Security event crazyness... help!
- From: "Smokey Grindle" <nospam@xxxxxxxxxxxxxx>
- Date: Thu, 14 Sep 2006 14:50:32 -0400
on our file server which is a 2 node cluster running windows 2003 x64bit and
has a SAN attached to it through fiber channel's is having some wierd
problems with only ONE! user... about every 15 to 45 seconds (randomly
varriers) I get a large group of about 20 entries saying logon/loggoff with
540/538 as teh even type here is even log entries, these are the same each
time
Event Type: Success Audit
Event Source: Security
Event Category: Logon/Logoff
Event ID: 540
Date: 9/14/2006
Time: 9:18:03 AM
User: RE\Beth
Computer: NODEA
Description:
Successful Network Logon:
User Name: Beth
Domain: RE
Logon ID: (0x0,0x8E09D5)
Logon Type: 3
Logon Process: NtLmSsp
Authentication Package: NTLM
Workstation Name: DT-03-BD
Logon GUID: -
Caller User Name: -
Caller Domain: -
Caller Logon ID: -
Caller Process ID: -
Transited Services: -
Source Network Address: 10.10.1.110
Source Port: 1423
Event Type: Success Audit
Event Source: Security
Event Category: Logon/Logoff
Event ID: 538
Date: 9/14/2006
Time: 9:18:03 AM
User: RE\Beth
Computer: NODEA
Description:
User Logoff:
User Name: Beth_Dishong
Domain: RE
Logon ID: (0x0,0x8E09D5)
Logon Type: 3
For more information, see Help and Support Center at
http://go.microsoft.com/fwlink/events.asp.
right now we have 65,000 entries for this pattern! and no end in sight...
any idaes of what to check to stop this? all the other users (50 some of
them) dont show this behavior.. thanks!
.
- Prev by Date: best way to install 2003svr
- Next by Date: RE: Misterious IP -> name resolution in 2003 server
- Previous by thread: best way to install 2003svr
- Next by thread: Dynamic Disks
- Index(es):
Relevant Pages
|