Solved

Event Viewer being flooded with success logs

Posted on 2010-09-10
11
423 Views
Last Modified: 2012-05-10
My backup DC  Win 2000 box is being inundated with success login event logs from workstations. Getting dozens a second over many times during the day.  I believe this has just started because my SQL server also seems to be slower than usual. Ran a network virus scan but nothing picked up.  Any ideas?
0
Comment
Question by:infranetsupport
[X]
Welcome to Experts Exchange

Add your voice to the tech community where 5M+ people just like you are talking about what matters.

  • Help others & share knowledge
  • Earn cash & points
  • Learn & ask questions
  • 4
  • 4
  • 2
  • +1
11 Comments
 
LVL 1

Expert Comment

by:Alginald
ID: 33645975
Remove the auditiing of successful logins in auditing in the default domain controller group policy.
Open the default domain controller policy, navigate to Computer Configuration / Windows Settings / Security Sttings / Local Policy / Audit Policy and change the audit account logon events entry.
0
 
LVL 10

Expert Comment

by:duffman76
ID: 33646001
If your backup dc is what everyone is using for authentication then you will see this.  

You can turn off the success logs if you don't want to see them by right clicking the security log in eventviewer and then choosing filter and unchecking success audit.

With SQL and Outlook and anything else clients will authenticate constantly with your dc.  That would give you success logs assuming everything is working like it should.
0
 

Author Comment

by:infranetsupport
ID: 33646002
I dont want to remove the successful logins, i suspect there is an issue. what would cause my server to log so many audits, like 30, in a second?
0
Ransomware-A Revenue Bonanza for Service Providers

Ransomware – malware that gets on your customers’ computers, encrypts their data, and extorts a hefty ransom for the decryption keys – is a surging new threat.  The purpose of this eBook is to educate the reader about ransomware attacks.

 
LVL 1

Expert Comment

by:Alginald
ID: 33646042
Is there any more information in the event entry, which workstation, which user, etc?
0
 
LVL 10

Expert Comment

by:duffman76
ID: 33646224
If they all point to one user then that could be an issue.  If it is multiple users and workstations it could be any number of things.  You should try and see if you can limit your scope and find similarities in all the messages.
0
 

Author Comment

by:infranetsupport
ID: 33646249
Ive narrowed it down to two users but they are thin clients that login into citrix.  all the event log messages are simple successful login messages for one user to a workstation.
0
 

Author Comment

by:infranetsupport
ID: 33646475
It seems like the logins keep happening over and over again all day long.
0
 
LVL 10

Expert Comment

by:duffman76
ID: 33647503
Is the workstation having a connection issue or does it have any software on it that may try to authenticate constantly.  
0
 

Author Comment

by:infranetsupport
ID: 33675467
THe workstations are thin clients and i believe wouldnt work very well at all if connection was at all lost. there is no special software running that would authenticate a lot. The TS clients all pretty much access a SQL server.
0
 
LVL 10

Expert Comment

by:duffman76
ID: 33676370
If the sql database is using windows authentication they could authenticate each time they try to access a table or any part of the database.  
0
 
LVL 4

Accepted Solution

by:
HRL earned 500 total points
ID: 33758628
This may be a setting on the Citrix machines called session sharing. check out the following link for advice on forcing session sharing effectively.

http://support.citrix.com/article/CTX118579
0

Featured Post

Free Tool: Port Scanner

Check which ports are open to the outside world. Helps make sure that your firewall rules are working as intended.

One of a set of tools we are providing to everyone as a way of saying thank you for being a part of the community.

Question has a verified solution.

If you are experiencing a similar issue, please ask a related question

Suggested Solutions

Title # Comments Views Activity
Windows 2000 Kerberos problem 5 355
auto copy 8 620
Task scheduler to manage event fails 4 909
removing broke domain controller...then upgrading to MS Win 2K12 6 405
NTFS file system has been developed by Microsoft that is widely used by Windows NT operating system and its advanced versions. It is the mostly used over FAT file system as it provides superior features like reliability, security, storage, efficienc…
Determining the an SCCM package name from the Package ID
I've attached the XLSM Excel spreadsheet I used in the video and also text files containing the macros used below. https://filedb.experts-exchange.com/incoming/2017/03_w12/1151775/Permutations.txt https://filedb.experts-exchange.com/incoming/201…
This video shows how to use Hyena, from SystemTools Software, to update 100 user accounts from an external text file. View in 1080p for best video quality.
Suggested Courses

737 members asked questions and received personalized solutions in the past 7 days.

Join the community of 500,000 technology professionals and ask your questions.

Join & Ask a Question