Re: Failure audit in security log

From: Eric Fitzgerald [MS] (ericf@online.microsoft.com)
Date: 10/31/02


From: "Eric Fitzgerald [MS]" <ericf@online.microsoft.com>
Date: Thu, 31 Oct 2002 12:13:28 -0800


If the workstation is on the same subnet as you, or if it points to your
WINS environment, then the following command will return the machine's IP
address:

nbtstat -a workstationname

If the machine is not resolvable by WINS or broadcast, then no, you can't
get any more information about it after the fact.

Eric

"AiKay" <iwazeer2@hotmail.com> wrote in message
news:#F#gxFPgCHA.2256@tkmsftngp12...
> I saw some Failure audits in my security log with Event Code Ids 529 and
> 681. The log (in event viewer) only shows a workstation name in the
> Workgroup domain. Is there anyway I can find out more information about
that
> workstation or try to gather more information that will be useful for my
> network security person?
>
> Aikay
>
>



Relevant Pages

  • Re: a forensic question
    ... > findstring then do the same for any network drive access they have. ... > it the slave on a machine with Easy Recovery Pro installed. ... But she discovered that some important files on her workstation ... >> security log of the PDC? ...
    (comp.security.misc)
  • Re: Event ID 560 Problem
    ... >Error 560s usually refer to object access. ... >whenever a user makes a connection to something out on ... >> this repeated event in my security log that I can't ... Whenever someone log off their workstation, ...
    (microsoft.public.win2000.security)
  • Failure audit in security log
    ... I saw some Failure audits in my security log with Event Code Ids 529 and ... The log (in event viewer) only shows a workstation name in the ...
    (microsoft.public.win2000.security)
  • Re: Security Event logs dont match
    ... I am not saying that the DC log is untrustworthy; ... The DC's log says that it was accessed remotely from his workstation from ... >> The primary domain controller security log says that Steve ... >> that time, but contains login info from that morning, and ...
    (microsoft.public.security)
  • Re: account lockout fails
    ... In my domain controller security log I received the following events ... Address is the workstation IP address. ... each other in the security log until there were a total of 24. ... domain lockout policy did not take effect and lock the account. ...
    (microsoft.public.win2000.security)