asked on
Event Type: Success Audit
Event Source: Security
Event Category: Account Logon
Event ID: 672
Date: 7/22/2008
Time: 8:56:51 AM
User: NT AUTHORITY\SYSTEM
Computer: SERVER_NAME
Description:
Authentication Ticket Request:
User Name: SERVER_NAME$
Supplied Realm Name: DOMAIN.LOCAL
User ID: DOMAIN\SERVER_NAME$
Service Name: krbtgt
Service ID: DOMAIN\krbtgt
Ticket Options: 0x40810010
Result Code: -
Ticket Encryption Type: 0x17
Pre-Authentication Type: 2
Client Address: 127.0.0.1
Certificate Issuer Name:
Certificate Serial Number:
Certificate Thumbprint:
Event Type: Success Audit
Event Source: Security
Event Category: Logon/Logoff
Event ID: 552
Date: 7/22/2008
Time: 8:56:51 AM
User: NT AUTHORITY\SYSTEM
Computer: SERVER_NAME
Description:
Logon attempt using explicit credentials:
Logged on user:
User Name:
Domain:
Logon ID: (0x0,0x914F)
Logon GUID: -
User whose credentials were used:
Target User Name: SERVER_NAME$
Target Domain:
Target Logon GUID: -
Target Server Name: SERVER_NAME.our-domain.com
Target Server Info: SERVER_NAME.our-domain.com
Caller Process ID: 1632
Source Network Address: -
Source Port: -
Event Type: Failure Audit
Event Source: Security
Event Category: Logon/Logoff
Event ID: 537
Date: 7/22/2008
Time: 8:56:51 AM
User: NT AUTHORITY\SYSTEM
Computer: SVR
Description:
Logon Failure:
Reason: An error occurred during logon
User Name: SERVER_NAME$
Domain: DOMAIN
Logon Type: 3
Logon Process: ÈùÒ
Authentication Package: NTLM
Workstation Name: SERVER_NAME
Status code: 0xC000006D
Substatus code: 0x0
Caller User Name: -
Caller Domain: -
Caller Logon ID: -
Caller Process ID: -
Transited Services: -
Source Network Address: -
Source Port: -