Share via

can see audit logs are cleared by NETWORK SERVICE. Want to know if this is expected or not.

Sayed Mohammed Junaid 21 Reputation points
2021-08-28T09:09:02.187+00:00

Hi
Lately, I am seeing below logs from Exchange server:

"AgentDevice=WindowsLog AgentLogFile=Application Source=Microsoft-Filtering-FIPFS Computer=XYZ User=NETWORK SERVICE Domain=NETWORK SERVICE EventID=1102 EventIDCode=1102 EventType=4 EventCategory=0 RecordNumber=XYZ TimeGenerated=XYZ TimeWritten=XYZ Message=MS Filtering Engine Update process is running. "

Per event ID 1102 it means that audit logs are cleared. Can someone tell me why the audit logs are being cleared by NETWORK SERVICE? what exactly is causing it and whether it is expected? I confirmed with the team that they didn't make any changes.

Exchange | Exchange Server | Management
Exchange | Exchange Server | Management

The administration and maintenance of Microsoft Exchange Server to ensure secure, reliable, and efficient email and collaboration services across an organization.

Microsoft Security | Microsoft Entra | Microsoft Entra ID
Microsoft System Center | Other
0 comments No comments
{count} votes

Answer accepted by question author
  1. Vipul Sparsh 16,336 Reputation points Microsoft Employee Moderator
    2021-08-30T04:23:26.773+00:00

    @Sayed Mohammed Junaid Thanks for reaching out.

    You should not see event normally, I would highly recommend to investigate this as this might be a attempt to delete the proof of entry to the system or a breach.
    There might be genuine scenarios as well like any service getting upgraded which might try to do this. (Rare case)

    A thorough investigation needs to be happen either way.

    -----------------------------------------------------------------------------------------------------------------

    Please remember to "Accept Answer" if any answer/reply helped, so that others in the community facing similar issues can easily find the solution.

    1 person found this answer helpful.

1 additional answer

Sort by: Most helpful
  1. Yuki Sun-MSFT 41,466 Reputation points Moderator
    2021-08-30T04:44:51.593+00:00

    Hi @Sayed Mohammed Junaid

    As regards to the EventID 1102 which means that audit logs are cleared, based on my research it usually shows up in the SECURITY logs:
    127396-1.png
    But “AgentLogFile=Application” included in the logs you mentioned earlier indicates this is an Application event which will be located in the APPLICATION logs:
    127367-2.png

    Also according to description in this official document, this event log doesn't seem to be related to "Microsoft-Filtering-FIPFS" and "MS Filtering Engine Update process is running" mentioned in the logs you shared above:
    127456-3.png

    Therefore, it seems to me that the event ID 1102 in your case is different from the event which means "Windows Security audit log was cleared".

    While after searching a lot there isn't an official article explaining this application event 1102 specifically for Exchange server, according to the clues I found from some other threads(like "That is the anti-malware update" in this thread ), events involving "MS Filtering Engine Update process" in the APPLICATION logs usually occurs when Exchange is downloading the antimalware engine and definition updates. I checked it in my test lab and also noticed some events for FIPFS, all these events have "NETWORK SERVICE" showing as the USER, so it looks normal that "User=NETWORK SERVICE" is contained in your events:
    127379-4.png

    With the above being said, and considering that the "Message=MS Filtering Engine Update process is running" in the event logs doesn't sound like there's anything wrong, I assume you can rest assured and just ignore this event.

    Furthermore, noticed the thread below which discussed the application Event 1102, and the reply provided there by Joyce also indicates such kind of logs can be ingored safely:
    Microsoft-Filtering-FIPFS
    "So it should be different if it comes in security or application event id 1102. And the level of the log above is information, generally Information messages indicate a successful action. We can ignore such kind of logs safely."


    If an Answer is helpful, please click "Accept Answer" and upvote it.
    Note: Please follow the steps in our documentation to enable e-mail notifications if you want to receive the related email notification for this thread.

    2 people found this answer helpful.

Your answer

Answers can be marked as 'Accepted' by the question author and 'Recommended' by moderators, which helps users know the answer solved the author's problem.