Unable to Log Events to Security Logs Event ID 521

Unable to Log Events to Security Logs Event ID 521

In this article  

  • Issue description

  • Prerequisites

  • Possible causes

  • Resolution

  • Related topics and articles

  • How to reach support

 

Issue description  

Event ID 521 is generated when the system fails to write audit events to the Security Log. This typically indicates a serious problem with the auditing mechanism on the system. When this event occurs, critical audit data might be lost, impacting security monitoring, forensic investigations, and compliance requirements. It is essential to resolve this promptly to restore reliable audit logging.

Prerequisites  

  • ADAudit Plus service account or local system account if used should have the Manage auditing and security log privilege.

  • Ensure the Windows Event Log service is running and set to Automatic startup.

  • Ensure no conflicting Group Policies restrict security logging or overwrite settings.

Possible cause  s

  • The Security log is full and set to not overwrite events.

  • Insufficient permissions for the audit process to write to the log.

  • Corruption or misconfiguration in the Windows Event Log service.

  • Group Policy settings that prevent overwriting or managing log sizes.

 

 

Resolution

ADAudit Plus requires events to be logged correctly in the Event Viewer. If Event ID 521 is generated, it indicates that the system has failed to log security events resulting in log collection failure. To increase the security log size in the Event Viewer:

    • Start > run > eventvwr.

    • Double click Windows Logs > right click > Security > Properties.

    • Set the Maximum log size (KB): to 4194240 KB which is 4GB.

    • Click Apply and OK.

 

   

Issue: Windows Event Log service is not running

  • Open Run (Win + R), type services.msc, and press Enter.

  • Locate the Windows Event Log service, ensure it is running and set to automatic.

  • If the service is stopped, right-click and start the service.

Related topics and documentation

 

  When and where to reach support

  • If the issue persists, contact our support team here

                  New to ADSelfService Plus?

                    • Related Articles

                    • Understanding how ADAudit Plus handles security Event Logs and Archiving

                      In this article : Question Explanation Important considerations Related topics and articles Question I would like to know if there’s a way to store historical security event logs within ADAudit Plus, access older logs, and view the raw event data. ...
                    • No Data Available in the Printer Auditing report

                      In this article: Issue description Possible causes Prerequisites Resolution Related topics and articles How to reach support Issue description This issue occurs when ADAudit Plus is unable to collect logs related to printer auditing. This can be due ...
                    • Troubleshooting Entra ID Log Collection Error: 'Lifetime validation failed - Token Expired'

                      In this article: Issue description Prerequisites Possible cause Resolution Related topics and articles How to reach support Issue description While ADAudit Plus is collecting logs from Entra ID modules, the following error occurs: Lifetime validation ...
                    • No data available in local account management

                      In this article Issue description Possible causes Prerequisites Resolution Related topics and articles When and how to contact support Issue description The Local Account Management reports in ADAudit Plus display "No Data Available," preventing the ...
                    • No data available in computer startup and shutdown auditing

                      In this article Issue description Prerequisites Possible causes Resolution Related topics and articles When and how to contact support Issue description The Computer Startup and Shutdown reports in ADAudit Plus display "No Data Available," preventing ...