question

BorislavVitanov-1003 avatar image
0 Votes"
BorislavVitanov-1003 asked ·

Event ID 4006 MSComplianceAudit

Hello guys,
I have one a little bit annoying event in the logs:

Log Name: Application
Source: MSComplianceAudit
Date: 1/18/2021 2:09:19 PM
Event ID: 4006
Task Category: LogReader
Level: Warning
Keywords: Classic
User: N/A
Computer: mailserver1.domain.com
Description:
The LogReader queue for log prefix audit is full. Reader will not parse it until the queue is no longer full.
Event Xml:
<Event xmlns="http://schemas.microsoft.com/win/2004/08/events/event">;
<System>
<Provider Name="MSComplianceAudit" />
<EventID Qualifiers="32768">4006</EventID>
<Level>3</Level>
<Task>4</Task>
<Keywords>0x80000000000000</Keywords>
<TimeCreated SystemTime="2021-01-18T13:09:19.000000000Z" />
<EventRecordID>56863123</EventRecordID>
<Channel>Application</Channel>
<Computer>mailserver1.domain.com</Computer>
<Security />
</System>
<EventData>
<Data>audit</Data>
</EventData>
</Event>

and I couldn't find much helpful information about. Does someone know how to get rid of it?

Thanks

office-exchange-server-administration
10 |1000 characters needed characters left characters exceeded

Up to 10 attachments (including images) can be used with a maximum of 3.0 MiB each and 30.0 MiB total.

LucasLiu-MSFT avatar image
0 Votes"
LucasLiu-MSFT answered ·

Hi @BorislavVitanov-1003 ,
Is there a issue with any Exchange functions?
According to the event information, this seems to be a event related to the database, please try to restart the Microsoft Exchange Search service.
In addition, only this event log is difficult to determine the cause of the warning event, is there have any other related event log in the Event View? If so, please share with us, please pay attention to covering the personal information.



If the response is helpful, please click "Accept Answer" and upvote it.
Note: Please follow the steps in our documentation to enable e-mail notifications if you want to receive the related email notification for this thread.


·
10 |1000 characters needed characters left characters exceeded

Up to 10 attachments (including images) can be used with a maximum of 3.0 MiB each and 30.0 MiB total.

BorislavVitanov-1003 avatar image
0 Votes"
BorislavVitanov-1003 answered ·

Hi @LucasLiu-MSFT

in general everything is working on Exchange (outlook etc.) . We have as well another warnings in the logs but I'm not sure which one would be related to this one. We reboot our Exchange server every Saturday but the events still come up. I've even temporary set the auditing logs to 0 days and after a couple of hours set it back to 30 days. We have as well Veeam as backup to backup and clean the logs. We have as well a scheduled task to cleaner IIS logs older than 7 days.

Thanks

· 2 ·
10 |1000 characters needed characters left characters exceeded

Up to 10 attachments (including images) can be used with a maximum of 3.0 MiB each and 30.0 MiB total.

Hi @BorislavVitanov-1003 ,
Did you change any settings before this event log was displayed?
Are there have any logs related Exchange auditing or database?
Based on my knowledge, the MS complianceAudit service could provide Exchange auditing features. Can these related functions work normally?
And as mentioned above, this event also related to database, Can functions such as search work normally?
According to the event information, this is a warning event. Normally this type of event is not produced by an obvious error. So if we want to find the root cause, we need more relevant logs for analysis.
In addition, if it does not affect the normal work of Exchange server, I think you can ignore it temporarily.



If the response is helpful, please click "Accept Answer" and upvote it.

0 Votes 0 ·

Hi @BorislavVitanov-1003 ,
It's long time no receive your reply, I want to confirm with you how thing going now?



If the response is helpful, please click "Accept Answer" and upvote it.
Note: Please follow the steps in our documentation to enable e-mail notifications if you want to receive the related email notification for this thread.


0 Votes 0 ·
BorislavVitanov-1003 avatar image
0 Votes"
BorislavVitanov-1003 answered ·

Hi @LucasLiu-MSFT

the so called solution for me was to turn off the audit on all mailboxes - users, shared mailboxes etc.

after this the event stopped.

I couldn't find anything related how to clean the logs.

Thanks

·
10 |1000 characters needed characters left characters exceeded

Up to 10 attachments (including images) can be used with a maximum of 3.0 MiB each and 30.0 MiB total.