Excessive Security Log Events - Event ID 5379 - Windows 10

Anonymous
2020-04-26T06:15:06+00:00

I have been experiencing Windows Application crashes on my 3 month old Windows 10 install. While troubleshooting, I noticed that there 50+ security events each minute in the Event Viewer under Windows Logs > Security.  

Is this normal?  

The majority are Audit Success Messages with the Event ID 5379.  There are approximately 50 of these identical messages every minute. Thanks for any insight on this.

See below for typical Message:

Credential Manager credentials were read.

Subject:

Security ID: DESKTOP\*****

Account Name: *****

Account Domain: DESKTOP

Logon ID: 0x354889

Read Operation: Enumerate Credentials

This event occurs when a user performs a read operation on stored credentials in Credential Manager.

Windows for home | Windows 10 | Performance and system failures

Locked Question. This question was migrated from the Microsoft Support Community. You can vote on whether it's helpful, but you can't add comments or replies or follow the question.

0 comments No comments

52 answers

Sort by: Newest
  1. Anonymous
    2021-02-11T23:07:20+00:00

    @Rashad Rivera,

    If you look at other reports of "Audit Success" logging in the event logs, you will see that firstly this cannot (currently) be turned off, and secondly, it is NORMAL to see multiple entries for this, as Windows 10 internal functions are always checking when they start any activity, that they have the "credentials" to do so, and this is just showing "this software DLL/API or program was OK and valid with its assigned (normal or system) account ". So, I very much doubt this is a "rogue process", it is normal. You could check if any APPS are running in background mode that you don't need to, and check "autoruns" to see if there are any items that you do not need to start up with Windows when it boots.

    There will be another ID number for "Audit failure", and you could set up a custom view yourself to see these if you want to, to aid troubleshooting.

    I DO agree it is often excessive (Audit Success), and for techies looking for an issue, we SHOULD be able to turn it off (at least once before say a reboot).

    Was this answer helpful?

    2 people found this answer helpful.
    0 comments No comments
  2. Anonymous
    2021-02-11T21:25:10+00:00

    So this is a ridiculous issue.  If I was a hacker trying to cover my tracks, I would flood event logs with garbage like this.  Why doesn't Microsoft provide more details so that we can know the process generating these logs.  Why is it so hard to figure out what's going on here.

    In my case, I get 50+ per minute and I cannot find bad activity because the log is flushed.  This issue should be raised as a security concern especially since the it involves the Security event logs.  

    A tool that allows us to pinpoint the cause would alleviate the need for us to guesstimate the cause.  Does anyone know if tools like procmon.exe would help in identifying the process causing this issue? 

    Note, I've checked my GPO and no Audit Policy settings are set; leading me to believe that a rogue process is logging them.

    Was this answer helpful?

    10+ people found this answer helpful.
    0 comments No comments
  3. Anonymous
    2020-12-18T22:14:25+00:00

    so does anyone have a fix for this or nah? is it as simple as updating or is this something I have to live with now.

    Was this answer helpful?

    1 person found this answer helpful.
    0 comments No comments
  4. Anonymous
    2020-10-26T23:03:54+00:00

    That might be true for old Wireless Mice, where the Bluetooth protocol uses old security protocols, and do not work after updates that fix the enforcement of better security in the Bluetooth software stack. However, for $15 or so, I would rather replace any older mouse or keyboard, to ensure good security.

    As regards bugs, Microsoft do not do this intentionally, but with hundreds of thousands of different hardware configurations and driver combinations (many items with unsigned drivers), it must be very hard, even for a large company like Microsoft, to get it 100% correct every time. If an issue occurs after any update, check the forums, and go to the manufacturers site for your device in error, and ensure you have the latest software and drivers. This is especially true for Graphics Cards.

    Was this answer helpful?

    1 person found this answer helpful.
    0 comments No comments
  5. Anonymous
    2020-10-26T21:50:19+00:00

    It looks like microsoft is rolling out bugs to force people to update their hardware.

    Was this answer helpful?

    4 people found this answer helpful.
    0 comments No comments