﻿<?xml version='1.0' encoding='UTF-8'?><rss version="2.0" xmlns:dc="http://purl.org/dc/elements/1.1/"><channel><title>UltimateWindowsSecurity.com Forum / Ultimate Windows Security Forum / Security Log / 528 - Successful Logon </title><generator>InstantForum.NET v4.1.4</generator><description>UltimateWindowsSecurity.com Forum</description><link>http://forum.ultimatewindowssecurity.com/</link><webMaster>noreply@ultimatewindowssecurity.com</webMaster><lastBuildDate>Tue, 07 Feb 2012 11:57:58 GMT</lastBuildDate><ttl>20</ttl><item><title>event 528 -source network address 127.0.0.1</title><link>http://forum.ultimatewindowssecurity.com/Topic895-22-1.aspx</link><description>I'm seeing successful logins for a local admin account on a 2003 server where it's shown as event 528, type 10, source network address 127.0.0.1.  There doesn't appear to be an ilo card and the only interfaces are loopback and an ethernet card.  Any ideas why a remote login would appear to come from the local host?  =/</description><pubDate>Thu, 19 Jan 2012 13:37:48 GMT</pubDate><dc:creator>sbenjamin</dc:creator></item><item><title>Event 528 Missing Source IP</title><link>http://forum.ultimatewindowssecurity.com/Topic807-22-1.aspx</link><description>What would cause the source address to be missing in 528 events from Windows 2003 servers? I see this constantly and it greatly diminishes the value of these logs.&lt;br&gt;&lt;br&gt;Best Regards,&lt;br&gt;Paul</description><pubDate>Tue, 27 Sep 2011 20:06:34 GMT</pubDate><dc:creator>PaulL</dc:creator></item><item><title>What logon type for VPN access?</title><link>http://forum.ultimatewindowssecurity.com/Topic195-22-1.aspx</link><description>Our users logon with the Cisco VPN client and I was wondering what logon type Microsoft considers this to be?&lt;br&gt;&lt;br&gt;Thanks</description><pubDate>Mon, 31 Aug 2009 11:22:49 GMT</pubDate><dc:creator>jwalzer</dc:creator></item><item><title>528 and audit settings</title><link>http://forum.ultimatewindowssecurity.com/Topic113-22-1.aspx</link><description>What audit settings on the DC control whether 528 records are recorded?&lt;/P&gt;&lt;P&gt;Our system is flooded with 540 events, but the only 528 events seem to be when an ADMIN logs on to the DC directly. &lt;/P&gt;&lt;P&gt;We want to trap workstation logon events only.   &lt;/P&gt;&lt;P&gt;Are the audit settings that will accomplish this as well as retaining the other AD events recommended on your website?&lt;/P&gt;&lt;P&gt;Thanks,&lt;/P&gt;&lt;P&gt;John </description><pubDate>Mon, 22 Jun 2009 09:10:09 GMT</pubDate><dc:creator>jwspain</dc:creator></item></channel></rss>
