Security Log fills up everyday!!!
Hi all
I have a problem with the security log in windows Xp Pro, it fills up everyday even though i've changed the log retention settings to overwrite events older than one day, we still get the error message when we log onto windows that "the security log is full and only the administrator can clear the log" and the log size limit is set to 64K. Sometimes it does'nt allow my users to log onto their computers. I'm currently running Symantec Antivirus Corporate Edition on all our pc's on the network and it gets updated on a daily basis. If anyone knows of an antivirus tool that i can use to resolve my problem please please please let me know.
I have a problem with the security log in windows Xp Pro, it fills up everyday even though i've changed the log retention settings to overwrite events older than one day, we still get the error message when we log onto windows that "the security log is full and only the administrator can clear the log" and the log size limit is set to 64K. Sometimes it does'nt allow my users to log onto their computers. I'm currently running Symantec Antivirus Corporate Edition on all our pc's on the network and it gets updated on a daily basis. If anyone knows of an antivirus tool that i can use to resolve my problem please please please let me know.
Comments
-
mrhaun03 Member Posts: 359We run Symantec here as well. Once in a while I see this problem. If you go into the Security Log properties and check "Overwrite Events as Needed"...this should take care of your problem. By default it's set to overwrite events older than 7 days.Working on Linux+
-
ITjunkie Member Posts: 2 ■□□□□□□□□□Thanks for your help mrhaun03 hope this will solve my problem but i still think it's a virus infection because this problem only started about 4 weeks ago. I will keep on searching for a solution and as soon as i find it i will let you know.
-
Ye Gum Noki Member Posts: 115If you have Symantec Corporate running and it is up to date, you don't have a virus. You should overwrite the log, but more importantly you need to find out what's causing the log entries and deal with that cause, by either changed the policy generating the entries or fixing any the problem.
Good luck,"What we think, or what we know, or what we believe is, in the end, of little consequence. The only consequence is what we do." John Ruskin. -
mrhaun03 Member Posts: 359Since you have the log set to overwrite events older than 1 day, its only going to take 1 day to fill up again. Set it to overwrite events as needed.Working on Linux+
-
JDMurray Admin Posts: 13,089 AdminAlso, increase your log size to something reasonable, like 10-20MB. 64K reminds me of the days of Windows NT4, with tiny CPUs and precious-little disk space.