Security Compliance

SEM Manager crashes after a high number of alerts from Windows 7 or Windows Server 2008

This article provides instructions on tuning Windows Advanced Audit Policy Configuration on computers running Windows 7 and Windows Server 2008 to avoid overloading your SEM Manager with unnecessary alerts.

First published date

10/10/2018 7:46 PM

Last published date

5/28/2019 7:25 PM

Overview

Tune Windows Advanced Audit Policy Configuration on computers running Windows 7 and Windows Server 2008 to avoid overloading your Security Event Manager (formerly Log & Event Manager) Manager with unnecessary alerts. 

Product section

Security Event Manager

Cause

Advanced Audit Policy Configuration interacts with Windows Filtering Platform (WFP), a new application in Windows 7 and Windows Server 2008 that logs firewall and IPsec related events to the System Security Log. This advanced auditing is turned on by default, so if you have a SEM Agent on a server or workstation with WFP and you have not tuned it properly, it will log an extremely high number of events, eventually causing your SEM Manager to crash. 

For additional information about Advanced Audit Policy Configuration, see the Microsoft TechNet article on Advanced Security Auditing FAQ.

Resolution

By making a single change to Windows Advanced Audit Policy Configuration, you are telling Windows to favor Advance Audit Policy over your basic or standard audit policies, which causes the default Advanced Audit Policy to override any custom settings in Local Security Settings > Local Policies > Audit Policies. If you implement the following recommendation, you must also replicate your current basic/standard audit policies using Advanced Audit Policy Configuration.

Set the following subcategories to No Auditing to tune Windows Advanced Audit Policy logging for your SEM implementation:

  • Logon/Logoff > Audit IPsec Extended Mode
  • Logon/Logoff > Audit IPsec Main Mode
  • Logon/Logoff > Audit IPsec Quick Mode
  • Object Access > Audit Filtering Platform Connection
  • Object Access > Audit Filtering Platform Packet Drop
  • Policy Change > Audit Filtering Platform Policy Change
  • System > Audit IPsec Driver

To set a WFP subcategory to No Auditing using Group Policies (recommended):

  1. Launch Group Policy Management from Control Panel > Administrative Tools.
  2. Open Group Policy Management Editor for the domain policy you want to edit. For example, click Default Domain Policy, and then click Action > Edit.
  3. Under Computer Configuration, click Policies > Windows Settings > Security Settings > Advanced Audit Policy Configuration > Audit Policies.
  4. Click each policy under this node to view and edit its subcategories.
  5. In the right pane, click the subcategory you want to edit, and then click Action > Properties.
  6. On the Policy tab, select Configure the following audit events.

    Do not select Success or Failure.

To edit WFP auditing using local policy instead, open Administrative Tools > Local Security Policy, and then expand Advanced Audit Policy Configuration.


Disclaimer: Please note, any content posted herein is provided as a suggestion or recommendation to you for your internal use. This is not part of the SolarWinds software or documentation that you purchased from SolarWinds, and the information set forth herein may come from third parties. Your organization should internally review and assess to what extent, if any, such custom scripts or recommendations will be incorporated into your environment.  You elect to use third party content at your own risk, and you will be solely responsible for the incorporation of the same, if any.