Windows Security Log Event ID 4612

Operating Systems Windows 2008 R2 and 7
Windows 2012 R2 and 8.1
Windows 2016 and 10
Windows Server 2019 and 2022
Category
 • Subcategory
System
 • System Integrity
Type Success
Corresponding events
in Windows 2003
and before
516  

4612: Internal resources allocated for the queuing of audit messages have been exhausted, leading to the loss of some audits.

On this page

This event has not been observed but would indicate that an extremely high period of activity prevented Windows from logging a number of security events. I haven't been able to produce this event. Have you? If so, please start a discussion (see above) and post a sample along with any comments you may have! Don't forget to sanitize any private information.

Microsoft reports they have tested logging to over 10,000 events per second. However a bottleneck in disk I/O or other resources could also cause a problem.  If you see this event it probably means you are auditing too much.

Free Security Log Resources by Randy

Description Fields in 4612

  • Number of audit messages discarded: %1

Setup PowerShell Audit Log Forwarding in 4 Minutes

 

Examples of 4612

Internal resources allocated for the queuing of audit messages have been exhausted, leading to the loss of some audits.

Number of audit messages discarded: %1

This event is generated when audit queues are filled and events must be discarded.  This most commonly occurs when security events are being generated faster than they are being written to disk, or when the auditing system loses connectivity to the event log, such as when the event log service is stopped.

Top 10 Windows Security Events to Monitor

Free Tool for Windows Event Collection



 

Upcoming Webinars
    Additional Resources