Excessive Security Log Events - Event ID 5379 - Windows 10

Anonymous
2020-04-26T06:15:06+00:00

I have been experiencing Windows Application crashes on my 3 month old Windows 10 install. While troubleshooting, I noticed that there 50+ security events each minute in the Event Viewer under Windows Logs > Security.  

Is this normal?  

The majority are Audit Success Messages with the Event ID 5379.  There are approximately 50 of these identical messages every minute. Thanks for any insight on this.

See below for typical Message:

Credential Manager credentials were read.

Subject:

Security ID: DESKTOP\*****

Account Name: *****

Account Domain: DESKTOP

Logon ID: 0x354889

Read Operation: Enumerate Credentials

This event occurs when a user performs a read operation on stored credentials in Credential Manager.

Windows for home | Windows 10 | Performance and system failures

Locked Question. This question was migrated from the Microsoft Support Community. You can vote on whether it's helpful, but you can't add comments or replies or follow the question.

0 comments No comments

52 answers

Sort by: Oldest
  1. Anonymous
    2021-03-01T14:52:45+00:00

    I had the same problem.

    First thing to do is run a cmd prompt as administrator

    at the prompt run the following

    sfc /scannow

    when that finishes, read the results.

    disconnect any usb connections and any flash drives.

    Restart computer

    Clear security and other logs.

    Restart again.

    Now look at the security log and see if the replication has stopped.

    If it has, then one by one add back the flash drives or usb connections to find the one that is causing the problem

    Was this answer helpful?

    3 people found this answer helpful.
    0 comments No comments
  2. Anonymous
    2021-03-01T15:24:04+00:00

    Hi, thanks for the reply; I tried this and for a long time I suspected a faulty USB device. Finally, I fixed it by turning off the "slide show" on the screen backgrounds - I have three screens and a short period between changes. The slide show isn't what caused the pausing of the machine, but Windows automatically recolours windows to "match" the background - so everything was being redrawn every few minutes - I turned off the slide show and much improved the performance.

    Was this answer helpful?

    2 people found this answer helpful.
    0 comments No comments
  3. Anonymous
    2021-03-01T15:52:45+00:00

    OK. I think I have this resolved.

    Go to local users

    Make sure Administrator, DefaultAccount, and WDAGUtilityAccount are all active - not disabled.

    Make sure the Administrator account has a password set.

    Clear the security log and reboot.

    clear the security log again

    reboot

    This fixed my problem.

    Hope it fixes yours too.

    Was this answer helpful?

    0 comments No comments
  4. Anonymous
    2021-03-02T12:22:22+00:00

    @RemoteComputerTechnician - I would be very interested to know if, after a couple of days use with your suggested workarounds:

    1) Have any Event ID 5379 for Audit Success returned?

    2) Do all your expected functions (backups, scheduled programs, AV and other Win32 programs) still work OK?

    3) Do all of your UWT APPS still work OK?

    4) Do all of your sharing/casting and other network activities all still function as normal?

    Incidentally, as regards the DefaultAccount (the DSMA account), Microsoft have this to say:

    From here:

    https://docs.microsoft.com/en-us/windows/security/identity-protection/access-control/local-accounts

    Recommendations for managing the Default Account (DSMA)

    Microsoft does not recommend changing the default configuration, where the account is disabled. There is no security risk with having the account in the disabled state. Changing the default configuration could hinder future scenarios that rely on this account.

    Was this answer helpful?

    0 comments No comments
  5. Anonymous
    2021-05-13T18:40:37+00:00

    I have been experiencing Windows Application crashes on my 3 month old Windows 10 install. While troubleshooting, I noticed that there 50+ security events each minute in the Event Viewer under Windows Logs > Security.  

    Is this normal?  

    The majority are Audit Success Messages with the Event ID 5379.  There are approximately 50 of these identical messages every minute. Thanks for any insight on this.

    See below for typical Message:

    Credential Manager credentials were read.

    Subject:

    Security ID: DESKTOP\*****

    Account Name: *****

    Account Domain: DESKTOP

    Logon ID: 0x354889

    Read Operation: Enumerate Credentials

    This event occurs when a user performs a read operation on stored credentials in Credential Manager.

      

    i had ex[eriences like that last night  - my laptop so slowly

    Was this answer helpful?

    0 comments No comments