Excessive Security Log Events - Event ID 5379 - Windows 10

Anonymous
2020-04-26T06:15:06+00:00

I have been experiencing Windows Application crashes on my 3 month old Windows 10 install. While troubleshooting, I noticed that there 50+ security events each minute in the Event Viewer under Windows Logs > Security.  

Is this normal?  

The majority are Audit Success Messages with the Event ID 5379.  There are approximately 50 of these identical messages every minute. Thanks for any insight on this.

See below for typical Message:

Credential Manager credentials were read.

Subject:

Security ID: DESKTOP\*****

Account Name: *****

Account Domain: DESKTOP

Logon ID: 0x354889

Read Operation: Enumerate Credentials

This event occurs when a user performs a read operation on stored credentials in Credential Manager.

Windows for home | Windows 10 | Performance and system failures

Locked Question. This question was migrated from the Microsoft Support Community. You can vote on whether it's helpful, but you can't add comments or replies or follow the question.

0 comments No comments

52 answers

Sort by: Most helpful
  1. Anonymous
    2021-06-06T14:36:22+00:00

    Non of it matters because the 5379 Audit Success postings are back. I thought they were gone, but no, they are back.

    Was this answer helpful?

    2 people found this answer helpful.
    0 comments No comments
  2. Anonymous
    2021-03-01T15:24:04+00:00

    Hi, thanks for the reply; I tried this and for a long time I suspected a faulty USB device. Finally, I fixed it by turning off the "slide show" on the screen backgrounds - I have three screens and a short period between changes. The slide show isn't what caused the pausing of the machine, but Windows automatically recolours windows to "match" the background - so everything was being redrawn every few minutes - I turned off the slide show and much improved the performance.

    Was this answer helpful?

    2 people found this answer helpful.
    0 comments No comments
  3. Anonymous
    2021-02-27T02:09:23+00:00

    @Daved11 - I doubt very much that just because you see these (very normal) events, that it has ANYTHING relevant to your issue. Here is a description of the event; "Event 5379:

    Credential Manager credentials were read. This event occurs when a user performs a read operation on stored credentials in Credential Manager"

    So, just to be clear, ANY interface, or function that needs to check your account credentials via the Credential Manager before the function is allowed to execute (program/ap/api/DLL etc) will create this "OK" event.

    Please post what your make/model of machine is, and what the Windows 10 level is. The easy way to do this is to right-click on the start icon (bottom left), choose "run" from the list, then key in winver in the command box. Post the version and OS build from the little window that comes up.

    Also, what Anti-Virus program do you have, and have you been "persuaded" by advert clicks to add any (probably useless) "virus scanners" and Driver scanner checkers, that will "fight" for CPU and disk resources on your PC, and conflict with your actual anti-virus program?

    I did notice my laptop, once it had updated to Feature Update 2004 (that means April 2020 ), the Windows Search Indexer became much more aggressive than before, and was running very actively for long periods. After a few hours, it settled down to normal. You can check what is running and taking up a lot of the CPU or Disk I/O by making intelligent use of the Task Manager. You can start that by right-click on any black (blank) space on the activity menu bar at the bottom, and choose Task manager from the list. When it start, let it settle down for about a minute, make sure you click on the "more details" link near the bottom left side if you have never run it before, then click on the "Processes" tab at the top. Check for any process or app/program using a high CPU% (more than 25% means a probable CPU core hog/loop). Post back anything running that you are not expecting to be running.

    Was this answer helpful?

    2 people found this answer helpful.
    0 comments No comments
  4. Anonymous
    2021-02-11T23:07:20+00:00

    @Rashad Rivera,

    If you look at other reports of "Audit Success" logging in the event logs, you will see that firstly this cannot (currently) be turned off, and secondly, it is NORMAL to see multiple entries for this, as Windows 10 internal functions are always checking when they start any activity, that they have the "credentials" to do so, and this is just showing "this software DLL/API or program was OK and valid with its assigned (normal or system) account ". So, I very much doubt this is a "rogue process", it is normal. You could check if any APPS are running in background mode that you don't need to, and check "autoruns" to see if there are any items that you do not need to start up with Windows when it boots.

    There will be another ID number for "Audit failure", and you could set up a custom view yourself to see these if you want to, to aid troubleshooting.

    I DO agree it is often excessive (Audit Success), and for techies looking for an issue, we SHOULD be able to turn it off (at least once before say a reboot).

    Was this answer helpful?

    2 people found this answer helpful.
    0 comments No comments
  5. Anonymous
    2020-05-11T06:21:10+00:00

    Of course. But so far I did not find a solution for the problem.

    Was this answer helpful?

    1 person found this answer helpful.
    0 comments No comments