Beste Fellow Tweakers,
Ik had even een vraagje! Bij mijn security log op mijn DC komen de heletijd 3 Soorten Succes Audit per keer erbij als een user inlogt volgens mijn waarom doet hij dat en waarom dan 3 .
Hieronder de Logs
Event Type: Success Audit
Event Source: Security
Event Category: Logon/Logoff
Event ID: 538
Date: 19-5-2005
Time: 10:40:49
User: NT AUTHORITY\SYSTEM
Computer: W2K3SRV1
Description:
User Logoff:
User Name: W2K3SRV1$
Domain: Random
Logon ID: (0x0,0x113288A)
Logon Type: 3
Event Type: Success Audit
Event Source: Security
Event Category: Logon/Logoff
Event ID: 538
Date: 19-5-2005
Time: 10:40:49
User: NT AUTHORITY\SYSTEM
Computer: W2K3SRV1
Description:
User Logoff:
User Name: W2K3SRV1$
Domain: Random
Logon ID: (0x0,0x11328D5)
Logon Type: 3
Event Type: Success Audit
Event Source: Security
Event Category: Logon/Logoff
Event ID: 540
Date: 19-5-2005
Time: 10:40:48
User: NT AUTHORITY\SYSTEM
Computer: W2K3SRV1
Description:
Successful Network Logon:
User Name: W2K3SRV1$
Domain: Random
Logon ID: (0x0,0x11328D5)
Logon Type: 3
Logon Process: Kerberos
Authentication Package: Kerberos
Workstation Name:
Logon GUID: {d018f425-4f62-b0ec-cabc-7e57e3c43cfe}
Caller User Name: -
Caller Domain: -
Caller Logon ID: -
Caller Process ID: -
Transited Services: -
Source Network Address: 192.168.1.1
Source Port: 26805
Event Type: Success Audit
Event Source: Security
Event Category: Logon/Logoff
Event ID: 576
Date: 19-5-2005
Time: 10:40:48
User: NT AUTHORITY\SYSTEM
Computer: W2K3SRV1
Description:
Special privileges assigned to new logon:
User Name: W2K3SRV1$
Domain: Random
Logon ID: (0x0,0x11328D5)
Privileges: SeTcbPrivilege
SeSecurityPrivilege
SeBackupPrivilege
SeRestorePrivilege
SeTakeOwnershipPrivilege
SeDebugPrivilege
SeSystemEnvironmentPrivilege
SeLoadDriverPrivilege
SeImpersonatePrivilege
SeEnableDelegationPrivilege
Event Type: Success Audit
Event Source: Security
Event Category: Logon/Logoff
Event ID: 540
Date: 19-5-2005
Time: 10:40:48
User: NT AUTHORITY\SYSTEM
Computer: W2K3SRV1
Description:
Successful Network Logon:
User Name: W2K3SRV1$
Domain: Random
Logon ID: (0x0,0x113288A)
Logon Type: 3
Logon Process: Kerberos
Authentication Package: Kerberos
Workstation Name:
Logon GUID: {61d50ee0-435c-4e3e-93de-8b9cabaefefa}
Caller User Name: -
Caller Domain: -
Caller Logon ID: -
Caller Process ID: -
Transited Services: -
Source Network Address: 127.0.0.1
Source Port: 26800
Ik had even een vraagje! Bij mijn security log op mijn DC komen de heletijd 3 Soorten Succes Audit per keer erbij als een user inlogt volgens mijn waarom doet hij dat en waarom dan 3 .
Hieronder de Logs
Event Type: Success Audit
Event Source: Security
Event Category: Logon/Logoff
Event ID: 538
Date: 19-5-2005
Time: 10:40:49
User: NT AUTHORITY\SYSTEM
Computer: W2K3SRV1
Description:
User Logoff:
User Name: W2K3SRV1$
Domain: Random
Logon ID: (0x0,0x113288A)
Logon Type: 3
Event Type: Success Audit
Event Source: Security
Event Category: Logon/Logoff
Event ID: 538
Date: 19-5-2005
Time: 10:40:49
User: NT AUTHORITY\SYSTEM
Computer: W2K3SRV1
Description:
User Logoff:
User Name: W2K3SRV1$
Domain: Random
Logon ID: (0x0,0x11328D5)
Logon Type: 3
Event Type: Success Audit
Event Source: Security
Event Category: Logon/Logoff
Event ID: 540
Date: 19-5-2005
Time: 10:40:48
User: NT AUTHORITY\SYSTEM
Computer: W2K3SRV1
Description:
Successful Network Logon:
User Name: W2K3SRV1$
Domain: Random
Logon ID: (0x0,0x11328D5)
Logon Type: 3
Logon Process: Kerberos
Authentication Package: Kerberos
Workstation Name:
Logon GUID: {d018f425-4f62-b0ec-cabc-7e57e3c43cfe}
Caller User Name: -
Caller Domain: -
Caller Logon ID: -
Caller Process ID: -
Transited Services: -
Source Network Address: 192.168.1.1
Source Port: 26805
Event Type: Success Audit
Event Source: Security
Event Category: Logon/Logoff
Event ID: 576
Date: 19-5-2005
Time: 10:40:48
User: NT AUTHORITY\SYSTEM
Computer: W2K3SRV1
Description:
Special privileges assigned to new logon:
User Name: W2K3SRV1$
Domain: Random
Logon ID: (0x0,0x11328D5)
Privileges: SeTcbPrivilege
SeSecurityPrivilege
SeBackupPrivilege
SeRestorePrivilege
SeTakeOwnershipPrivilege
SeDebugPrivilege
SeSystemEnvironmentPrivilege
SeLoadDriverPrivilege
SeImpersonatePrivilege
SeEnableDelegationPrivilege
Event Type: Success Audit
Event Source: Security
Event Category: Logon/Logoff
Event ID: 540
Date: 19-5-2005
Time: 10:40:48
User: NT AUTHORITY\SYSTEM
Computer: W2K3SRV1
Description:
Successful Network Logon:
User Name: W2K3SRV1$
Domain: Random
Logon ID: (0x0,0x113288A)
Logon Type: 3
Logon Process: Kerberos
Authentication Package: Kerberos
Workstation Name:
Logon GUID: {61d50ee0-435c-4e3e-93de-8b9cabaefefa}
Caller User Name: -
Caller Domain: -
Caller Logon ID: -
Caller Process ID: -
Transited Services: -
Source Network Address: 127.0.0.1
Source Port: 26800