Server 2008  LSA queue issues, Event 1107, and disappearing security audits.
Posted in the wrong forum earlier Server 2008 (32 bit) Domain Controller will be running just fine, then the normal 4624, 4634, etc. events will cease and the following will appear: The event logging service encountered an error while processing an incoming event from publisher Microsoft-Windows-Security-Auditing and trying to process the metadata for it. EVENT ID: 1107 I understand that LSA has a queue set in HKLM\SYSTEM\CurrentControlSet\Control\Lsa. It is currently 0x00 30 00 00 00 20 00 00. I have also found the following data: "Specifies thresholds for managing the length of the kernel-mode Local Security Authority ( LSA ) audit queue. The audit queue stores kernel-mode events destined for the Security Log in Event Viewer. The value of this entry is an 8-byte binary field. The value of the first four bytes specifies the maximum number of items that can be held in the audit queue (the upper bound). When the number of audits exceeds this value, LSA discards all new audits until the number of audits remaining in the queue reaches the lower bound, as specified by the value of the last four bytes. The system does not notify you when the queue is nearing, has reached, or has exceeded its upper bound. To prevent the system from running when it cannot report all security events, set the value of CrashOnAuditFail to 1." Well.... I am getting mighty tired of rebooting a domain controller because it is not logging properly. Are there any settings, changes, mods, upgrades that will allow me to run the system without repeatedly resetting? Note... In one case, clearing the security log 2x times allowed the queued events to be read and the event log to continue running. However, normally the event viewer crashes instead, requiring a full reboot. Dell PowerEdge 750 Pentium 4 Dual Core 2.8 Ghz 2.5 GB Ram
January 26th, 2011 1:48pm

No ideas?
Free Windows Admin Tool Kit Click here and download it now
January 27th, 2011 7:19pm

170+ views and not one response? If I am not clear, please tell me. If there is no fix, please let me know.
January 31st, 2011 4:34pm

380+ views and no ideas?
Free Windows Admin Tool Kit Click here and download it now
February 8th, 2011 5:23pm

800+ Views............. Any takers?
March 18th, 2011 5:59pm

Nearly 1000 views and not one response.... Does no one know the answer to my question? Are there any settings, changes, mods, upgrades that will allow me to run the system without repeatedly rebooting to clear the 1107 events? More RAM? Larger LSA audit queue? If a larger queue, how large?
Free Windows Admin Tool Kit Click here and download it now
March 29th, 2011 3:10pm

No answers?
May 27th, 2011 4:30pm

Has passed 2000 views and yet not one person can assist?
Free Windows Admin Tool Kit Click here and download it now
July 12th, 2011 4:50pm

This topic is archived. No further replies will be accepted.

Other recent topics Other recent topics