My security log is overflowing with failure audits with various username accounts. The failures are happening every minute or so. It seems I will have a success audit followed by a couple failures. It keeps doing this every minute, and continually changes usernames every 4 or 5. Any help would be appreciated! Below is a few examples of the logs I are recieving. thanks for your help in advance!
p.s. we recently upgraded this server to windows 2003 and exchange 2003
Event Type: Failure Audit
Event Source: Security
Event Category: Object Access
Event ID: 565
Date: 7/25/2005
Time: 12:59:39 PM
User: (my domain name)\Temp1
Computer: SLNNT7
Description:
Object Open:
Object Server: Microsoft Exchange
Object Type: Microsoft Exchange Logon
Object Name: /o=(my domain name)/ou=NORFOLK/cn=Recipi
ents/cn=Te
mp1
Handle ID: -
Operation ID: {0,944494624}
Process ID: 4692
Process Name: D:\Program Files\Exchsrvr\BIN\store.e
xe
Primary User Name: SLNNT7$
Primary Domain: (my domain name)
Primary Logon ID: (0x0,0x3E7)
Client User Name: Temp1
Client Domain: (my domain name)
Client Logon ID: (0x0,0x384BD7DF)
Accesses: Unknown specific access (bit 8)
Privileges: -
Properties:
READ_CONTROL
WRITE_DAC
WRITE_OWNER
ACCESS_SYS_SEC
Unknown specific access (bit 3)
Unknown specific access (bit 9)
Unknown specific access (bit 10)
Unknown specific access (bit 12)
Unknown specific access (bit 15)
Send As
---
user
Access Mask: 0
For more information, see Help and Support Center at
http://go.microsoft.com/fwlink/events.asp.
Event Type: Success Audit
Event Source: Security
Event Category: Object Access
Event ID: 565
Date: 7/25/2005
Time: 12:59:18 PM
User: (my domain name)\jgresock
Computer: SLNNT7
Description:
Object Open:
Object Server: Microsoft Exchange
Object Type: Microsoft Exchange Database
Object Name: /O=(my domain name)/OU=NORFOLK/cn=Config
uration/cn
=Servers/c
n=SLNNT7/c
n=Microsof
t Private MDB
Handle ID: 0
Operation ID: {0,944488645}
Process ID: 4692
Process Name: D:\Program Files\Exchsrvr\BIN\store.e
xe
Primary User Name: SLNNT7$
Primary Domain: (my domain name)
Primary Logon ID: (0x0,0x3E7)
Client User Name: jgresock
Client Domain: (my domain name)
Client Logon ID: (0x0,0x384BC0A3)
Accesses: -
Privileges: -
Properties:
---
%{a8df74ba-c5ea-11d1-bbcb-
0080c76670
c0}
Unknown specific access (bit 8)
Create named properties in the information store
Create public folder
Access Mask: 0
For more information, see Help and Support Center at
http://go.microsoft.com/fwlink/events.asp.
Event Type: Failure Audit
Event Source: Security
Event Category: Object Access
Event ID: 565
Date: 7/25/2005
Time: 12:59:18 PM
User: (my domain name)\jgresock
Computer: SLNNT7
Description:
Object Open:
Object Server: Microsoft Exchange
Object Type: Microsoft Exchange Database
Object Name: /O=(my domain name)/OU=NORFOLK/cn=Config
uration/cn
=Servers/c
n=SLNNT7/c
n=Microsof
t Private MDB
Handle ID: 0
Operation ID: {0,944488646}
Process ID: 4692
Process Name: D:\Program Files\Exchsrvr\BIN\store.e
xe
Primary User Name: SLNNT7$
Primary Domain: (my domain name)
Primary Logon ID: (0x0,0x3E7)
Client User Name: jgresock
Client Domain: (my domain name)
Client Logon ID: (0x0,0x384BC0A3)
Accesses: Unknown specific access (bit 8)
Privileges: -
Properties:
---
Modify public folder deleted item retention
%{a8df74ba-c5ea-11d1-bbcb-
0080c76670
c0}
Unknown specific access (bit 0)
Unknown specific access (bit 1)
Unknown specific access (bit 2)
%{d74a8774-2289-11d3-aa62-
00c04f8eed
d8}
Administer information store
Unknown specific access (bit 0)
Unknown specific access (bit 1)
Unknown specific access (bit 3)
Modify public folder replica list
Unknown specific access (bit 0)
Unknown specific access (bit 2)
Unknown specific access (bit 4)
View information store status
Unknown specific access (bit 1)
Unknown specific access (bit 2)
Unknown specific access (bit 5)
Unknown specific access (bit 9)
Modify public folder quotas
Unknown specific access (bit 0)
Unknown specific access (bit 8)
Unknown specific access (bit 10)
Modify public folder ACL
Unknown specific access (bit 0)
Unknown specific access (bit 1)
Unknown specific access (bit 2)
Unknown specific access (bit 3)
Unknown specific access (bit 4)
Unknown specific access (bit 5)
Unknown specific access (bit 9)
Unknown specific access (bit 10)
Modify public folder admin ACL
ACCESS_SYS_SEC
Create top level public folder
Modify public folder expiry
DELETE
READ_CONTROL
Unknown specific access (bit 0)
Unknown specific access (bit 1)
Unknown specific access (bit 4)
Unknown specific access (bit 5)
Unknown specific access (bit 6)
Unknown specific access (bit 7)
Unknown specific access (bit 9)
Unknown specific access (bit 11)
Unknown specific access (bit 14)
Mail-enable public folder
Access Mask: 0
For more information, see Help and Support Center at
http://go.microsoft.com/fwlink/events.asp.
Start Free Trial