Re: The security log on this system is full



Thanks Mike,

Even I clear the event security logs, the error disappears during some days
until I reach approximatly 400 Mbytes space for the security logs (this not
the maximum space value I have specified and therefore there are still enough
space) and again I get the error.
Very confugsing !
I found the only solution to solve it is to modify the event security log
parameters by sepcifying : overwrite events as needed.
Job



"Special Access" wrote:

On Wed, 25 Oct 2006 03:03:01 -0700, Job
<Job@xxxxxxxxxxxxxxxxxxxxxxxxx> wrote:

Thanks Mike but the value of the registry key is ''O'' therefore normal.
I wouldn't set to ''1'' because it will crash my server.
Do you have any other solutions ?
Thanks for your reply,
Job

"Special Access" wrote:

On Tue, 24 Oct 2006 07:14:02 -0700, Job
<Job@xxxxxxxxxxxxxxxxxxxxxxxxx> wrote:

Dear All,

I activated most of security audit (within the default domain controller
policy) for the domain controllers installed with Windows 2000 sp4 (Active
Directory) and it ran well.
Then I have recently upgrated to Windows 2003 sp1 all domain controllers and
now I get the following error when I open a session on domain controllers :

"the security log on this system is full"

When I look at the properties of security event logs file, it shows that
the log size isn't full and there is enough space to further events security
logs. Could you tell me why I get this error ?
I precised that I have defined the log to overwrite events security logs
older than 60 days.
Thanks for your help,
Job

Open REGEDIT and look at
HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\LSA and look for a
key of "CrashOnAuditFail". It's value should be either 0 (ignore) or
1 (active). If it's value is 2 (tripped) or NONE (also tripped) then
you need to reset it to either 1 or 0 and reboot.

The fact the log isn't full won't stop this error. This is because
the system can't write to the security log "for whatever reason". This
reason could be:
Disk is full
Log is full
Your stomach is full
The candy dish on the table is full
<smile>

If "crash on audit fail" is active, and the system can't write to the
log, it will crash and give you this error.

Mike


IF you set it to 1, it shouldn't "crash the server" but enable the
crash should the logs become full. If the logs are full or the error
is persistent, then clear (and save) the logs to see if the error goes
away. I have not seen this error without also seeing the tripped
CrashOnAuditFail indication as well so I'm sorta out of answers <grin>

Mike

.



Relevant Pages

  • Re: unaccesible system event log
    ... Sophos EM Library is one part of antivirus solution for distributing ... I have no access to server now, so I can't answer exactly your questions ... about security logs ... And what do you see in the security logs (is auditing turned up so you get ...
    (microsoft.public.windows.server.active_directory)
  • Re: unaccesible system event log
    ... antivirus protection Sophos to workstations. ... I have no access to server now, so I can't answer exactly your questions ... about security logs ... And what do you see in the security logs (is auditing turned up so you ...
    (microsoft.public.windows.server.active_directory)
  • Re: unaccesible system event log
    ... "Al Mulnick" wrote: ... I have no access to server now, so I can't answer exactly your questions ... about security logs ... And what do you see in the security logs (is auditing turned up so you ...
    (microsoft.public.windows.server.active_directory)
  • Re: Analyse der Security Logs (DCs)
    ... > ich suche Produkte zur Analyse von Security Logs. ... wäre MOM eine Möglichkeit. ... jedoch out-of-the-box keine Regeln für die Analyse von Security Logs, ...
    (microsoft.public.de.german.win2000.active_directory)
  • Re: MM2 crashing
    ... No error is the system logs, for the app events, security, or system. ... Let me take a min to explain the crash. ... When MM2 or Media Player or Notepad ... MM2 and Media player both lock up ...
    (microsoft.public.windowsxp.moviemaker)