Re: Empty Event 529
- From: "Eric Fitzgerald [MSFT]" <ericf@xxxxxxxxxxxxxxxxxxxx>
- Date: Wed, 17 May 2006 11:48:02 -0700
Kerberos logon failure events sometimes show up blank like this, when the
ticket can't be decrypted (and therefore the machine performing the logon
can't extract the information needed for the audit event.
Eric
--
This information is provided "AS-IS" with no warranty, and confers no
rights.
"ML" <lindeboy@xxxxxxxxxxxxx> wrote in message
news:e%23Q5RxOmFHA.3304@xxxxxxxxxxxxxxxxxxxxxxx
Hi!
I'm getting numerous event 529s on a W2K3 SP1 server on our network.
However, all that is shown in the event is the following. So apart from
having an IP there's nothing else. Why are the other fields left blank?
Event Type: Failure Audit
Event Source: Security
Event Category: Logon/Logoff
Event ID: 529
Date: 04/08/2005
Time: 12:45:03
User: NT AUTHORITY\SYSTEM
Computer: SERVER
Description:
Logon Failure:
Reason: Unknown user name or bad password
User Name:
Domain:
Logon Type: 3
Logon Process: Kerberos
Authentication Package: Kerberos
Workstation Name: -
Caller User Name: -
Caller Domain: -
Caller Logon ID: -
Caller Process ID: -
Transited Services: -
Source Network Address: 192.168.1.243
Source Port: 0
For more information, see Help and Support Center at
http://go.microsoft.com/fwlink/events.asp.
.
- Prev by Date: Re: Data Recovery Agent exspired in Windows 2003 AD
- Next by Date: W2K3 & VPN blocking access to server
- Previous by thread: Re: Data Recovery Agent exspired in Windows 2003 AD
- Next by thread: W2K3 & VPN blocking access to server
- Index(es):
Relevant Pages
|
|