Event id: 4739 shows garbage characters inside


hello, 

the scenario is:

windows 2012r2 std, , want audit policy changes, in gpo \policies\windows setting\secutirysettings\accountpolicies\password policy\

when configure "password policy modified"   audit , in de event viewer shows  invalid characters this:

domain policy changed.

change type: password policy modified

subject:
security id: system
account name: sv-xxx-xxx-xxx
account domain: xxx
logon id: 0x3e7

domain:
domain name: gcatst
domain id: gcatst\

changed attributes:
min. password age: Ì
max. password age: 䀀Ì
force logoff: 䀀-
lockout threshold: -
lockout observation window: -
lockout duration: -
password properties: -
min. password length: 1
password history length: 2
machine account quota: -
mixed domain mode: -
domain behavior version: -
oem information: -

additional information:
privileges: -



in details shows

event not displayed correctly because underlying xml not formed. below raw text of event.

4739001356900x80200000000000002427680securitysv-123-tst-ad01.tst.intranet.xxxt.orgpassword policysts-1-5-21-2009545363-352543261-3975245381s-1-5-18sv-srv-tst-ad01$xxtst0x3e7-Ì䀀Ì䀀-----12---- 

any idea resolution??

thanks in advance.


hi jose,

would please let me confirm whether password policy correctly applied client computers? did other events display correctly? garbage characters occurred in event 4739?

please check if necessary updates installed on windows server 2012 r2. meanwhile, please refer following kb , check if can you.

security event id 4739 not displayed correctly in windows server 2008 r2 , windows 7

if update, please feel free let me know.

hope helps.

best regards,

justin gu



Windows Server  >  Management



Comments

Popular posts from this blog

Error: 0x80073701 when trying to add Print Services Role in Windows 2012 Standard

Disconnecting from a Windows Server 2012 R2 file sharing session on a Windows 7,8,10 machine

Event ID 64,77,1008 Certificates Events Windows Server 2008, 2008R2