MSS: (WarningLevel) Percentage threshold for the security event log at which the system will generate a warningID: oval:org.secpod.oval:def:57172 | Date: (C)2019-07-06 (M)2023-07-04 |
Class: COMPLIANCE | Family: windows |
The registry value entry WarningLevel was added to the template file in the HKEY_LOCAL_MACHINE\ SYSTEM\CurrentControlSet\Services\Eventlog\Security\ registry key. The entry appears as MSS: (WarningLevel) Percentage threshold for the security event log at which the system will generate a warning in the SCE.
This setting can generate a security audit in the Security event log when the log reaches a user-defined threshold.
Note If log settings are configured to Overwrite events as needed or Overwrite events older than x days, this event will not be generated.
Fix:
(1) GPO: Computer Configuration\Windows Settings\Security Settings\Local Policies\Security Options!The entry appears as MSS: (WarningLevel) Percentage threshold for the security event log at which the system will generate a warning in the SCE.
(2) REG: HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\Eventlog\Security!WarningLevel
Platform: |
Microsoft Windows Server 2019 |