Hi Fellows,
I am getting Event ID 26007 & 26008 followed by 26005 very frequently. As described in below thread, I am monitoring SAM Objects Access and have a huge pile of event ID 4661 in my domain controller's security event logs. I cannot compromise on disabling the Object access. I need to know if there is any way to disable monitoring Event ID 4661 or whole Security Event log on domain controllers?
https://social.technet.microsoft.com/Forums/systemcenter/en-US/28b0c0b1-4fdf-4c6c-a9f6-6f84a0107420/opsmgr-eventid-26007-on-domain-controllers-the-eventlog-service-reported-that-the-security-event?forum=operationsmanagergeneral&prof=required
26007:
The EventLog service reported that the Security event log on computer 'DC1' is corrupt. The Windows Event Log Provider will attempt to recover by re-opening log.
One or more workflows were affected by this.
Workflow name: MomUIGeneratedRule43c0a0798f374c14960aac5a7cb411ff
Instance name: DC1
Instance ID: {AEBA31FC-0490-C83F-C22F-6287F6612DEC}
Management group: SCOMMG
26008
The Security event log on computer 'DC1' is still corrupt. The Event Log Provider will attempt to recover by skipping over a possible bad record. The Provider may skip up to two records.
One or more workflows were affected by this.
Workflow name: MomUIGeneratedRule43c0a0798f374c14960aac5a7cb411ff
Instance name: DC1
Instance ID: {AEBA31FC-0490-C83F-C22F-6287F6612DEC}
Management group: SCOMMG
26005
The Windows Event Log Provider has resumed processing the Security event log on computer 'DC1' after recovering from errors.One or more workflows were affected by this.
Workflow name: MomUIGeneratedRule43c0a0798f374c14960aac5a7cb411ff
Instance name: DC1
Instance ID: {AEBA31FC-0490-C83F-C22F-6287F6612DEC}
Management group: SCOMMG
J.A