We've been having this issue with various alerts spamming the event log such as port interface speed changes, some ifDescription change (logs thousands per second) and this new one, saying this (or variations of it): Local Area Connection* 7-QoS Packet Scheduler-0000 Physical Address changed from BAC420524153 to 903920524153
The question is, we're not doing anything like MAC spoofing or anything crazy like that, so why would the physical address keep changing over and over again? This will be the third SQL job I have to setup to get rid of these useless events that keep filling up the event log.