Security Audit 560 Filling Security Log
I have the following event literally thousands of times on my Exchange Server: WinEvtLog: Security: AUDIT_FAILURE(560): Security: SYSTEM: NT AUTHORITY: SERVERNAME: Object Open: Object Server: Security Object Type: Key Object Name: \REGISTRY\MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Perflib Handle ID: - Operation ID: {0,3015636319} Process ID: 4976 Image File Name: C:\WINDOWS\system32\wbem\wmiprvse.exe Primary User Name: NETWORK SERVICE Primary Domain: NT AUTHORITY Primary Logon ID: (0x0,0x3E4) Client User Name: SERVERNAME$ Client Domain: DOMAIN Client Logon ID: (0x0,0x3E7) Accesses: %%1542 %%1543 Privileges: - Restricted Sid Count: 0 Access Mask: 0x3000000 My question is two part based on the information above; a) Is this a access viloation I should be concerned with? b) If it is not something serious how should I go about at least eliminating the event? Thanks. Al
May 13th, 2010 8:01pm

I have the same question. The Network Service is trying to access wmiprvse.exe every second but generates a failure audit 560 in the Security log. Someone has to know something about this. I can not find any useful information anywhere. The error is generated on Windows Server 2003 SE with SP2 which is the Exchange 6.5 server. Changing permissions, restarting the services, modifying the registry did not help. We two can not be the only ones experiencing this, so put your gray matter to work and give us a clue. Thank you.
Free Windows Admin Tool Kit Click here and download it now
March 7th, 2011 12:55pm

any luck on this issue becuase I am having same problem thks
May 6th, 2011 12:13pm

This topic is archived. No further replies will be accepted.

Other recent topics Other recent topics