Re: Failure Audit Event 681: Any way to get the Offending IP Address?

From: Eric Fitzgerald [MSFT] (ericf@online.microsoft.com)
Date: 12/31/02


From: "Eric Fitzgerald [MSFT]" <ericf@online.microsoft.com>
Date: Tue, 31 Dec 2002 13:26:57 -0800


Not currently; we're adding IP address to logon events in Windows .NET
Server.

Eric

-- 
Eric Fitzgerald
Program Manager, Windows Auditing and Intrusion Detection
Microsoft Corporation
This posting is provided "AS IS" with no warranties, and confers no rights.
"Tom Rossi" <TomRossi7@yahoo.com> wrote in message
news:cb00dd30.0212240722.1293606a@posting.google.com...
> I have noticed a ton of failed login attempts to one my W2K servers.
> I have the events in my security log, but it only tells me a hostname
> for the computer.  Is there a way to get the IP Address?
>
> Here is an example:
>
> 12/23/2002 12:18:25 PM Security Failure Audit Account Logon 681 NT
> AUTHORITY\SYSTEM SERVERNAME The logon to account: MemProxyUser1
>  by: MICROSOFT_AUTHENTICATION_PACKAGE_V1_0
>  from workstation: SPSERVER
>  failed. The error code was: 3221226036
>
> Thanks,
> Tom Rossi


Relevant Pages

  • Re: Event ID: 599
    ... Eric Fitzgerald ... Windows Auditing and Intrusion Detection ... > Unprotection of auditable protected data. ... > Protected Data Flags: 0x0 ...
    (microsoft.public.windowsxp.security_admin)
  • Re: COTS application suggestions for auditing
    ... Eric Fitzgerald wrote: ... > The performance impact is probably caused by having to perform two ... > I also suggest against auditing reads of any sort, ... > Program Manager, Windows Auditing ...
    (microsoft.public.security)
  • Re: monitoring connections to my server/workstation
    ... Hey Svyatoslav, ... >> Eric Fitzgerald ... >> Program Manager, Windows Auditing ... >> Microsoft Corporation ...
    (microsoft.public.security)