Re: IP address in security event log?
From: Steven L Umbach (n9rou_at_nsattbi.com)
Date: 07/17/03
- Next message: Steven L Umbach: "Re: RPC server"
- Previous message: Steven L Umbach: "Re: how to disable access to w2k server"
- In reply to: Dario: "IP address in security event log?"
- Messages sorted by: [ date ] [ thread ] [ subject ] [ author ] [ attachment ]
Date: Thu, 17 Jul 2003 05:37:34 GMT
Not consistently - Windows 2003 is supposed to have fixed that. Look
into using something like Sygate Pro personal firewall. It is worth if for
it's logging alone and you can shut down the firewall. Then you can
correlate failures in the security log to events in the firewall log by
time. It also has a backtrace function. You can download and try it for
free. -- Steve
"Dario" <brignone@unitec.it> wrote in message
news:02a501c34b78$a117dc00$a001280a@phx.gbl...
> hi all,
> on my win2k Adv Server i noticed a lot of 529 event id
> like this:
> Logon Failure:
> Reason: Unknown user name or bad password
> User Name: Administrator
> Domain: JULIETTE
> Logon Type: 3
> Logon Process: NtLmSsp
> Authentication Package: NTLM
> Workstation Name:JULIETTE
>
> I'd like that windows will be able to log the ip address,
> not just the name of the domain. Is it possible to do it?
> Thanks, Dario
- Next message: Steven L Umbach: "Re: RPC server"
- Previous message: Steven L Umbach: "Re: how to disable access to w2k server"
- In reply to: Dario: "IP address in security event log?"
- Messages sorted by: [ date ] [ thread ] [ subject ] [ author ] [ attachment ]
Relevant Pages
|