Excessive Security Log Events - Event ID 5379 - Windows 10

Anonymous
2020-04-26T06:15:06+00:00

I have been experiencing Windows Application crashes on my 3 month old Windows 10 install. While troubleshooting, I noticed that there 50+ security events each minute in the Event Viewer under Windows Logs > Security.  

Is this normal?  

The majority are Audit Success Messages with the Event ID 5379.  There are approximately 50 of these identical messages every minute. Thanks for any insight on this.

See below for typical Message:

Credential Manager credentials were read.

Subject:

Security ID: DESKTOP\*****

Account Name: *****

Account Domain: DESKTOP

Logon ID: 0x354889

Read Operation: Enumerate Credentials

This event occurs when a user performs a read operation on stored credentials in Credential Manager.

Windows for home | Windows 10 | Performance and system failures

Locked Question. This question was migrated from the Microsoft Support Community. You can vote on whether it's helpful, but you can't add comments or replies or follow the question.

0 comments No comments

52 answers

Sort by: Oldest
  1. Anonymous
    2020-07-04T21:21:31+00:00

    I have was experiencing a similar thing with my desktop today (event entries for eventID 5379 - about 20 entries in one second -  but no crashes + eventID 4798 - random frequency but typically every 1 to 4 seconds).

    I had alternating sets of log entries for of event 5379 and 4798 and a constant "disconnected device" sound alert. I came across an article about a failing USB device so I disconnected my USB memory card reader and both the sound alert and the log entries for those 2 eventID's have stopped for the past 20 mins.

    It could be that the card reader is failing or perhaps not properly plugged in. It could be the USB plug itself that has an issue, I haven't tested any further yet, I'm just glad that the constant bleeps have stopped!

    Was this answer helpful?

    3 people found this answer helpful.
    0 comments No comments
  2. Anonymous
    2020-07-20T18:36:27+00:00

    1- When you change the buldin accounts passwords like, "default user", "guest" or "administrator"

    2- When you disable "server"service. You may get similar warning messages in event viewer, event id 5379, 5382, 4779 that's may little experiences, good luck.

    Was this answer helpful?

    0 comments No comments
  3. Anonymous
    2020-07-21T09:45:28+00:00

    RUN gpedit.msc

    Local Computer configuration

    \Administrative Templates

    \Network

    \Microsoft Peer-to-Peer Networking Services

    \Peer Name Resolution Protocol

    \Global Clouds

    \Link-Local Clouds

    \Site-Local Clouds

        (Under all 3 headers)   

    Turn off Multicast Bootstrap    Enabled

        Set PNRP cloud to resolve only    Enabled   

        Turn off PNRP cloud creation    Enabled   


    \Network\Microsoft Peer-to-Peer Networking Services

        Turn off Microsoft Peer-to-Peer Networking Services    Enabled   


    \Network\Network Connections\Windows Defender Firewall\Domain Profile

        Windows Defender Firewall: Protect all network connections    Enabled   

    \Network\Network Connections\Windows Defender Firewall\Standard Profile

        Windows Defender Firewall: Protect all network connections    Enabled

    Forget the warnings

    Was this answer helpful?

    10+ people found this answer helpful.
    0 comments No comments
  4. Anonymous
    2020-08-04T16:07:39+00:00

    I'm having the same issue except I get over 500 of these events at a time

    Was this answer helpful?

    6 people found this answer helpful.
    0 comments No comments
  5. Anonymous
    2020-08-08T23:11:32+00:00

    I'm having the same issue except I get over 500 of these events at a time

    Same and I am on a gaming PC so it happens a lot when I am playing which causes me to freeze and then my game crashes.

    Was this answer helpful?

    7 people found this answer helpful.
    0 comments No comments