Windows 10: WinRM Security - Event Logs

Discus and support WinRM Security - Event Logs in Windows 10 Gaming to solve the problem; Hi, could someone please take a look at the logs attached and tell me if it's possible to tell by the logs if anyone might have used WinRM on my... Discussion in 'Windows 10 Gaming' started by RooYu, Jan 6, 2023.

  1. RooYu Win User

    WinRM Security - Event Logs


    Hi, could someone please take a look at the logs attached and tell me if it's possible to tell by the logs if anyone might have used WinRM on my machine to gain unauthorized access? I use Windows 11 and I never set up WinRM to begin with. Thank you so much in advance.

    :)
     
    RooYu, Jan 6, 2023
    #1

  2. What's WinRM?

    Thank you very much for your response Ed.

    Is there any way to find out what could be the culprit of these entries? They seem to occur almost daily at random times.

    There are 4 events which keep repeating over and over again:


    Event 145: WSMan operation Enumeration started with resourceUri http://schemas.microsoft.com/wbem/ws...onfig/listener
    Event 254: Activity Transfer
    Event 161: The client cannot connect to the destination specified in the request. Verify that the service on the destination is running and is accepting requests. Consult the logs and documentation for the WS-Management service running on the destination, most commonly IIS or WinRM. If the destination is the WinRM service, run the following command on the destination to analyze and configure the WinRM service: "winrm quickconfig".
    Event 142: WSMan operation Enumeration failed, error code 2150858770
     
    ayylmao212, Jan 6, 2023
    #2
  3. VicImp Win User
    Unable to configure WinRM on domain user

    Hi everyone,

    I'm unable to configure WinRM on a domain computer. I have a simple domain with

    1) Windows server 2012

    2) A client running Windows 7

    If I try to run WinRM on the local Administrator, everything works fine, but if I switch to a domain user, than problems occured.

    For example, if i run winrm quickconfig in powershell as the domain Administrator, then I get:

    WinRM already is set up to receive requests on this machine.

    WSManFault

    Message = WinRM cannot process the request. The following error occured while using Negotiate authentication: An unknown security error occurred.

    Possible causes are:

    -The user name or password specified are invalid.

    -Kerberos is used when no authentication method and no user name are specified.

    -Kerberos accepts domain user names, but not local user names.

    -The Service Principal Name (SPN) for the remote computer name and port does not exist.

    -The client and remote computers are in different domains and there is no trust between the two domains.

    After checking for the above issues, try the following:

    -Check the Event Viewer for events related to authentication.

    -Change the authentication method; add the destination computer to the WinRM TrustedHosts configuration setting or use

    HTTPS transport.

    Note that computers in the TrustedHosts list might not be authenticated.

    -For more information about WinRM configuration, run the following command: winrm help config.

    Error number: -2144108387 0x8033809D

    An unknown security error occurred.

    When i run it as local admin, everything goes well.

    So, what am I missing?
     
    VicImp, Jan 6, 2023
    #3
  4. Amit_Sun Win User

    WinRM Security - Event Logs

    Events 4672 & 4624 Win 10 Freezes - special LOGON ?

    Hi,

    Thank you for writing to Microsoft Community Forums.

    1. Are you on a domain network?
    2. May I know the make and the model number of your system?

    The event logs you have provided seems to be the security logs that is generated when you login to your system. For more information on the event that was generated, you can check
    4672(S): Special privileges assigned to new logon.

    The Windows error logs will be located at Event Viewer > Windows Logs > System.

    Please follow the step below and check if it works for you.

    Step: Improve Windows 10 Performance.

    Try some of the following suggestions to help
    make your Windows 10 PC run better
    . The steps are listed in order, so start with the first one, see if that fixes the problem, and then continue to the next one if it doesn’t.

    Note: The last step on the article contains Windows Reset, I suggest you not to perform Windows reset, as there is a change your data and applications will be wiped and also
    the OS will reverted back to previous version you upgraded from.

    If the issue still persists, please reply to this post with more information so that we can identify the root cause of this issue and assist you further.

    Hope it helps.

    Amit Sunar

    Microsoft Community – Moderator
     
    Amit_Sun, Jan 6, 2023
    #4
Thema:

WinRM Security - Event Logs

Loading...
  1. WinRM Security - Event Logs - Similar Threads - WinRM Security Event

  2. WinRM log forwarding in Windows 2012 R2 Server

    in Windows 10 Gaming
    WinRM log forwarding in Windows 2012 R2 Server: I have various server in Active Directory with different Roles like SCCM server, Database Server, MS Lync, MS Exchange 2013 and MS Share Point Server.For their Security logs auditing, we have RSA Netwitness Platform.In of them some of services configured via WinRM method for...
  3. WinRM Security - Event Logs

    in Windows 10 Software and Apps
    WinRM Security - Event Logs: Hi, could someone please take a look at the logs attached and tell me if it's possible to tell by the logs if anyone might have used WinRM on my machine to gain unauthorized access? I use Windows 11 and I never set up WinRM to begin with. Thank you so much in advance....
  4. Event Log > Security Event ID 5156 and 5158 filling it up

    in Windows 10 Gaming
    Event Log > Security Event ID 5156 and 5158 filling it up: I am trying to use a Powershell scanner in PDQ Inventory which runs a PS1 and enter the returning data into the asset that scans the Security log for log on and log off events. The script then enters the data into that asset which allows us to see who has been using it and...
  5. Event Log > Security Event ID 5156 and 5158 filling it up

    in Windows 10 Software and Apps
    Event Log > Security Event ID 5156 and 5158 filling it up: I am trying to use a Powershell scanner in PDQ Inventory which runs a PS1 and enter the returning data into the asset that scans the Security log for log on and log off events. The script then enters the data into that asset which allows us to see who has been using it and...
  6. Event Log > Security Event ID 5156 and 5158 filling it up

    in Windows 10 Customization
    Event Log > Security Event ID 5156 and 5158 filling it up: I am trying to use a Powershell scanner in PDQ Inventory which runs a PS1 and enter the returning data into the asset that scans the Security log for log on and log off events. The script then enters the data into that asset which allows us to see who has been using it and...
  7. thousands of security logs in event viewer

    in Windows 10 Support
    thousands of security logs in event viewer: I went to the Event Viewer to check why my system shut down and won't turn on for a few minutes after the shut down. Then I noticed that under "Windows Logs" >"Security", I have more than 10,000 "Audit Success" logs. more than 10 per second. Is this normal? EventID are...
  8. Archive Security Event Logs Filling HD

    in Windows 10 Network and Sharing
    Archive Security Event Logs Filling HD: I don't know what caused it but I am seeing a massive amount of logs that aren't clearing themselves. I don't know if someone set something in group policy to monitor something and forgot but I don't see anything abnormal. I have gone to 10 computers, all of ours are Win 10,...
  9. Excessive Security Log Events - Event ID 5379 - Windows 10

    in Windows 10 BSOD Crashes and Debugging
    Excessive Security Log Events - Event ID 5379 - Windows 10: I have been experiencing Windows Application crashes on my 3 month old Windows 10 install. While troubleshooting, I noticed that there 50+ security events each minute in the Event Viewer under Windows Logs > Security. Is this normal? The majority are Audit Success...
  10. Security Event Log flooded with 4656 Events

    in AntiVirus, Firewalls and System Security
    Security Event Log flooded with 4656 Events: We are having issues with our Security event log within Event Viewer. It is my understanding when you perform Object Access auditing and enable it within Group Policy, you still need to enable auditing on the Objects (to be audited) themselves. We just enabled Object Access...

Users found this page by searching for:

  1. winrm код ошибки 2150858770