MSS: (WarningLevel) Percentage threshold for the security event log at which the system will generate a warningID: oval:org.secpod.oval:def:8840 | Date: (C)2013-01-21 (M)2023-05-09 |
Class: COMPLIANCE | Family: windows |
The MSS: (WarningLevel) Percentage threshold for the security event log at which the system will generate a warning setting should be configured correctly.
The registry value entry WarningLevel was added to the template file in the HKEY_LOCAL_MACHINE\\ SYSTEM\\CurrentControlSet\\Services\\Eventlog\\Security\\ registry key. The entry appears as MSS: (WarningLevel) Percentage threshold for the security event log at which the system will generate a warning in the SCE. This setting can generate a security audit in the Security event log when the log reaches a user-defined threshold. Note If log settings are configured to Overwrite events as needed or Overwrite events older than x days, this event will not be generated.
Fix:
(1) GPO: Computer Configuration\Windows Settings\Security Settings\Local Policies\Security Options\MSS: (WarningLevel) Percentage threshold for the security event log at which the system will generate a warning
(2) KEY: HKLM\SYSTEM\CurrentControlSet\Services\Eventlog\Security\WarningLevel
Platform: |
Microsoft Windows Server 2008 R2 |