﻿<?xml version='1.0' encoding='UTF-8'?><rss version="2.0" xmlns:dc="http://purl.org/dc/elements/1.1/"><channel><title>UltimateWindowsSecurity.com Forum / Ultimate Windows Security Forum / Security Log / 540 - Successful Network Logon </title><generator>InstantForum.NET v4.1.4</generator><description>UltimateWindowsSecurity.com Forum</description><link>http://forum.ultimatewindowssecurity.com/</link><webMaster>noreply@ultimatewindowssecurity.com</webMaster><lastBuildDate>Tue, 07 Feb 2012 12:01:36 GMT</lastBuildDate><ttl>20</ttl><item><title>540's on local workstation &amp; DC</title><link>http://forum.ultimatewindowssecurity.com/Topic746-34-1.aspx</link><description>Can you provide any reason why I would see 540's on the local workstation and on the DC?  &lt;br&gt;&lt;br&gt;On the workstations I would expect to see \wkstn_name\userid and on the DC \domain\userid.  I would also expect to see identical times on both if ntp is working properly; however there doesn't seem to be a 1 to 1 correlation.&lt;br&gt;&lt;br&gt;In addition, why would you see 540's on the DC instead of the 672, 673, 674 if kerberos is being used for network authentication?</description><pubDate>Fri, 24 Jun 2011 09:09:07 GMT</pubDate><dc:creator>nuallain</dc:creator></item><item><title>Multiple 540/538 pairings from non-authorized systems</title><link>http://forum.ultimatewindowssecurity.com/Topic641-34-1.aspx</link><description>Over the last few months I have noticed multiple successful 540/538 pairs from users and systems that I know for 100% certainty, do NOT have access/accounts for this system. I have not yet been able to identify how or why they are logging successful events.&lt;P&gt;Can you provide any additional insight?&lt;/P&gt;&lt;P&gt;Type Date  Time Source  Category Event User Computer&lt;/P&gt;&lt;P&gt;Success Audit 1/3/2011 10:17:33 AM Security Logon/Logoff  540 Person Account1 &lt;BR&gt;Success Audit 1/3/2011 10:17:42 AM Security Logon/Logoff  538 Person Account1 &lt;BR&gt;Success Audit 1/4/2011 2:58:02 PM Security Logon/Logoff  540 Person Account2 &lt;BR&gt;Success Audit 1/4/2011 2:58:06 PM Security Logon/Logoff  538 Person Account2 &lt;BR&gt;Success Audit 1/4/2011 6:17:09 PM Security Logon/Logoff  538 Person Account2 &lt;BR&gt;Success Audit 1/4/2011 6:17:06 PM Security Logon/Logoff  540 Person Account2 &lt;BR&gt;Success Audit 1/19/2011 2:25:16 PM Security Logon/Logoff  540 Person Account3 &lt;BR&gt;Success Audit 1/19/2011 2:25:17 PM Security Logon/Logoff  538 Person Account3 &lt;BR&gt;Success Audit 1/19/2011 2:25:16 PM Security Logon/Logoff  540 MachineAccount1$ &lt;BR&gt;Success Audit 1/19/2011 2:25:27 PM Security Logon/Logoff  538 MachineAccount1$ &lt;BR&gt;Success Audit 3/24/2011 7:01:46 AM Security Logon/Logoff  540 MachineAccount2$ &lt;BR&gt;Success Audit 3/24/2011 7:01:56 AM Security Logon/Logoff  538 MachineAccount2$ &lt;BR&gt;Success Audit 3/25/2011 4:43:35 PM Security Logon/Logoff  540 MachineAccount2$ &lt;BR&gt;Success Audit 3/25/2011 4:43:45 PM Security Logon/Logoff  538 MachineAccount2$ &lt;BR&gt;Success Audit 3/25/2011 1:20:17 PM Security Logon/Logoff  540 MachineAccount3$ &lt;BR&gt;Success Audit 3/25/2011 1:20:26 PM Security Logon/Logoff  538 MachineAccount3$&lt;BR&gt;Success Audit 4/2/2011 