Networking Forums

Networking Forums > Computer Networking > Windows Networking > Windows 2003 Server, Constant Logon/Logoff in my Security Log - does this mean something is worng?

Reply
Thread Tools Display Modes

Windows 2003 Server, Constant Logon/Logoff in my Security Log - does this mean something is worng?

 
 
Edgar E. Cayce
Guest
Posts: n/a

 
      07-22-2004, 07:55 PM
I have a Windows 2003 server acting as domian controller on a small (7
PC) office network.

Things seem to be working OK, but in my Event Viewer Security log, I
find constant Success Audits where the machines in my network are
doing Logon/Logoff and Privilege Use. These are happening many times
per minute and I am concerned that something may be amiss.

It usually seems to be Logon/Logoff EventID 540, the Privilege use
#576, then Logon/Logoff #538, like so:

Event Type: Success Audit
Event Source: Security
Event Category: Logon/Logoff
Event ID: 540
Date: 7/3/2004
Time: 1:39:54 PM
User: NT AUTHORITY\SYSTEM
Computer: MEDTEKSERVER
Description:
Successful Network Logon:
User Name: MEDTEKSERVER$
Domain: MEDTEK
Logon ID: (0x0,0x19D51B45)
Logon Type: 3
Logon Process: Kerberos
Authentication Package: Kerberos
Workstation Name:
Logon GUID: {09dc05ac-b256-11bc-da59-4245b06f1711}
Caller User Name: -
Caller Domain: -
Caller Logon ID: -
Caller Process ID: -
Transited Services: -
Source Network Address: 192.168.1.200
Source Port: 3957


Event Type: Success Audit
Event Source: Security
Event Category: Privilege Use
Event ID: 576
Date: 7/3/2004
Time: 1:39:54 PM
User: NT AUTHORITY\SYSTEM
Computer: MEDTEKSERVER
Description:
Special privileges assigned to new logon:
User Name: MEDTEKSERVER$
Domain: MEDTEK
Logon ID: (0x0,0x19D51B45)
Privileges: SeBackupPrivilege
SeRestorePrivilege
SeDebugPrivilege
SeChangeNotifyPrivilege


Event Type: Success Audit
Event Source: Security
Event Category: Logon/Logoff
Event ID: 538
Date: 7/3/2004
Time: 1:39:54 PM
User: NT AUTHORITY\SYSTEM
Computer: MEDTEKSERVER
Description:
User Logoff:
User Name: MEDTEKSERVER$
Domain: MEDTEK
Logon ID: (0x0,0x19D51AF8)
Logon Type: 3


Is this stuff normal? Is my auditing set too high? Any help would be
muchly appreciated.

Ed
 
Reply With Quote
 
 
 
Reply

Thread Tools
Display Modes

Posting Rules
You may not post new threads
You may not post replies
You may not post attachments
You may not edit your posts

BB code is On
Smilies are On
[IMG] code is On
HTML code is Off
Trackbacks are On
Pingbacks are On
Refbacks are Off


Similar Threads
Thread Thread Starter Forum Replies Last Post
DOS logon Windows Server 2003 Andreas Wöckl Windows Networking 13 10-05-2006 01:03 PM
Constant DHCP Conflicts on Windows 2003 Server lfillmore@bedford.gov.uk Windows Networking 3 07-20-2006 11:44 AM
WIN 95 cannot logon to Windows Server 2003 GW Windows Networking 4 03-19-2005 07:56 PM
Windows 98 logon to Server 2003 Pat Fry Windows Networking 2 09-16-2004 03:58 PM
Windows 98 share logon to windows server 2003 Bronson Windows Networking 1 10-29-2003 09:21 PM



1 2 3 4 5 6 7 8 9 10 11