Re: Security Event Logs / Network access



Hello Jeff,

Yes, I agree with your analysis. The network print job requires a
network login. This gets logged in the sequence you mentioned.

J Wolfgang Goerlich


On Dec 20, 11:35 am, Jeff <J...@xxxxxxxxxxxxxxxxxxxxxxxxx> wrote:
Hello everyone,

Had a minor issue this morning with a client machine on our network
regarding thesecuritylogs being full and not allowing a user-level login
that wasn't an admin.  This isn't the problem I am asking about however, this
has been corrected.

It prompted me to take a look into that computers event logs and it seems
that there are a lot of logon events for a particular user in thesecurity
log.  This user however, prints to a shared printer on the target computer.

The machines are both Windows XP, sp2, running on a Windows 2003 ADS network.

The event logs in question are:
1st
Event ID:       576
Special privileges assigned to new logon

2nd
Event ID:       540
Successful Network Logon

3rd
Event ID:       538
User Logoff

I'm thinking that because the user prints to that printer on the target
machine, that thesecuritylog is simply tracking these 3 events every time
the user prints, is this correct?

It makes sense to me but I wanted to verify with someone else that these
events are perfectly normal and there shouldn't be asecuritybreach.

We're often so busy here that we don't have time to review logs very often..

--
Thanks, Jeff

.



Relevant Pages

  • RE: VPN/ISA 2004 issue after SP1 install on sbs2003
    ... Thank you for posting in SBS newsgroup. ... the ISA server identifies the spoof attacking according to the ... The 14147 error could indicate network object configuration issue. ... | these are mentioned in the event logs. ...
    (microsoft.public.windows.server.sbs)
  • Re: Why do PCs lose their trust relationship?
    ... A duplicate name has been detected on the TCP network. ... NetBIOS Remote Machine Name Table ... >I see event logs on the domain controller saying their secure channel>password isn't correct. ... the server admins ran> into this problem when rebooting a server and voluntarily rejoining it to> the domain. ...
    (microsoft.public.win2000.active_directory)
  • Re: Why do PCs lose their trust relationship?
    ... A duplicate name has been detected on the TCP network. ... NetBIOS Remote Machine Name Table ... >I see event logs on the domain controller saying their secure channel>password isn't correct. ... the server admins ran> into this problem when rebooting a server and voluntarily rejoining it to> the domain. ...
    (microsoft.public.windows.server.active_directory)
  • Re: With no network connection--user logs in to blank screen
    ... The event logs don't seem to show anything crazy happening. ... Windows NT or Windows 2000 Domain Controller is available for domain ... Then the network adapters begin to log stuff. ... >> This is a strange combination of offline files and blank login ...
    (microsoft.public.win2000.networking)
  • Re: Roaming Profile
    ... (XP does not wait for some network elements to load unless a GPO turns off ... In our environmnet we use the same mandatory profile for Win2k and XP ... > Windows 2000 and XP mandatory profiles? ... Check the event logs for other clues. ...
    (microsoft.public.windowsxp.setup_deployment)