Why obtain "The security log on this system is full" after install Win11 22H2

Castro Cocotl, Favio Uriel 31 Reputation points
2022-11-11T16:19:10.547+00:00

In the most recent laptops that I installed the latest update of Windows 11 (22H2) every so often that I restart the computer I get the message "The security log on this system is full". I enter the event viewer with another credentials and choose the "Overwrite events" option but after a while it doesn't allow me to log in showing the same previous message and changing back to the "don't overwrite events" option.

Windows for business | Windows Client for IT Pros | User experience | Other
{count} votes

30 answers

Sort by: Most helpful
  1. Bill Moller 1 Reputation point
    2023-02-15T13:14:34.5166667+00:00

    Is anyone from Microsoft on this thread?

    0 comments No comments

  2. Anonymous
    2023-02-15T18:56:24.88+00:00

    We have found in our Default Domain Group Policy Object that it was set to retain events for 90 days. We believe this is what is causing the "Overwrite" setting to be removed on reboot. We have set the GPO to "Not Defined" for event retention. We have set on the laptop that has this issue to overwrite event logs as needed. We restarted the laptop and it kept the overwrite setting. We are going to let this go for a couple of weeks to see if this fixed the issue.


  3. Bill Moller 1 Reputation point
    2023-02-23T14:36:55.97+00:00

    Crickets from Microsoft. Maybe "broken" is the new expected behavior...

    0 comments No comments

  4. Luke Kiunga Ngore 0 Reputation points
    2023-07-03T12:09:32.5166667+00:00

    I faced a similar problem and enabling/ disabling the following policies via GPO sorted the issue out.

    1. Computer Configuration\Windows Settings\Security Settings\Local Policies\Security Options\Audit: Shut down system immediately if unable to log security audits
      Set the security policy to > disabled
    2. Computer Configuration > Administrative Templates > Windows Component > Event Log Service > Security > Control Event Log Behavior when the log file reaches its maximum size,

    Set the security policy to > disabled

    1. Computer Configuration\Windows Settings\Security Settings\Event Log\Retention method for security log Audit.

    Define this policy setting > select overwrite events as needed

    0 comments No comments

  5. Deleted

    This answer has been deleted due to a violation of our Code of Conduct. The answer was manually reported or identified through automated detection before action was taken. Please refer to our Code of Conduct for more information.


    Comments have been turned off. Learn more

Your answer

Answers can be marked as 'Accepted' by the question author and 'Recommended' by moderators, which helps users know the answer solved the author's problem.