1:29:35 PM Security Logon/Logoff  540 MachineAccount4$ &lt;BR&gt;Success Audit 4/2/2011 1:29:45 PM Security Logon/Logoff  538 MachineAccount4$ &lt;BR&gt;Success Audit 4/2/2011 11:28:53 PM Security Logon/Logoff  540 S-1-5-21-XXXXXXXXXX-XXXXXXXXXX-XXXXXXXXXX-XXXXXXX &lt;BR&gt;Success Audit 4/2/2011 11:29:07 PM Security Logon/Logoff  538 S-1-5-21-XXXXXXXXXX-XXXXXXXXXX-XXXXXXXXXX-XXXXXXX &lt;BR&gt;Success Audit 4/4/2011 1:25:39 AM Security Logon/Logoff  540 S-1-5-21-XXXXXXXXXX-XXXXXXXXXX-XXXXXXXXXX-XXXXXXX &lt;BR&gt;Success Audit 4/4/2011 1:25:51 AM Security Logon/Logoff  538 S-1-5-21-XXXXXXXXXX-XXXXXXXXXX-XXXXXXXXXX-XXXXXXX &lt;BR&gt;Success Audit 4/5/2011 10:16:05 AM Security Logon/Logoff  540 MachineAccount5$ &lt;BR&gt;Success Audit 4/5/2011 10:16:16 AM Security Logon/Logoff  538 MachineAccount5$ &lt;BR&gt;Success Audit 4/7/2011 4:23:22 PM Security Logon/Logoff  540 MachineAccount3$ &lt;BR&gt;Success Audit 4/7/2011 4:23:31 PM Security Logon/Logoff  538 MachineAccount3$ &lt;BR&gt;Success Audit 4/13/2011 10:12:19 PM Security Logon/Logoff  540 MachineAccount6$ &lt;BR&gt;Success Audit 4/13/2011 10:12:26 PM Security Logon/Logoff  538 MachineAccount6$ &lt;BR&gt;Success Audit 4/13/2011 5:05:14 PM Security Logon/Logoff  540 MachineAccount6$ &lt;BR&gt;Success Audit 4/13/2011 5:05:18 PM Security Logon/Logoff  538 MachineAccount6$ &lt;BR&gt;Success Audit 4/14/2011 11:43:03 AM Security Logon/Logoff  540 MachineAccount6$ &lt;BR&gt;Success Audit 4/14/2011 11:43:07 AM Security Logon/Logoff  538 MachineAccount6$ &lt;BR&gt;</description><pubDate>Wed, 20 Apr 2011 09:37:39 GMT</pubDate><dc:creator>Vern</dc:creator></item><item><title>Trying to create alerts based on Event ID 540</title><link>http://forum.ultimatewindowssecurity.com/Topic677-34-1.aspx</link><description>I am trying to set up an alert using a central logging solution to inform me when ever a certain service account authenticates from any source IP other than the server hosting the log collection tool.&lt;/P&gt;&lt;P&gt;I was going to key on Event ID 540, the username, and configure the alert to hit if the authentication came from any IP other than the server hosting the log collection tool.  &lt;/P&gt;&lt;P&gt;I have found that there are many log events (540) that have the Source Network Address blank.  Can someone explain why this is??&lt;/P&gt;&lt;P&gt;Thanks!!!!!!&lt;/P&gt;&lt;P&gt;ROB</description><pubDate>Wed, 11 May 2011 09:18:15 GMT</pubDate><dc:creator>rlanier</dc:creator></item><item><title>The computer name PCxxxx$ in 540 User field</title><link>http://forum.ultimatewindowssecurity.com/Topic381-34-1.aspx</link><description>Hi all,&lt;br&gt;&lt;br&gt;I was checking log from my domain controllers and I saw 540 messages with a strange value in the user field.&lt;br&gt;&lt;br&gt;user = PC1122$&lt;br&gt;computer = DC2&lt;br&gt;workstation name = PC3344&lt;br&gt;&lt;br&gt;Why did I see the computer name in the user field instead of the log on user's name? And what does it mean?&lt;br&gt;&lt;br&gt;I have W2003 domain controllers and XP clients (name starting with PCxxxx).&lt;br&gt;&lt;br&gt;Thank you for your answer/explanation.