Mombu the Microsoft Forum sponsored links

Go Back   Mombu the Microsoft Forum > Microsoft > more security log info
User Name
Password
REGISTER NOW! Mark Forums Read

sponsored links


Reply
 
1 8th August 11:23
sigm ‚gb±Ë¬²*²hœ®‹(~×(
External User
 
Posts: 1
Default more security log info



We have some inetersting activity in our security log during nighttime hours.
How do I tell if it is just network overhead protocols, or illegimate
attempts to access the network? Some of the event IDs are:
538,540,565,576,672,673,674, and 680. I would assume that some of these are
related to users/computers locking their workstation at night and the systems
are still responding to the server. Is this correct or do I have a serious
problem here. I've directed the question to my IS manager, and she does not
have any idea in regards to this.
  Reply With Quote


  sponsored links


2 8th August 11:23
steven l umbach
External User
 
Posts: 1
Default more security log info



It is not unusual to see events logged. Some of those are kerberos related
which may be computers renewing their tickets as they expire. Computers also
authenticate in a domain without any user logged on. I would not be too
concerned unless you have a lot of failures, particularly for user
"administrator" which could indicate hack attempts. The link below will
explain in more detail what some of those events mean. --- Steve

http://www.microsoft.com/technet/security/guidance/secmod144.mspx
  Reply With Quote
Reply


Thread Tools
Display Modes




Copyright © 2006 SmartyDevil.com - Dies Mies Jeschet Boenedoesef Douvema Enitemaus -
666