I've just started to analyse security event logs on our NT domain.
Originally there was a PDC and 3 NT BDCs. We've now got the PDC and 2
NT BDCs. Some Windows 2003 servers have been added and I've noticed
there's a huge amount of security activity on one of them, the file
server.
Is this server actually validating domain logons or is it merely
recording security events for each connection to a share? I'm assuming
it's the later as the 2003 servers don't have any login scripts etc on
them.
Can someone confirm my thoughts?
Cheers,
Rowan
|