</description><pubDate>Thu, 20 May 2010 04:57:26 GMT</pubDate><dc:creator>hunnypot</dc:creator></item><item><title>540 Events on Domain controllers</title><link>http://forum.ultimatewindowssecurity.com/Topic548-34-1.aspx</link><description>I'm seeing activity on domain controllers that show the machine name SYSNAMEHERE$ as the User Name and the Computer Name is the domain controller.  They are 540 type 8 logins that are successful, however, I'm trying to understand what is generating the event because I know that these users do not have proper credentials to log into a domain controller.  Is this some Windows background foo?  Perhaps Windows logon scripts, etc.?</description><pubDate>Wed, 12 Jan 2011 11:36:11 GMT</pubDate><dc:creator>tyoism</dc:creator></item><item><title>Workstation blank when Auth. package is Kerberos?</title><link>http://forum.ultimatewindowssecurity.com/Topic535-34-1.aspx</link><description>Hi Randy,&lt;P&gt;   On Eventid 540; I'm noticing the workstation name is blank (but the Source IP is still there) when the authentication package is Kerberos... Is this consistent in your experience? My guess is since the authenticaton package doesn't deal with workstation names, this field will be blank.   &lt;/P&gt;&lt;P&gt;   Just wanted a confirmation on your side...if you could  :cool:</description><pubDate>Fri, 19 Nov 2010 14:31:25 GMT</pubDate><dc:creator>Braino</dc:creator></item><item><title>Layout of fields in 540 event ?</title><link>http://forum.ultimatewindowssecurity.com/Topic363-34-1.aspx</link><description>I use a script to parse 540 events in the Security Log.&lt;br&gt;In some cases I see and event like this&lt;br&gt;        "eventtype" =&gt; "Audit Normal    ",&lt;br&gt;        "eventnumber" =&gt; "540",&lt;br&gt;        "category" =&gt; "2",&lt;br&gt;        "source" =&gt; "Security",&lt;br&gt;        "creationtime" =&gt; "Thu, 15 Apr 2010 10:44:41 UTC",&lt;br&gt;        "writetime" =&gt; "Thu, 15 Apr 2010 10:44:41 UTC",&lt;br&gt;        "computer" =&gt; "TTESTDC4",&lt;br&gt;        "SID" =&gt;"S-1-5-21-0-0-4-0",&lt;br&gt;        "Strings" =&gt; {&lt;br&gt;            "0" =&gt; 'TestUser1',&lt;br&gt;            "1" =&gt; 'TEST_DOM',&lt;br&gt;            "2" =&gt; '(0x0,0x7D709A)',&lt;br&gt;            "3" =&gt; '3',&lt;br&gt;            "4" =&gt; 'Kerberos',&lt;br&gt;            "5" =&gt; 'Kerberos',&lt;br&gt;            "6" =&gt; '',&lt;br&gt;            "7" =&gt; '{7a49e72b-ae5b-9137-633e-a392ed0569f2}',&lt;br&gt;            "8" =&gt; '-',&lt;br&gt;            "9" =&gt; '-',&lt;br&gt;            "10" =&gt; '-',&lt;br&gt;            "11" =&gt; '-',&lt;br&gt;            "12" =&gt; '-',&lt;br&gt;            "13" =&gt; '10.125.58.195',&lt;br&gt;            "14" =&gt; '0',&lt;br&gt;        }&lt;br&gt;&lt;br&gt;other events appear like this (see the values in the String part, ip addres in field 13 or 14 for example)&lt;br&gt;"eventtype" =&gt; "Audit Normal    ",&lt;br&gt;        "eventnumber" =&gt; "540",&lt;br&gt;        "category" =&gt; "2",&lt;br&gt;        "source" =&gt; "Security",&lt;br&gt;        "creationtime" =&gt; "Thu, 15 Apr 2010 10:43:51 UTC",&lt;br&gt;        "writetime" =&gt; "Thu, 15 Apr 2010 10:43:51 UTC",&lt;br&gt;        "computer" =&gt; "TESTDC4",&lt;br&gt;        "SID" =&gt;"S-1-5-21-0-0-4-0",&lt;br&gt;        "Strings" =&gt; {&lt;br&gt;            "0" =&gt; '',&lt;br&gt;            "1" =&gt; 'TestUser2',&lt;br&gt;            "2" =&gt; 'TEST_DOM',&lt;br&gt;            "3" =&gt; '(0x0,0x7DAC7A)',&lt;br&gt;            "4" =&gt; '3',&lt;br&gt;            "5" =&gt; 'Kerberos',&lt;br&gt;            "6" =&gt; 'Kerberos',&lt;br&gt;            "7" =&gt; '',&lt;br&gt;            "8" =&gt; '{87e77d0a-64ae-432a-89f4-d62ba36b4966}',&lt;br&gt;            "9" =&gt; '-',&lt;br&gt;            "10" =&gt; '-',&lt;br&gt;            "11" =&gt; '-',&lt;br&gt;            "12" =&gt; '-',&lt;br&gt;            "13" =&gt; '-',&lt;br&gt;            "14" =&gt; '10.125.58.131',&lt;br&gt;        }&lt;br&gt;&lt;br&gt;&lt;br&gt;Any suggestions why the event would be stored differently ?&lt;br&gt;&lt;br&gt;thanks</description><pubDate>Wed, 21 Apr 2010 06:45:19 GMT</pubDate><dc:creator>michaelluch</dc:creator></item><item><title>Many 540/538 events during short period of time.</title><link>http://forum.ultimatewindowssecurity.com/Topic300-34-1.aspx</link><description>Hello&lt;br&gt;&lt;br&gt;I wonder why are there so many 540/538 entries (each 540/538 pair with the same logon id) during so short period of time? It is even twice per second and is related to many users and workstations accounts.&lt;br&gt;&lt;br&gt;Besides from time to time some users (WinXP/Vista) can't login to AD. There is no strict rule - each time that problem is related to different users accounts.&lt;br&gt;&lt;br&gt;Thanks for your precious explanations/help&lt;br&gt;Pablo&lt;br&gt;&lt;br&gt;P.S.&lt;br&gt;Does anyone knows how to paste attachments here?</description><pubDate>Mon, 25 Jan 2010 04:19:12 GMT</pubDate><dc:creator>Pablo</dc:creator></item><item><title>Unexplained 540 events on W2K workstation in a domain</title><link>http://forum.ultimatewindowssecurity.com/Topic232-34-1.aspx</link><description>Does anyone have an explanation for this sequence of three Events on a W2K workstation that's in a domain? The workstation name is WK3577. The user in this case (AM\User1) is a valid domain user but there is no logical connection between them and this workstation.  The are multiple user accounts generating these Events.&lt;/P&gt;&lt;P&gt;&lt;BR&gt;Event Type: Success Audit&lt;BR&gt;Event Source: Security&lt;BR&gt;Event Category: Privilege Use &lt;BR&gt;Event ID: 576&lt;BR&gt;Date:  10/11/2009&lt;BR&gt;Time:  11:47:09 PM&lt;BR&gt;User:  AM\User1&lt;BR&gt;Computer: WK3577&lt;BR&gt;Description:&lt;BR&gt;Special privileges assigned to new logon:&lt;BR&gt;  User Name: &lt;BR&gt;  Domain:  &lt;BR&gt;  Logon ID:  (0x0,0x564620)&lt;BR&gt;  Assigned:  SeChangeNotifyPrivilege &lt;/P&gt;&lt;P&gt;&lt;BR&gt;Event Type: Success Audit&lt;BR&gt;Event Source: Security&lt;BR&gt;Event Category: Logon/Logoff &lt;BR&gt;Event ID: 540&lt;BR&gt;Date:  10/11/2009&lt;BR&gt;Time:  11:47:09 PM&lt;BR&gt;User:  AM\User1&lt;BR&gt;Computer: WK3577&lt;BR&gt;Description:&lt;BR&gt;Successful Network Logon:&lt;BR&gt;  User Name: User1&lt;BR&gt;  Domain:  AM&lt;BR&gt;  Logon ID:  (0x0,0x564620)&lt;BR&gt;  Logon Type: 3&lt;BR&gt;  Logon Process: Kerberos&lt;BR&gt;  Authentication Package: Kerberos&lt;BR&gt;  Workstation Name:  &lt;/P&gt;&lt;P&gt;&lt;BR&gt;Event Type: Success Audit&lt;BR&gt;Event Source: Security&lt;BR&gt;Event Category: Logon/Logoff &lt;BR&gt;Event ID: 538&lt;BR&gt;Date:  10/11/2009&lt;BR&gt;Time:  11:47:21 PM&lt;BR&gt;User:  AM\User1&lt;BR&gt;Computer: WK3577&lt;BR&gt;Description:&lt;BR&gt;User Logoff:&lt;BR&gt;  User Name: User1&lt;BR&gt;  Domain:  AM&lt;BR&gt;  Logon ID:  (0x0,0x564620)&lt;BR&gt;  Logon Type: 3&lt;BR&gt; </description><pubDate>Mon, 12 Oct 2009 13:23:35 GMT</pubDate><dc:creator>kr_lly</dc:creator></item><item><title>Multiple event 540 and 538 entries</title><link>http://forum.ultimatewindowssecurity.com/Topic218-34-1.aspx</link><description>What would cause one user to fill the event log on my domain server with event 540 and 538 entries?  I am talking over 1 million in 24 hours.  I can't detect any virus or spyware on the system and the system seems to run normally but only shutting off the user PC stops the stream of event losgs.</description><pubDate>Mon, 28 Sep 2009 09:52:16 GMT</pubDate><dc:creator>netwit</dc:creator></item><item><title>machine accounts in code 540, 538 events</title><link>http://forum.ultimatewindowssecurity.com/Topic80-34-1.aspx</link><description>Our WS2003 Event Viewer Security log contains many more machine log-ins than user account logins.  Is this a normal, useful configuration, or have we bollixed something?</description><pubDate>Mon, 27 Apr 2009 10:45:59 GMT</pubDate><dc:creator>Clay</dc:creator></item><item><title>EID - 540</title><link>http://forum.ultimatewindowssecurity.com/Topic175-34-1.aspx</link><description>Hi,&lt;/P&gt;&lt;P&gt;I am doing audit review for my company. In a server I can see in the log for EID - 540 from which workstation the access is made.&lt;/P&gt;&lt;P&gt;&lt;U&gt;Here I is the see log details&lt;/U&gt;:&lt;/P&gt;&lt;P&gt;"Successful Network Logon: User Name: &lt;STRONG&gt;$nrddu&lt;/STRONG&gt; Domain: sdap Logon ID: (0x0,0x5F637364) Logon Type: 3 Logon Process: &lt;STRONG&gt;NtLmSsp Authentication Package: NTLM Workstation Name&lt;/STRONG&gt;: &lt;STRONG&gt;Htf1&lt;/STRONG&gt;&lt;/P&gt;&lt;P&gt;Here I can not see the same in the server :&lt;/P&gt;&lt;P&gt;"Successful Network Logon: User Name: &lt;STRONG&gt;$nrddu&lt;/STRONG&gt; Domain: sdap Logon ID: (0x0,0x5F669D39) Logon Type: 3 Logon Process: &lt;STRONG&gt;Kerberos Authentication Package: Kerberos Workstation Name&lt;/STRONG&gt;:&lt;/P&gt;&lt;P&gt;Is there any differnace in this  NtLmSsp Authentication Package and Kerberos Authentication Package in capturing the logs...&lt;/P&gt;&lt;P&gt;Kishore&lt;/P&gt;&lt;P&gt;&lt;A href="mailto:kishoressk@rediffmail.com"&gt;&lt;/A&gt; </description><pubDate>Fri, 14 Aug 2009 03:18:41 GMT</pubDate><dc:creator>kitchu25</dc:creator></item><item><title>Logon Types for 540?</title><link>http://forum.ultimatewindowssecurity.com/Topic89-34-1.aspx</link><description>Hey - &lt;P&gt;I noticed the description says this eventid (540) only happens for logon type 3.  This isn't true as it also happens for Logon type 8 (NetworkClearText - most likely a Basic Authentication to IIS).  &lt;/P&gt;&lt;P&gt;Is this right? Does EventID 528 ever show Logon type 8? Do any other logon types show on EventID 540?&lt;/P&gt;&lt;P&gt;Thanks,&lt;/P&gt;&lt;P&gt;Braino! ;)</description><pubDate>Mon, 11 May 2009 19:24:41 GMT</pubDate><dc:creator>Braino</dc:creator></item></channel></rss>
