﻿<?xml version='1.0' encoding='UTF-8'?><rss version="2.0" xmlns:dc="http://purl.org/dc/elements/1.1/"><channel><title>UltimateWindowsSecurity.com Forum / Ultimate Windows Security Forum / Security Log / 540 - Successful Network Logon </title><generator>InstantForum.NET v4.1.4</generator><description>UltimateWindowsSecurity.com Forum</description><link>http://forum.ultimatewindowssecurity.com/</link><webMaster>noreply@ultimatewindowssecurity.com</webMaster><lastBuildDate>Sat, 31 Jul 2010 02:06:47 GMT</lastBuildDate><ttl>20</ttl><item><title>The computer name PCxxxx$ in 540 User field</title><link>http://forum.ultimatewindowssecurity.com/Topic381-34-1.aspx</link><description>Hi all,&lt;br&gt;&lt;br&gt;I was checking log from my domain controllers and I saw 540 messages with a strange value in the user field.&lt;br&gt;&lt;br&gt;user = PC1122$&lt;br&gt;computer = DC2&lt;br&gt;workstation name = PC3344&lt;br&gt;&lt;br&gt;Why did I see the computer name in the user field instead of the log on user's name? And what does it mean?&lt;br&gt;&lt;br&gt;I have W2003 domain controllers and XP clients (name starting with PCxxxx).&lt;br&gt;&lt;br&gt;Thank you for your answer/explanation.</description><pubDate>Thu, 20 May 2010 04:57:26 GMT</pubDate><dc:creator>hunnypot</dc:creator></item><item><title>Layout of fields in 540 event ?</title><link>http://forum.ultimatewindowssecurity.com/Topic363-34-1.aspx</link><description>I use a script to parse 540 events in the Security Log.&lt;br&gt;In some cases I see and event like this&lt;br&gt;        "eventtype" =&gt; "Audit Normal    ",&lt;br&gt;        "eventnumber" =&gt; "540",&lt;br&gt;        "category" =&gt; "2",&lt;br&gt;        "source" =&gt; "Security",&lt;br&gt;        "creationtime" =&gt; "Thu, 15 Apr 2010 10:44:41 UTC",&lt;br&gt;        "writetime" =&gt; "Thu, 15 Apr 2010 10:44:41 UTC",&lt;br&gt;        "computer" =&gt; "TTESTDC4",&lt;br&gt;        "SID" =&gt;"S-1-5-21-0-0-4-0",&lt;br&gt;        "Strings" =&gt; {&lt;br&gt;            "0" =&gt; 'TestUser1',&lt;br&gt;            "1" =&gt; 'TEST_DOM',&lt;br&gt;            "2" =&gt; '(0x0,0x7D709A)',&lt;br&gt;            "3" =&gt; '3',&lt;br&gt;            "4" =&gt; 'Kerberos',&lt;br&gt;            "5" =&gt; 'Kerberos',&lt;br&gt;            "6" =&gt; '',&lt;br&gt;            "7" =&gt; '{7a49e72b-ae5b-9137-633e-a392ed0569f2}',&lt;br&gt;            "8" =&gt; '-',&lt;br&gt;            "9" =&gt; '-',&lt;br&gt;            "10" =&gt; '-',&lt;br&gt;            "11" =&gt; '-',&lt;br&gt;            "12" =&gt; '-',&lt;br&gt;            "13" =&gt; '10.125.58.195',&lt;br&gt;            "14" =&gt; '0',&lt;br&gt;        }&lt;br&gt;&lt;br&gt;other events appear like this (see the values in the String part, ip addres in field 13 or 14 for example)&lt;br&gt;"eventtype" =&gt; "Audit Normal    ",&lt;br&gt;        "eventnumber" =&gt; "540",&lt;br&gt;        "category" =&gt; "2",&lt;br&gt;        "source" =&gt; "Security",&lt;br&gt;        "creationtime" =&gt; "Thu, 15 Apr 2010 10:43:51 UTC",&lt;br&gt;        "writetime" =&gt; "Thu, 15 Apr 2010 10:43:51 UTC",&lt;br&gt;        "computer" =&gt; "TESTDC4",&lt;br&gt;        "SID" =&gt;"S-1-5-21-0-0-4-0",&lt;br&gt;        "Strings" =&gt; {&lt;br&gt;            "0" =&gt; '',&lt;br&gt;            "1" =&gt; 'TestUser2',&lt;br&gt;            "2" =&gt; 'TEST_DOM',&lt;br&gt;            "3" =&gt; '(0x0,0x7DAC7A)',&lt;br&gt;            "4" =&gt; '3',&lt;br&gt;            "5" =&gt; 'Kerberos',&lt;br&gt;            "6" =&gt; 'Kerberos',&lt;br&gt;            "7" =&gt; '',&lt;br&gt;            "8" =&gt; '{87e77d0a-64ae-432a-89f4-d62ba36b4966}',&lt;br&gt;            "9" =&gt; '-',&lt;br&gt;            "10" =&gt; '-',&lt;br&gt;            "11" =&gt; '-',&lt;br&gt;            "12" =&gt; '-',&lt;br&gt;            "13" =&gt; '-',&lt;br&gt;            "14" =&gt; '10.125.58.131',&lt;br&gt;        }&lt;br&gt;&lt;br&gt;&lt;br&gt;Any suggestions why the event would be stored differently ?&lt;br&gt;&lt;br&gt;thanks</description><pubDate>Wed, 21 Apr 2010 06:45:19 GMT</pubDate><dc:creator>michaelluch</dc:creator></item><item><title>Many 540/538 events during short period of time.</title><link>http://forum.ultimatewindowssecurity.com/Topic300-34-1.aspx</link><description>Hello&lt;br&gt;&lt;br&gt;I wonder why are there so many 540/538 entries (each 540/538 pair with the same logon id) during so short period of time? It is even twice per second and is related to many users and workstations accounts.&lt;br&gt;&lt;br&gt;Besides from time to time some users (WinXP/Vista) can't login to AD. There is no strict rule - each time that problem is related to different users accounts.&lt;br&gt;&lt;br&gt;Thanks for your precious explanations/help&lt;br&gt;Pablo&lt;br&gt;&lt;br&gt;P.S.&lt;br&gt;Does anyone knows how to paste attachments here?</description><pubDate>Mon, 25 Jan 2010 04:19:12 GMT</pubDate><dc:creator>Pablo</dc:creator></item><item><title>Unexplained 540 events on W2K workstation in a domain</title><link>http://forum.ultimatewindowssecurity.com/Topic232-34-1.aspx</link><description>Does anyone have an explanation for this sequence of three Events on a W2K workstation that's in a domain? The workstation name is WK3577. The user in this case (AM\User1) is a valid domain user but there is no logical connection between them and this workstation.  The are multiple user accounts generating these Events.&lt;/P&gt;&lt;P&gt;&lt;BR&gt;Event Type: Success Audit&lt;BR&gt;Event Source: Security&lt;BR&gt;Event Category: Privilege Use &lt;BR&gt;Event ID: 576&lt;BR&gt;Date:  10/11/2009&lt;BR&gt;Time:  11:47:09 PM&lt;BR&gt;User:  AM\User1&lt;BR&gt;Computer: WK3577&lt;BR&gt;Description:&lt;BR&gt;Special privileges assigned to new logon:&lt;BR&gt;  User Name: &lt;BR&gt;  Domain:  &lt;BR&gt;  Logon ID:  (0x0,0x564620)&lt;BR&gt;  Assigned:  SeChangeNotifyPrivilege &lt;/P&gt;&lt;P&gt;&lt;BR&gt;Event Type: Success Audit&lt;BR&gt;Event Source: Security&lt;BR&gt;Event Category: Logon/Logoff &lt;BR&gt;Event ID: 540&lt;BR&gt;Date:  10/11/2009&lt;BR&gt;Time:  11:47:09 PM&lt;BR&gt;User:  AM\User1&lt;BR&gt;Computer: WK3577&lt;BR&gt;Description:&lt;BR&gt;Successful Network Logon:&lt;BR&gt;  User Name: User1&lt;BR&gt;  Domain:  AM&lt;BR&gt;  Logon ID:  (0x0,0x564620)&lt;BR&gt;  Logon Type: 3&lt;BR&gt;  Logon Process: Kerberos&lt;BR&gt;  Authentication Package: Kerberos&lt;BR&gt;  Workstation Name:  &lt;/P&gt;&lt;P&gt;&lt;BR&gt;Event Type: Success Audit&lt;BR&gt;Event Source: Security&lt;BR&gt;Event Category: Logon/Logoff &lt;BR&gt;Event ID: 538&lt;BR&gt;Date:  10/11/2009&lt;BR&gt;Time:  11:47:21 PM&lt;BR&gt;User:  AM\User1&lt;BR&gt;Computer: WK3577&lt;BR&gt;Description:&lt;BR&gt;User Logoff:&lt;BR&gt;  User Name: User1&lt;BR&gt;  Domain:  AM&lt;BR&gt;  Logon ID:  (0x0,0x564620)&lt;BR&gt;  Logon Type: 3&lt;BR&gt; </description><pubDate>Mon, 12 Oct 2009 13:23:35 GMT</pubDate><dc:creator>kr_lly</dc:creator></item><item><title>Multiple event 540 and 538 entries</title><link>http://forum.ultimatewindowssecurity.com/Topic218-34-1.aspx</link><description>What would cause one user to fill the event log on my domain server with event 540 and 538 entries?  I am talking over 1 million in 24 hours.  I can't detect any virus or spyware on the system and the system seems to run normally but only shutting off the user PC stops the stream of event losgs.</description><pubDate>Mon, 28 Sep 2009 09:52:16 GMT</pubDate><dc:creator>netwit</dc:creator></item><item><title>machine accounts in code 540, 538 events</title><link>http://forum.ultimatewindowssecurity.com/Topic80-34-1.aspx</link><description>Our WS2003 Event Viewer Security log contains many more machine log-ins than user account logins.  Is this a normal, useful configuration, or have we bollixed something?</description><pubDate>Mon, 27 Apr 2009 10:45:59 GMT</pubDate><dc:creator>Clay</dc:creator></item><item><title>EID - 540</title><link>http://forum.ultimatewindowssecurity.com/Topic175-34-1.aspx</link><description>Hi,&lt;/P&gt;&lt;P&gt;I am doing audit review for my company. In a server I can see in the log for EID - 540 from which workstation the access is made.&lt;/P&gt;&lt;P&gt;&lt;U&gt;Here I is the see log details&lt;/U&gt;:&lt;/P&gt;&lt;P&gt;"Successful Network Logon: User Name: &lt;STRONG&gt;$nrddu&lt;/STRONG&gt; Domain: sdap Logon ID: (0x0,0x5F637364) Logon Type: 3 Logon Process: &lt;STRONG&gt;NtLmSsp Authentication Package: NTLM Workstation Name&lt;/STRONG&gt;: &lt;STRONG&gt;Htf1&lt;/STRONG&gt;&lt;/P&gt;&lt;P&gt;Here I can not see the same in the server :&lt;/P&gt;&lt;P&gt;"Successful Network Logon: User Name: &lt;STRONG&gt;$nrddu&lt;/STRONG&gt; Domain: sdap Logon ID: (0x0,0x5F669D39) Logon Type: 3 Logon Process: &lt;STRONG&gt;Kerberos Authentication Package: Kerberos Workstation Name&lt;/STRONG&gt;:&lt;/P&gt;&lt;P&gt;Is there any differnace in this  NtLmSsp Authentication Package and Kerberos Authentication Package in capturing the logs...&lt;/P&gt;&lt;P&gt;Kishore&lt;/P&gt;&lt;P&gt;&lt;A href="mailto:kishoressk@rediffmail.com"&gt;&lt;/A&gt; </description><pubDate>Fri, 14 Aug 2009 03:18:41 GMT</pubDate><dc:creator>kitchu25</dc:creator></item><item><title>Logon Types for 540?</title><link>http://forum.ultimatewindowssecurity.com/Topic89-34-1.aspx</link><description>Hey - &lt;P&gt;I noticed the description says this eventid (540) only happens for logon type 3.  This isn't true as it also happens for Logon type 8 (NetworkClearText - most likely a Basic Authentication to IIS).  &lt;/P&gt;&lt;P&gt;Is this right? Does EventID 528 ever show Logon type 8? Do any other logon types show on EventID 540?&lt;/P&gt;&lt;P&gt;Thanks,&lt;/P&gt;&lt;P&gt;Braino! ;)</description><pubDate>Mon, 11 May 2009 19:24:41 GMT</pubDate><dc:creator>Braino</dc:creator></item></channel></rss>