Security Channel Publishing

Applies To: Windows Server 2008

As events are delivered to the Event Log service to be saved in the Security log, they pass through the operating system (OS) kernel. If the kernel does not have enough resources to deliver the events to the Event Log service (which can happen if the Event Log service has to handle a large number of events), then the events are lost. This can compromise the security of the system and ability of administrators, support personnel, and automated utilities to troubleshoot and diagnose problems.

Events

Event ID Source Message

1101

Microsoft-Windows-Eventlog

Audit events have been dropped by the transport. %1

1106

Microsoft-Windows-Eventlog

Events have been dropped by the event logging service. The reason code is %1.

Security Channel

Management Infrastructure