SEPM12.1 with XP clients logging heavily in security log
Created: 11 Sep 2012 | Updated: 11 Sep 2012 | 7 comments
Hi
Recently we installed SEPM 12.1 on the server and the clients have all since been updated. We predominantly use XP computers. What we are seeing is the security log is filling up with lot of eventID 577 and 526 with failures, whcih eventually stops users from loggin on to the PC until the log is cleared. Have I missed some setup which should not be logging this on the security log.
Regards
Venkatesh
Discussion Filed Under:
Comments 7 Comments • Jump to latest comment
hi,
This is not a SEP 12.1 Issue.I have also facing same issue before in xp system
You security log are not purgeing
Please follow this steps.
1) Open Event Viewer.
2) Security Logs Properties.
3) Select Below radio Buttion.
Note: If your Issue will be resolved don't forgot Mark as Solution
Thanks In Advance
Ashish Sharma
SEPM Knowledgebase Documents
I have checked this and all the PCs are set to overwrite events as needed, It definitely happened straight after the update of SEPM clients to version 12.1
HI
Check this microsoft Kbase.This is Microsoft XP Problem
Event ID 577 appears repeatedly in the security event log of your Windows XP-based computer
http://support.microsoft.com/kb/831905
Note: If your Issue will be resolved don't forgot Mark as Solution
Thanks In Advance
Ashish Sharma
SEPM Knowledgebase Documents
Hi Ashish
Thanks for the information, but I have explored all these options and most of our PCs are running the latest service pack and we cannot apply this hotfix as it was released in 2003 after SP1 had some issues. How did your problem get fixed?
Regards
Venkatesh
Hi,
For testing purpose Remove SEP client on machine and check Logs are created or not ?
Do you have installed the 3rd-party softwares such as McAfee
Failure Audit, Security, Privilege Use, Event ID 577 (displayed on client after installing McAfee Agent 4.5)
https://kc.mcafee.com/corporate/index?page=content&id=KB67976
Hundreds of event 577 every SECOND! how do i stop this
http://social.technet.microsoft.com/Forums/en/winserversecurity/thread/736531f4-7982-4f95-a56e-8a53e46235c5
Thanks In Advance
Ashish Sharma
SEPM Knowledgebase Documents
are you referring to Microsoft security log, then agree with the above comments. You may test it if you uninstall SEP agent on one machine and monitor for the logs.
Cheers!
Pete
Help Link: http://www.symantec.com/business/support/overview.jsp?pid=54619
hi Venkatesh,
Any update on this ?
Thanks In Advance
Ashish Sharma
SEPM Knowledgebase Documents
Would you like to reply?
Login or Register to post your comment.