10-25-2017 01:48 AM
Hi,
We are running 8 exchange server backups in our Infra. Windows security event logs increasing in huge while NetBackup exchange backup running.
Below is the windows event logs captured in server every seconds.
An operation was attempted on a privileged object.
Subject:
Security ID:
Account Name:
Account Domain:
Logon ID: 0x2BBFA3
Object:
Object Server: Security
Object Type: -
Object Name: -
Object Handle: 0x3dc
Process Information:
Process ID: 0x3f9c
Process Name: C:\Program Files\Veritas\NetBackup\bin\bpinetd.exe
Requested Operation:
Desired Access: 1048576
Privileges: SeBackupPrivilege
Event ID 4674
10-25-2017 02:16 AM
bpinetd is the process that initiates the comms service. This is needed for connectivity between the client and server.
Extract from Backup and restore startup process section in NBU Logging Guide:
A daemon that executes on all servers and clients is the NetBackup client daemon (service),
bpcd. On UNIX clients, inetd starts bpcd automatically so no special actions are
required. On Windows clients, bpinetd performs the same functions as inetd.
So, IMHO, perfectly normal.
10-25-2017 03:38 AM
We have not see this abnormality before. Almost 150 GB of my C drive occupied by the security event logs every time exchange backup runs. Even we have not done any changes at OS and security level.
10-25-2017 06:08 AM
I doubt Netbackup is to blame. I would start asking around if someones has set increased logging level.