We are running 8 exchange server backups in our Infra. Windows security event logs increasing in huge while NetBackup exchange backup running.
Below is the windows event logs captured in server every seconds.
An operation was attempted on a privileged object.
Logon ID: 0x2BBFA3
Object Server: Security
Object Type: -
Object Name: -
Object Handle: 0x3dc
Process ID: 0x3f9c
Process Name: C:\Program Files\Veritas\NetBackup\bin\bpinetd.exe
Desired Access: 1048576
Event ID 4674
bpinetd is the process that initiates the comms service. This is needed for connectivity between the client and server.
Extract from Backup and restore startup process section in NBU Logging Guide:
A daemon that executes on all servers and clients is the NetBackup client daemon (service),
bpcd. On UNIX clients, inetd starts bpcd automatically so no special actions are
required. On Windows clients, bpinetd performs the same functions as inetd.
So, IMHO, perfectly normal.
We have not see this abnormality before. Almost 150 GB of my C drive occupied by the security event logs every time exchange backup runs. Even we have not done any changes at OS and security level.