Announcement

Collapse
No announcement yet.

Excessive Security Log Events - Event ID 5379

Collapse
X
 
  • Filter
  • Time
  • Show
Clear All
new posts

  • Excessive Security Log Events - Event ID 5379

    I noticed that there are 50+ security events (ID 5379) each minute in the Event Viewer under Windows Logs > Security.
    This event type is about reading credentials from Credential Manager (Audit Success Messages - Credential Manager credentials were read).
    I think this is related to Chaos licensing system because of TargetName in Event Data: ChaosULA

    Data for typical message:
    Subject:
    Security ID: *****
    Account Name: *****
    Account Domain: *****
    Logon ID: *****
    Read Operation: Enumerate Credentials

    EventData
    SubjectUserSid *****
    SubjectUserName *****
    SubjectDomainName *****
    SubjectLogonId 0x1432f5b62
    TargetName ChaosULA:ula
    Type 1
    CountOfCredentialsReturned 1
    ReadOperation %%8099
    ReturnCode 0
    ProcessCreationTime 2023-03-31T08:44:59.5961121Z
    ClientProcessId 30268


    Why is that? Is this something wrong with my computer?
    I don't think such flooding of security events is normal...​

  • #2
    so I unistalled everything from Chaos: events stopped appearing.
    After installing V-ray and licence server - events comes back.
    When I stopped everything (Cosmos Browser, Licence Server and Unified Logon) - no more security events.

    What can I do to prevent this flooding of secutity events? And to use V-ray in the same time, of course...​

    Comment


    • #3
      Just uninstall Chaos Unified Login.
      Kostadin Botev

      Technical Support Representative
      Contact Support

      Chaos

      Comment


      • #4
        Uninstalled and nothing changed...
        I have to stop BOTH Cosmos Browser and Chaos Licence Server to prevent this events to show up.
        If any of this is working events are generated and ClientProcessId in event details shows PID of cbservice.exe or vrol.exe.

        Maybe it's supposed to be like that?

        Comment

        Working...
        X