We are running Exchange Server 2003 SP2. While doing some cleanup of the mailboxes, I noticed that 99% of our user's mailboxes have a last logged in as <DOMAIN>\Administrator. I am not concerned that someone is using the Administrator account to look at peoples mailboxes but I am concerned that there is some process that accesses Exchange that is running as the Administrator account. I am trying to find out which machine this service might be running on. I turned on maximum diagnostic logging for mailbox logons and access control and I can see a number of 1016 and 1009 events but this only tells me that the Administrator is logging in and not from where.
How can I find out where the Administrator account is being used?