Event ID 4006 MSComplianceAudit

Borislav Vitanov 81 Reputation points
2021-01-18T13:18:41.43+00:00

Hello guys,
I have one a little bit annoying event in the logs:

Log Name: Application
Source: MSComplianceAudit
Date: 1/18/2021 2:09:19 PM
Event ID: 4006
Task Category: LogReader
Level: Warning
Keywords: Classic
User: N/A
Computer: mailserver1.domain.com
Description:
The LogReader queue for log prefix audit is full. Reader will not parse it until the queue is no longer full.
Event Xml:
<Event xmlns="http://schemas.microsoft.com/win/2004/08/events/event">
<System>
<Provider Name="MSComplianceAudit" />
<EventID Qualifiers="32768">4006</EventID>
<Level>3</Level>
<Task>4</Task>
<Keywords>0x80000000000000</Keywords>
<TimeCreated SystemTime="2021-01-18T13:09:19.000000000Z" />
<EventRecordID>56863123</EventRecordID>
<Channel>Application</Channel>
<Computer>mailserver1.domain.com</Computer>
<Security />
</System>
<EventData>
<Data>audit</Data>
</EventData>
</Event>

and I couldn't find much helpful information about. Does someone know how to get rid of it?

Thanks

Exchange Server Management
Exchange Server Management
Exchange Server: A family of Microsoft client/server messaging and collaboration software.Management: The act or process of organizing, handling, directing or controlling something.
7,386 questions
0 comments No comments
{count} votes

3 answers

Sort by: Most helpful
  1. Lucas Liu-MSFT 6,161 Reputation points
    2021-01-19T04:26:08.753+00:00

    Hi @Borislav Vitanov ,
    Is there a issue with any Exchange functions?
    According to the event information, this seems to be a event related to the database, please try to restart the Microsoft Exchange Search service.
    In addition, only this event log is difficult to determine the cause of the warning event, is there have any other related event log in the Event View? If so, please share with us, please pay attention to covering the personal information.

    ----------

    If the response is helpful, please click "Accept Answer" and upvote it.
    Note: Please follow the steps in our documentation to enable e-mail notifications if you want to receive the related email notification for this thread.

    0 comments No comments

  2. Borislav Vitanov 81 Reputation points
    2021-01-21T10:38:19.073+00:00

    Hi @Lucas Liu-MSFT

    in general everything is working on Exchange (outlook etc.) . We have as well another warnings in the logs but I'm not sure which one would be related to this one. We reboot our Exchange server every Saturday but the events still come up. I've even temporary set the auditing logs to 0 days and after a couple of hours set it back to 30 days. We have as well Veeam as backup to backup and clean the logs. We have as well a scheduled task to cleaner IIS logs older than 7 days.

    Thanks


  3. Borislav Vitanov 81 Reputation points
    2021-03-08T09:40:19.707+00:00

    Hi @Lucas Liu-MSFT

    the so called solution for me was to turn off the audit on all mailboxes - users, shared mailboxes etc.

    after this the event stopped.

    I couldn't find anything related how to clean the logs.

    Thanks

    0 comments No comments