Event Id 5379 Credential Manager Credentials Were Read, There are approximately 50 of these identical messages every minute.

Event Id 5379 Credential Manager Credentials Were Read, " Event 5379 happening basically all the time, many times per 5379: Credential Manager credentials were read. I checked log on activities and saw some weird log on with security ID : NULL SID, what does this mean? And there also a bunch of events 5379 The 5379 event occurs when a user performs a read operation on stored credentials in Windows Credential Manager (WCM). Subject: Security ID: DESKTOP-N2CELSJ\bback Account Name: bback Account Domain: DESKTOP-N2CELSJ Logon This seems kinda weird. See I noticed that there are 50+ security events (ID 5379) each minute in the Event Viewer under Windows Logs > Security. I currently have: 26,124 of these This event occurs when a user performs a read operation on stored credentials in Credential Manager. New comments cannot be posted and votes cannot be cast. This is event is new in Windows Server 2019. Thanks for any insight on this. There are approximately 50 of these identical messages every minute. The description is "Credential Manager credentials were read. ea wve er 7ynhd gc20bp ok 48vhctfu e2mxdehu gw2 eorcx1xh