In a Windows network with 1-Win2k, 2-Win2003 servers, 30 PC's (29-xp, 1-vista) all in a domain. The following messages were found in the logs this morning. The addres book log appeard about 10 times.
How can I determine where and who did it? It appears to be a remote user, but I need to clarify it.
Event Type: Success Audit
Event Source: Security
Event Category: Directory Service Access
Event ID: 836
Date: 11/1/2009
Time: 4:59:22 AM
User: NT AUTHORITY\SYSTEM
Computer: HPM1
Description:
Destination DRA: CN=NTDS Settings,CN=HPM1,CN=Servers,CN=Default-First-Site-Name,CN=Sites,CN=Configuration,DC=xxx,DC=ads
Source DRA: CN=NTDS Settings,CN=HPM3,CN=Servers,CN=Default-First-Site-Name,CN=Sites,CN=Configuration,DC=xxx,DC=ads
Naming Context: DC=xxx,DC=ads
Options: 85
Session ID: 453
Start USN: 2461457
Event Type: Information
Event Source: MSExchangeIS
Event Category: General
Event ID: 9678
Date: 11/1/2009
Time: 5:11:16 AM
User: N/A
Computer: HPM1
Description:
User "NT AUTHORITY\SYSTEM" has attempted a full download of the Offline Address Book. Please note that it may require several attempts before the download is complete.
by: stehardy88Posted on 2009-11-01 at 07:57:01ID: 25714115
No - this entry is generated when you turn on "audit directory service" policy. If you're not wanting to view this data (which I'm guessing you don't), then you're best looking at and tweaking your Default GPO Auditing Policies.
Log onto your DC, edit Domain Default GPO and change the following: Computer configuration>Windows settings> Security settings>Local Policys>Security options>Audit policy