Quantcast
Viewing all articles
Browse latest Browse all 11941

SCOM 2012 RMS emulator windows security log flooded with EventID 4666 and 26401

Hello,

My RMS emulator windows security log is flooded with EventID 4666 and 26401 events.

I'm getting over 20 events per second

Is there something that i need to do?

Log Name:      Security
Source:        MOMSDK Service Security
Date:          10/18/2012 10:43:20 PM
Event ID:      26401
Task Category: (3)
Level:         Information
Keywords:      Classic,Audit Failure
User:          domain\username
Computer:      rms
Description:
Data access operation: User_IsAdministrator__Check
Data access method: IsUserAdministrator
User name: domain\username
sessionId: uuid:0b231063-f3fb-4b9f-9872-b88645968fda;id=6

Log Name:      Security
Source:        Microsoft-Windows-Security-Auditing
Date:          10/18/2012 10:43:20 PM
Event ID:      4666
Task Category: Application Generated
Level:         Information
Keywords:      Audit Failure
User:          N/A
Computer:     
Description:
An application attempted an operation:

Subject:
    Client Name:        username
    Client Domain:        domain

   Client Context ID:    3649027831

Object:
    Object Name:        IsUserAdministrator
    Scope Names:        50585907-7858-4488-ab9c-13e0eaac08be

Application Information:
    Application Name:    Microsoft System Center
    Application Instance ID:    3649001670

Access Request Information:
    Role:            Role
    Groups:            Group
    Operation Name:    User_IsAdministrator__Check (142)


Viewing all articles
Browse latest Browse all 11941

Trending Articles



<script src="https://jsc.adskeeper.com/r/s/rssing.com.1596347.js" async> </script>