Applies To: Windows Server 2008

As events are delivered to the Event Log service to be saved in the Security log, they pass through the operating system (OS) kernel. If the kernel does not have enough resources to deliver the events to the Event Log service (which can happen if the Event Log service has to handle a large number of events), then the events are lost. This can compromise the security of the system and ability of administrators, support personnel, and automated utilities to troubleshoot and diagnose problems.


Event ID Source Message



Audit events have been dropped by the transport. %1



Events have been dropped by the event logging service. The reason code is %1.

