Video Screencast Help
Search Video Help Close Back
to help

SEPM12.1 with XP clients logging heavily in security log

Created: 11 Sep 2012 | Updated: 11 Sep 2012 | 7 comments
venkat444's picture
0 0 Votes
Login to vote

Hi

Recently we installed SEPM 12.1 on the server and the clients have all since been updated. We predominantly use XP computers. What we are seeing is the security log is filling up with lot of eventID 577 and 526 with failures, whcih eventually stops users from loggin on to the PC until the log is cleared. Have I missed some setup which should not be logging this on the security log.

 

Regards

Venkatesh

Comments 7 CommentsJump to latest comment

Ashish-Sharma's picture

hi,

This is not a SEP 12.1 Issue.I have also facing same issue before in xp system

You security log are not purgeing

Please follow this steps.

1) Open Event Viewer.

2) Security Logs Properties.

3) Select Below radio Buttion.

 

Note: If your Issue will be resolved don't forgot Mark as Solution

Thanks In Advance

Ashish Sharma

SEPM Knowledgebase Documents  

 

0
Login to vote
  • Actions
venkat444's picture

I have checked this and all the PCs are set to overwrite events as needed, It definitely happened straight after the update of SEPM clients to version 12.1

0
Login to vote
  • Actions
Ashish-Sharma's picture

HI

Check this microsoft Kbase.This is Microsoft XP Problem

Event ID 577 appears repeatedly in the security event log of your Windows XP-based computer

http://support.microsoft.com/kb/831905

 

Note: If your Issue will be resolved don't forgot Mark as Solution

Thanks In Advance

Ashish Sharma

SEPM Knowledgebase Documents  

 

0
Login to vote
  • Actions
venkat444's picture

Hi Ashish

Thanks for the information, but I have explored all these options and most of our PCs are running the latest service pack and we cannot apply this hotfix as it was released in 2003 after SP1 had some issues. How did your problem get fixed?

 

Regards

Venkatesh

0
Login to vote
  • Actions
Ashish-Sharma's picture

Hi,

For testing purpose Remove SEP client on machine and check Logs are created or not ?

Do you have installed the 3rd-party softwares such as McAfee

Failure Audit, Security, Privilege Use, Event ID 577 (displayed on client after installing McAfee Agent 4.5)
https://kc.mcafee.com/corporate/index?page=content&id=KB67976
 

Hundreds of event 577 every SECOND! how do i stop this

http://social.technet.microsoft.com/Forums/en/winserversecurity/thread/736531f4-7982-4f95-a56e-8a53e46235c5

Thanks In Advance

Ashish Sharma

SEPM Knowledgebase Documents  

 

0
Login to vote
  • Actions
pete_4u2002's picture

are you referring to Microsoft security log, then agree with the above comments. You may test it if you uninstall SEP agent on one machine and monitor for the logs.

0
Login to vote
  • Actions
Ashish-Sharma's picture

hi Venkatesh,

Any update on this ?

Thanks In Advance

Ashish Sharma

SEPM Knowledgebase Documents  

 

0
Login to vote
  • Actions