Excessive Logon Audit Events

From: Chris Wilkins (Wilkins_at_discussions.microsoft.com)
Date: 06/28/04


Date: Mon, 28 Jun 2004 08:05:01 -0700

I have a stand alone Windows 2000 server sp4 running SQL 2000 sp3. I need to be able to audit successful and failed Logon events and I have the group policy set to do this. The box is in an offsite facility connected by at T1 over a VPN connection. My SQL developers have the remote server registered in their Enterprise Manager along with the local SQL servers. When they have Enterprise Manager open, the following event is logged on the remote SQL server every 10 seconds. It is filling my log and making it difficult to read. Why is this happening and can I make it stop?

Event Type: Success Audit
Event Source: Security
Event Category: Account Logon
Event ID: 680
Date: 6/28/2004
Time: 9:01:29 AM
User: NT AUTHORITY\SYSTEM
Computer: CONDOR
Description:
Account Used for Logon by: MICROSOFT_AUTHENTICATION_PACKAGE_V1_0
 Account Name:
         SomeUser
 Workstation:
         UserWorkstation