An unknown security error occurred.

    Possible causes are:

    -The user name or password specified are invalid.

    -Kerberos is used when no authentication method and no user name are specified.

    -Kerberos accepts domain user names, but not local user names.

    -The Service Principal Name (SPN) for the remote computer name and port does not exist.

    -The client and remote computers are in different domains and there is no trust between the two domains.

    After checking for the above issues, try the following:

    -Check the Event Viewer for events related to authentication.

    -Change the authentication method; add the destination computer to the WinRM TrustedHosts configuration setting or use

    HTTPS transport.

    Note that computers in the TrustedHosts list might not be authenticated.

    -For more information about WinRM configuration, run the following command: winrm help config.

    Error number: -2144108387 0x8033809D

    An unknown security error occurred.

    When i run it as local admin, everything goes well.

    So, what am I missing?
     
    VicImp, Jan 6, 2023
    #3
  4. Amit_Sun Win User

    WinRM Security - Event Logs

    Events 4672 & 4624 Win 10 Freezes - special LOGON ?

    Hi,

    Thank you for writing to Microsoft Community Forums.

    1. Are you on a domain network?
    2. May I know the make and the model number of your system?

    The event logs you have provided seems to be the security logs that is generated when you login to your system. For more information on the event that was generated, you can check
    4672(S): Special privileges assigned to new logon.

    The Windows error logs will be located at Event Viewer > Windows Logs > System.

    Please follow the step below and check if it works for you.

    Step: Improve Windows 10 Performance.

    Try some of the following suggestions to help
    make your Windows 10 PC run better
    . The steps are listed in order, so start with the first one, see if that fixes the problem, and then continue to the next one if it doesn’t.

    Note: The last step on the article contains Windows Reset, I suggest you not to perform Windows reset, as there is a change your data and applications will be wiped and also
    the OS will reverted back to previous version you upgraded from.

    If the issue still persists, please reply to this post with more information so that we can identify the root cause of this issue and assist you further.

    Hope it helps.

    Amit Sunar

    Microsoft Community – Moderator
     
    Amit_Sun, Jan 6, 2023
    #4
Thema:

WinRM Security - Event Logs

Loading...
  1. WinRM Security - Event Logs - Similar Threads - WinRM Security Event

  2. Security event gets logged continuously

    in Windows 10 Gaming
    Security event gets logged continuously: Hello Team,One of our 2 domain controllers have this security event logged continuously.The forest and domain functional level is 2016.Microsoft Windows security auditing. Event id 4625Audit FailureAn account failed to log on.Subject: Security ID: NULL SID Account Name: -...
  3. Security event gets logged continuously

    in Windows 10 Software and Apps
    Security event gets logged continuously: Hello Team,One of our 2 domain controllers have this security event logged continuously.The forest and domain functional level is 2016.Microsoft Windows security auditing. Event id 4625Audit FailureAn account failed to log on.Subject: Security ID: NULL SID Account Name: -...
  4. Event ID 521, Unable to log events to Security log

    in Windows 10 News
    Event ID 521, Unable to log events to Security log: [ATTACH]If you see Event ID 521 along with a message saying Unable to log events to security log on Windows Server, here is how you can fix the problem. It appears when the maximum log size is set to minimum or anything lower than maximum. In order to fix this issue, you need...
  5. Windows Event Logs- No Security logs No Registry Key for Security Logs

    in Windows 10 Gaming
    Windows Event Logs- No Security logs No Registry Key for Security Logs: Hello,I don't know how but I just noticed that I could not view Security Logs from Event Viewer---I cannot even attempt to edit the properties ---I tried entering the path to System32 for the Security.evtx but "Apply" was still greyed out and clicking OK never saved that...
  6. Windows Event Logs- No Security logs No Registry Key for Security Logs

    in Windows 10 Software and Apps
    Windows Event Logs- No Security logs No Registry Key for Security Logs: Hello,I don't know how but I just noticed that I could not view Security Logs from Event Viewer---I cannot even attempt to edit the properties ---I tried entering the path to System32 for the Security.evtx but "Apply" was still greyed out and clicking OK never saved that...
  7. Windows Event Logs- No Security logs No Registry Key for Security Logs

    in AntiVirus, Firewalls and System Security
    Windows Event Logs- No Security logs No Registry Key for Security Logs: Hello,I don't know how but I just noticed that I could not view Security Logs from Event Viewer---I cannot even attempt to edit the properties ---I tried entering the path to System32 for the Security.evtx but "Apply" was still greyed out and clicking OK never saved that...
  8. WinRM Security - Event Logs

    in Windows 10 Gaming
    WinRM Security - Event Logs: Hi, could someone please take a look at the logs attached and tell me if it's possible to tell by the logs if anyone might have used WinRM on my machine to gain unauthorized access? I use Windows 11 and I never set up WinRM to begin with. Thank you so much in advance....
  9. thousands of security logs in event viewer

    in Windows 10 Support
    thousands of security logs in event viewer: I went to the Event Viewer to check why my system shut down and won't turn on for a few minutes after the shut down. Then I noticed that under "Windows Logs" >"Security", I have more than 10,000 "Audit Success" logs. more than 10 per second. Is this normal? EventID are...
  10. Security Event Log flooded with 4656 Events

    in AntiVirus, Firewalls and System Security
    Security Event Log flooded with 4656 Events: We are having issues with our Security event log within Event Viewer. It is my understanding when you perform Object Access auditing and enable it within Group Policy, you still need to enable auditing on the Objects (to be audited) themselves. We just enabled Object Access...