All 4907 events comes from a service called wbengine.exe, present in our Active Directory servers.
This wbengine.exe service is part of "Active Directory Backup and Restore" solution (, and it is utilised in our processes.
Are this events a threat? Are normal events? What configurations have to do to configure properly wbengine.exe