too many logon/logoff events in security log

From: microsoft newsgroup (news_register_at_yahoo.com.hk)
Date: 11/25/04

  • Next message: Trevor: "Re: too many logon/logoff events in security log"
    Date: Thu, 25 Nov 2004 11:51:55 +0800
    
    

    Hi, all,

    I turn on the audit policy to monitor the logon/logoff envents in security
    log. However, there is too many logon/logoff events, average 3 times per
    minute. sometimes the logon/logoff by systems user, sometimes by
    administrators. I have not idea to troubleshoot this event. I capture the
    logs detail as below:

    User Logoff:
      User Name: ITRA$
      Domain: ITRANET0
      Logon ID: (0x0,0x105A389)
      Logon Type: 3

    Successful Network Logon:
      User Name: ITRA$
      Domain: ITRANET0
      Logon ID: (0x0,0xD3FD88)
      Logon Type: 3
      Logon Process: Kerberos
      Authentication Package: Kerberos
      Workstation Name:
      Logon GUID: {d4e327c2-d024-f080-3e0b-1d7c89e9e484}
      Caller User Name: -
      Caller Domain: -
      Caller Logon ID: -
      Caller Process ID: -
      Transited Services: -
      Source Network Address: 127.0.0.1
      Source Port: 4644

    Any idea or am I be hacked? why the source network address is the server
    itself but the logon type is 3.

    Thanks you very much advance!

    Regards,
    Trevor


  • Next message: Trevor: "Re: too many logon/logoff events in security log"

    Relevant Pages

    • Re: event viewer
      ... It is in the Logon/Logoff category. ... 538 is a logoff event- someone (local or remote) logged off the system. ... Correlate it with event 540 or event 528 on the "logon id" field. ... 680 is an account logon event- someone used an account that is owned by this ...
      (microsoft.public.win2000.security)
    • Re: Many Logon/Logoff Entries
      ... last week-end troubleshooting a Logon/LogOff issue and discovered just how ... over 170,000 of these entries in the Security Log. ... > Logon ID: ... > Caller User Name: - ...
      (microsoft.public.windows.server.sbs)
    • Re: Since W2003 SP1, many event 537 (failed logon)
      ... > Event Category: Logon/Logoff ... You will be taken to the proper newsgroup that will be able to help ... > Logon Failure: ... > Caller User Name: ...
      (microsoft.public.windowsupdate)
    • Re: please help to extract security event log
      ... I want to select security events of " logon/logoff" category between say ... Successful Network Logon: ... Caller User Name: - ...
      (microsoft.public.scripting.vbscript)
    • Security event crazyness... help!
      ... 540/538 as teh even type here is even log entries, ... Event Category: Logon/Logoff ... Successful Network Logon: ... Caller User Name: - ...
      (microsoft.public.windows.server.general)