Hi @Sayed Junaid ,
As regards to the EventID 1102 which means that audit logs are cleared, based on my research it usually shows up in the SECURITY logs:
But “AgentLogFile=Application” included in the logs you mentioned earlier indicates this is an Application event which will be located in the APPLICATION logs:
Also according to description in this official document, this event log doesn't seem to be related to "Microsoft-Filtering-FIPFS" and "MS Filtering Engine Update process is running" mentioned in the logs you shared above:
Therefore, it seems to me that the event ID 1102 in your case is different from the event which means "Windows Security audit log was cleared".
While after searching a lot there isn't an official article explaining this application event 1102 specifically for Exchange server, according to the clues I found from some other threads(like "That is the anti-malware update" in this thread ), events involving "MS Filtering Engine Update process" in the APPLICATION logs usually occurs when Exchange is downloading the antimalware engine and definition updates. I checked it in my test lab and also noticed some events for FIPFS, all these events have "NETWORK SERVICE" showing as the USER, so it looks normal that "User=NETWORK SERVICE" is contained in your events:
With the above being said, and considering that the "Message=MS Filtering Engine Update process is running" in the event logs doesn't sound like there's anything wrong, I assume you can rest assured and just ignore this event.
Furthermore, noticed the thread below which discussed the application Event 1102, and the reply provided there by Joyce also indicates such kind of logs can be ingored safely:
Microsoft-Filtering-FIPFS
"So it should be different if it comes in security or application event id 1102. And the level of the log above is information, generally Information messages indicate a successful action. We can ignore such kind of logs safely."
If an Answer is helpful, please click "Accept Answer" and upvote it.
Note: Please follow the steps in our documentation to enable e-mail notifications if you want to receive the related email notification for this thread.