Re: Excessive Security Success audits



steve s wrote:
Thanks for putting my mind at ease. I saw a post from lanwench that
said sometimes to the effect that the event logs can drive you crazy.
I am starting to see what she means.

Set a filter and unselect 'information', 'success' and things you aren't so
concerned with. It makes a quick read of an event log ( You can reenable
later if you need to see all the events). Also saving and clearing the log
every month or so makes life much easier.


"Susan Bradley, CPA aka Ebitz - SBS Rocks" wrote:

And you will get that SBSmonacct every day at 4:30 a.m.... if you
don't.. you have bigger problems.

steve s wrote:
So a normal security log will have 150,000 entries over a five day
period? We have seven users and about ten devices.

"Susan Bradley, CPA aka Ebitz - SBS Rocks" wrote:


If a machine is on, yes there are normal "pings" to the server.

steve s wrote:

I have read past threads about the event ID #538,540, and 576
being normal log in and log out processes, but I am seeing these
postings every minute of every hour. It would seem that at 2am
at night we shouldn't have this activity because no one is here
and no one is logging in remotely. My log has over 150,000
entries over a five day period. This can't be normal can it? I
am also seeing event ID #624 with the following:

Event Type: Success Audit
Event Source: Security
Event Category: Account Management
Event ID: 624
Date: 5/31/2007
Time: 4:30:03 AM
User: ROSEHILLCAPITAL\administrator
Computer: 2007SERVER
Description:
User Account Created:
New Account Name: sbsmonacct
New Domain: ROSEHILLCAPITAL
New Account ID: S-1-5-21-3139612681-1260921997-520203349-1195
Caller User Name: administrator
Caller Domain: ROSEHILLCAPITAL
Caller Logon ID: (0x0,0xA1E7C)
Privileges -
Attributes:
Sam Account Name: sbsmonacct
Display Name: <value not set>
User Principal Name: -
Home Directory: <value not set>
Home Drive: <value not set>
Script Path: <value not set>
Profile Path: <value not set>
User Workstations: <value not set>
Password Last Set: <never>
Account Expires: <never>
Primary Group ID: 513
AllowedToDelegateTo: -
Old UAC Value: 0x0
New UAC Value: 0x15
User Account Control:
Account Disabled
'Password Not Required' - Enabled
'Normal Account' - Enabled
User Parameters: <value changed, but not displayed>
Sid History: -
Logon Hours: <value not set>


For more information, see Help and Support Center at
http://go.microsoft.com/fwlink/events.asp.

______________________________________________________________________


And event ID 552 with the following:

Event Type: Success Audit
Event Source: Security
Event Category: Logon/Logoff
Event ID: 552
Date: 5/31/2007
Time: 4:30:00 AM
User: NT AUTHORITY\SYSTEM
Computer: 2007SERVER
Description:
Logon attempt using explicit credentials:
Logged on user:
User Name: 2007SERVER$
Domain: ROSEHILLCAPITAL
Logon ID: (0x0,0x3E7)
Logon GUID: {0fffdf39-11ef-7331-378d-e54365cced1b}
User whose credentials were used:
Target User Name: administrator
Target Domain: ROSEHILLCAPITAL
Target Logon GUID: {4af82be1-608a-c06c-e5f4-dc39c94eabe8}

Target Server Name: localhost
Target Server Info: localhost
Caller Process ID: 1348
Source Network Address: -
Source Port: -


For more information, see Help and Support Center at
http://go.microsoft.com/fwlink/events.asp.

--
/kj


.



Relevant Pages

  • Re: images blocked
    ... "Steve Cochran" wrote in message ... I had to click on the Icon at the Welcome Screen to continue to my Desktop and I never set a logon password. ... If you go to the Control Panel | User Accounts, you should see an ASP.NET account that was created. ... wonder if there's some underlying security settings in that .NET Framework ...
    (microsoft.public.windows.inetexplorer.ie6_outlookexpress)
  • Re: Excessive Security Success audits
    ... steve s wrote: ... Event Category: Account Management ... Caller Logon ID: ... Target Server Name: localhost ...
    (microsoft.public.windows.server.sbs)
  • Re: Excessive Security Success audits
    ... Event Category: Account Management ... Caller Domain: ROSEHILLCAPITAL ... Caller Logon ID: ... Target Server Name: localhost ...
    (microsoft.public.windows.server.sbs)
  • Re: logon message
    ... As what Steve says - its always worked for me ... >> I have a computer that when anyone tries to logon the ... >> because the systems computer account in its primary ... > Try deleting the machine account on the server. ...
    (microsoft.public.win2000.general)
  • Re: Copying Profiles - Easy fix? Please help
    ... Ah, thanks for the note, Steve. ... >> Profiles stored on this computer, click the user profile you want to ... You cannot copy the account you are currently logged in on. ... If you create a new account, you must logon once before you copy ...
    (microsoft.public.windowsxp.general)