Share via

Excessive "Audit Success" log events for event ID 5061 and 5058

Anonymous
2023-01-17T20:00:30+00:00

I'm getting these 2 event IDs logged every 5 seconds in my Security log on Windows 11 Pro.

This seems excessive. Also unsure why this is happening like clockwork, regardless what I'm doing on my laptop.

Anyone else seeing this? Wondering whether I can/need to update my Audit Policy. Thoughts?

Windows for home | Windows 11 | Security and privacy

Locked Question. This question was migrated from the Microsoft Support Community. You can vote on whether it's helpful, but you can't add comments or replies or follow the question.

0 comments No comments

1 answer

Sort by: Most helpful
  1. Anonymous
    2023-01-17T23:37:26+00:00

    Hi, I’m Nicole, I’ll be happy to help you out today.

    Event ID 5061 and 5058 are both related to the Windows Firewall service. Event ID 5061 is generated when the Windows Firewall service starts or stops, and Event ID 5058 is generated when the Windows Firewall service is configured.

    These events are logged every 5 seconds because the Windows Firewall service is checking its configuration every 5 seconds to ensure that it is properly configured and running. This is normal behavior for the Windows Firewall service.

    You can verify the configuration of your Windows Firewall service by going to the Control Panel and clicking on the Windows Firewall icon. From there, you can view the current firewall rules and settings.

    It's also worth to check your software security solutions you have installed, these messages could be caused by a third-party firewall, or check if there is any scheduled task or script that could be causing this log.

    Kindly regards,

    Was this answer helpful?

    0 comments No comments