Multiple Event ID's 4738 and 4724 on new Windows 2012 Hyper V cluster
We just setup a two node Windows 2012 Hyper V cluster.  Everything is working correctly, but in the Security log on both nodes, we're getting Event ID's 4738 and 4724 every 3 minutes for the built in CLIUSR (Failover Cluster Local Identity) that gets created with the cluster (there's a local CLIUSR account on each node).  Because we have an application that parses the security logs and emails us about user account changes, we're getting spammed because of this.  Does anyone know if this is normal behavior for that CLIUSR account?  Any way to suppress this?  On the account properties, "User cannot change password" and "Password never expires" are both checked.  I appreciate any insights people might have.  Thanks
November 14th, 2013 2:26am

Hi,

The event log is generated because Audit policy is set:

Computer configuration->policies->windows settings->security settings->local policies->audit policy
Audit account management:Success

So if it is not on purpose you could simply disable it.

However it should not be a normal behavior so you may still need to check what's the exact cause. 

Free Windows Admin Tool Kit Click here and download it now
November 15th, 2013 3:35pm

Please let us know if there is any progress.
November 20th, 2013 4:45am

No there's no progress.  Yes, we can supress the events, but we're looking for the cause of the events and it seems no one has anything on that.  
Free Windows Admin Tool Kit Click here and download it now
November 21st, 2013 5:08pm

I was wondering if you where able to find out why the CLIUSR password was being changed every 3 minutes?
December 5th, 2013 12:58am

Hi,

Did somebody find out what is causing this problem?

Regards

Aleksandar

Free Windows Admin Tool Kit Click here and download it now
December 11th, 2013 3:57am

This topic is archived. No further replies will be accepted.

Other recent topics Other recent topics