Why obtain "The security log on this system is full" after install Win11 22H2

Castro Cocotl, Favio Uriel 31 Reputation points
2022-11-11T16:19:10.547+00:00

In the most recent laptops that I installed the latest update of Windows 11 (22H2) every so often that I restart the computer I get the message "The security log on this system is full". I enter the event viewer with another credentials and choose the "Overwrite events" option but after a while it doesn't allow me to log in showing the same previous message and changing back to the "don't overwrite events" option.

Windows 11
Windows 11
A Microsoft operating system designed for productivity, creativity, and ease of use.
8,220 questions
{count} votes

30 answers

Sort by: Most helpful
  1. Armin 21 Reputation points
    2022-12-05T14:56:14.613+00:00

    Hi,
    as a workaround I've configured a GPO for the settings of security event log and applied it to the affected machines. This seems to work.
    However I agree that this is something Microsoft should look into.

    4 people found this answer helpful.

  2. Hitesh Chaudhary 6 Reputation points
    2022-12-20T17:08:10.137+00:00

    Hi All,

    I am also experiencing the same issue with the new laptops we setup which are practically Windows 11 out of the box.

    One thing I found out as a Fix is that if you set the following group policy to Disabled and do a gpupdate /force it changes to Overwrite events as needed on event viewer.

    Go to Edit Group policy on the target computer

    Select Computer Configuration > Administrative Templates > Windows Component > Event Log Service > Security > Control Event Log Behavior when the log file reaches its maximum size, Ser it to Disable.

    For now my log size is 100096KB and is already reached to its maximum size but still the option on my Event Viewer is set to Overwrite events as needed with the above change I made.

    Please try the Fix I suggested and let me know the results.

    1 person found this answer helpful.

  3. Wesley Li-MSFT 4,376 Reputation points Microsoft Vendor
    2022-11-16T03:28:04.29+00:00

    Hello

    You can try to check if you have the following policy enabled:
    Computer Configuration\Windows Settings\Security Settings\Local Policies\Security Options\Audit: Shut down system immediately if unable to log security audits
    If so, please consider disabling the policy.

    You can also clear log, increase the maximum log size or let it overwrite older entries. Refer to: Start --> Run --> EVENTVWR.MSC --> Right click Security log, go to Properties. Then, you can clear log, increase maximum log size or choose “Overwrite events as needed (oldest events first).

    Best Regards,
    Wesley Li

    0 comments No comments

  4. Armin 21 Reputation points
    2022-11-30T08:07:17.753+00:00

    Hi there,

    we do have the same problem on different Computers with Win11 22H2. Regardless of the settings we make in even log's properties, the settings switch back to "do not overwrite" when the computer reboots. As a result the user cannot log it.
    Any other ideas?

    Armin

    0 comments No comments

  5. Darrelle Alexander 1 Reputation point
    2022-11-30T16:40:29.767+00:00

    We are also experiencing this error on our domain. So far, we've identified four machines with the issue, all running 22H2 (one was a clean install and the other three were upgrades). I think it's safe to say at this point that Microsoft needs to look into this. The fix posted does not apply to us; our domain functionality level is 2016 and we do not have that policy enabled on our DCs. I also came across a reddit post that had the same issue where they resolved it by upgrading their domain level to 2022, but that should not be a fix for a problem that clearly was introduced by 22H2. All of the machines were running 21H2 and had no issues until upgrading to 22H2 within the last two weeks, so something has triggered this for systems that are domain joined.

    0 comments No comments