Excessive Security Log Events - Event ID 5379 - Windows 10

Anonymous
2020-04-26T06:15:06+00:00

I have been experiencing Windows Application crashes on my 3 month old Windows 10 install. While troubleshooting, I noticed that there 50+ security events each minute in the Event Viewer under Windows Logs > Security.  

Is this normal?  

The majority are Audit Success Messages with the Event ID 5379.  There are approximately 50 of these identical messages every minute. Thanks for any insight on this.

See below for typical Message:

Credential Manager credentials were read.

Subject:

Security ID: DESKTOP\*****

Account Name: *****

Account Domain: DESKTOP

Logon ID: 0x354889

Read Operation: Enumerate Credentials

This event occurs when a user performs a read operation on stored credentials in Credential Manager.

Windows for home | Windows 10 | Performance and system failures

Locked Question. This question was migrated from the Microsoft Support Community. You can vote on whether it's helpful, but you can't add comments or replies or follow the question.

0 comments No comments

52 answers

Sort by: Most helpful
  1. Anonymous
    2021-03-01T15:52:45+00:00

    OK. I think I have this resolved.

    Go to local users

    Make sure Administrator, DefaultAccount, and WDAGUtilityAccount are all active - not disabled.

    Make sure the Administrator account has a password set.

    Clear the security log and reboot.

    clear the security log again

    reboot

    This fixed my problem.

    Hope it fixes yours too.

    Was this answer helpful?

    0 comments No comments
  2. Anonymous
    2021-03-01T14:36:55+00:00

    Go to C\users\your user account\apdata\local\Packages\Microsoft.zuneVideo bla bla bla\local state\database\

    and delete the database.

    Was this answer helpful?

    0 comments No comments
  3. Anonymous
    2021-02-26T19:07:52+00:00

    I'm having the same problem. The system was fine last November and sat for about four months. When I turned it on last night, after all updates were applied and Outlook was downloading emails, the "freezing" issue started. After rebooting it stopped and I was hoping it was a one-time deal. After using the system for about 5 hours today, it started up again. Last night I was able to still use the computer, albeit very difficult. Today I wasn't even able to close windows (I think I managed to get two before I gave up and hit CTRL+ALT+DEL). The system was back to being normal/responsive after the ctrl/alt/del screen appeared (no idea what it's called). I logged out, forced applications to shut down (the shutdown process took a bit longer than usual), logged back in and the problem persisted. I rebooted the computer and the issue stopped.

    I decided to take a peak in the Event Viewer since the issue seems bizarre. I, too, found many 5379 events. I usually don't even bother with the Event Viewer because of the plethora of events that tend to be logged in there. However, in this case, I think the 5379 events ARE significant. Looking at the time stamps, they began occurring around the same time the freezing issue began. I tried to use the computer while the issue was happening for about ten minutes and there were eight pages (around 130 entries) of 5379 events occurring within seconds of each other.

    The same seems to be true from last night. There was a handful of 5379 events when I first logged in but during the first five hours of use there weren't hundreds of them, so... I'm off to search for more answers on this. Will come back here if I find one.

    Was this answer helpful?

    0 comments No comments
  4. Anonymous
    2020-08-31T09:52:32+00:00

    I have not figured it out yet. What i did find out though is my pc is incompatible with the new windows version and so it likes to malfunction. I cant use any of microsofts built in software due to it, and i cant revert back to 1909 either. So right now my pc is literally for gaming. I cant even open a picture on my computer.

    Was this answer helpful?

    0 comments No comments
  5. Anonymous
    2020-07-20T18:36:27+00:00

    1- When you change the buldin accounts passwords like, "default user", "guest" or "administrator"

    2- When you disable "server"service. You may get similar warning messages in event viewer, event id 5379, 5382, 4779 that's may little experiences, good luck.

    Was this answer helpful?

    0 comments No comments