RE: Event Log entries?

From: Bobby McMillan [MSFT] (robertmc_at_online.microsoft.com)
Date: 12/31/03


Date: Wed, 31 Dec 2003 07:21:38 GMT

INLINE:

Pleae note that there are some products that cause excessive 538's 540's
and 576's ... What products are on the server that was pusing these every
second for 5 hours...

--------------------
| From: "Kevin" <anonymous@discussions.microsoft.com>
| Sender: "Kevin" <anonymous@discussions.microsoft.com>
| Subject: Event Log entries?
| Date: Tue, 30 Dec 2003 11:06:03 -0800

|
| This is a lengthy post... Sorry but need to describe....
|
| We have a server that we setup to capture every event in
| the event log. We are noticing a strange group of entries
| that we are not sure what it is. I assume it is some
| standard OS / Network level entry because it happens often
| and is a consistent set of entries but we do not know what
| the entries mean and would like to know if anyone out
| there does.
|
| Log Entries....
| Success audit
| Category: Privilege use
| Event ID: 576
| Username: domain\computername$
|
| In the Description:
| Special Privileges assigned to new user
| User Name and Domain Blank
| Assigned: SeChangeNotifyPrivilege

>>>>>>822774 System Performance Decreases, and Many Event ID 576 Entries
Are Logged
>>>>>>http://support.microsoft.com/?id=822774

|
| Success audit
| Category: Logon/Logoff
| Event ID: 540
| Username: domain\computername$
|
| In the Description:
| Successful Network logon
| User Name: computername$
| Domain: domain
| Logon Type: 3

>>>>>>Machine authenticating to the domain

|
| Success audit
| Category: Logon/Logoff
| Event ID: 538
| Username: domain\computername$
|
| In the Description:
| User Logoff
| User Name: computername$
| Domain: domain
| Logon Type: 3

>>>>>> Machine ending communication with domain at this time.
|
| These 3 entries always accompany each other. The
| interesting issue is that this happened to one of our
| servers over the weekend but that the entries were taking
| place every second and filled up our 25mb log file in
| about 5 hours. We disconnected the computer from the
| network that was mentioned in the username field and these
| entries stopped. We plugged the computer back in this
| morning and it isn't happening?
|
| We have done the normal virus / hack research but this
| does not appear to be that at all. In fact we see in the
| logs where other entries of this type are in the system
| but for different computers....
|
| We did notice that the Computer Browser service was on for
| this server and it shouldn't have been so we turned it off.
|
| Does anyone know what this is?
|
| Kevin
|
|
|

This posting is provided "AS IS" with no warranties, and confers no rights.



Relevant Pages

  • Event Log entries?
    ... We are noticing a strange group of entries ... Success audit ... Username: domain\computername$ ... this server and it shouldn't have been so we turned it off. ...
    (microsoft.public.win2000.security)
  • Re: Partial Replication of W2K3 DC After DCPROMO
    ... Connecting to directory service on server willdc01. ... Latency information for 1 entries in the vector were ... PASS - All the DNS entries for DC are registered on DNS server ...
    (microsoft.public.windows.server.active_directory)
  • RE: Event Log entries?
    ... The server is a W2K web server with OWA 5.5. ... The workstation that was identified in the event log ... >| Subject: Event Log entries? ... >| Username: domain\computername$ ...
    (microsoft.public.win2000.security)
  • Re: OAB Generation Problem 9339
    ... exchange server 3450 GAL entries from the DC back. ... same command from my client I get 4934 entries back. ... To get the NSPITool is difficult there is no link on a Microsft site and PSS ... OABInteg test was done without any problem - all seams to be OK! ...
    (microsoft.public.exchange.admin)
  • Re: Excel data consolidation question
    ... it's talking to the server and trying to auto-complete the name ... you can save your form as a Data Access Page ... you know when you save a spreadsheet as HTML and 'add interactivity'? ... it would if you were so incompetent not to check all entries. ...
    (microsoft.public.excel)