ABR 11.5 causes thousands of Windows Event ID 4674 Audit Success Sensitive Privilege Use entries
Greetings,
I am currently utilizing ABR 11.5 in my network. I have an Admin workstation that has ABR 11.5 installed on it; I use this to manage a few clients that have ABR 11.5 installed on them as well. I have noticed after reviewing my Security Logs in Windows Event Viewer that the systems that have ABR 11.5 installed in them generate THOUSANDS of Windows Event ID 4674 Audit Success Sensitive Privilege Use entries. I know that it is Acronis that is generating these entries because the other systems in my network, which are identical in configuration, that do not have ABR installed on them are not generating the same entries in the Security Log. These particular entries will keep generating until the machine is eventually turned off. I have configured the Security logs to archive when full but eventually I could run out of hard drive space because these entries are filling the Security Log.
Here is the details of the entry. I have changed some of the names in the entry due to sensitivity:
' An operation was attempted on a privileged object
Subject:
Security ID: DOMAIN\admin.user
Account Name admin.user
Account Domain DOMAIN
Login ID: 0x12345
Object:
Object Server: Security
Object Type: -
Object Name: -
Object Handle: 0x1234
Process Information:
Process ID: 0x1234
Process Name: C:\Windows\System32\wbem\WmiPrvSE.exe
Requested Operation:
Desired Access: 2032127
Privileges: SeTakeOwnershipPrivilege '
I am the administrative user on the machine that generated this event log; so "admin.user" is me. What I want to know is this:
1) What role does the WmiPrvSE.exe play in the whole scheme of ABR?
2) Why is this generating so many audit entries on my system?