Hi,
Windows Security event log was being flooded by Opalis PolicyModule.exe. How can we prevent Opalis PolicyModule.exe from logging in Security event log?
Hi,
can you post what is logged (EventID, Level, General ...) and which version from Opalis (e.g.) you are using?
Regards,
Stefan
Hi Stefan,
Thanks for your prompt response.
Below is the details of one of the event flooding our Security event log:
- System
- Provider
[ Name] Microsoft-Windows-Security-Auditing
[ Guid] {54849625-5478-4994-A5BA-3E3B0328C30D}
EventID 4663
Version 0
Level 0
Task 12800
Opcode 0
Keywords 0x8020000000000000
- TimeCreated
[ SystemTime] 2012-12-12T09:45:55.268860300Z
EventRecordID 34498210
Correlation
- Execution
[ ProcessID] 4
[ ThreadID] 88
Channel Security
Computer <hostname.domain>
Security
- EventData
SubjectUserSid S-1-5-21-114097353-1821660256-2561232206-202233
SubjectUserName <username>
SubjectDomainName <domain>
SubjectLogonId 0x193c7
ObjectServer Security
ObjectType File
ObjectName C:\Windows\SysWOW64\httpapi.dll
HandleId 0x784
AccessList %%4416
AccessMask 0x1
ProcessId 0x1bf0
ProcessName C:\Program Files (x86)\Opalis Software\Opalis Integration Server\Action Server\PolicyModule.exe
Hello,
Sorry, I can't find or reproduce (UACL, Security settings) this messages even with the "Invoke Web Services" Object (because httpapi.dll). So, no idea ...
Sorry,
Stefan