﻿<?xml version='1.0' encoding='UTF-8'?><rss version="2.0" xmlns:dc="http://purl.org/dc/elements/1.1/"><channel><title>UltimateWindowsSecurity.com Forum / Ultimate Windows Security Forum / Security Log / 540 - Successful Network Logon  / EID - 540 / Latest Posts</title><generator>InstantForum.NET v4.1.4</generator><description>UltimateWindowsSecurity.com Forum</description><link>http://forum.ultimatewindowssecurity.com/</link><webMaster>noreply@ultimatewindowssecurity.com</webMaster><lastBuildDate>Tue, 07 Feb 2012 12:18:27 GMT</lastBuildDate><ttl>20</ttl><item><title>RE: EID - 540</title><link>http://forum.ultimatewindowssecurity.com/Topic175-34-1.aspx</link><description>I can't test it right now but my memory and knowledge of the difference between the 2 protocols says you may be right.  However there should be a field in the 540 event that specifies the workstation IP address.</description><pubDate>Fri, 14 Aug 2009 07:39:28 GMT</pubDate><dc:creator>RandyFranklinSmith</dc:creator></item><item><title>EID - 540</title><link>http://forum.ultimatewindowssecurity.com/Topic175-34-1.aspx</link><description>Hi,&lt;/P&gt;&lt;P&gt;I am doing audit review for my company. In a server I can see in the log for EID - 540 from which workstation the access is made.&lt;/P&gt;&lt;P&gt;&lt;U&gt;Here I is the see log details&lt;/U&gt;:&lt;/P&gt;&lt;P&gt;"Successful Network Logon: User Name: &lt;STRONG&gt;$nrddu&lt;/STRONG&gt; Domain: sdap Logon ID: (0x0,0x5F637364) Logon Type: 3 Logon Process: &lt;STRONG&gt;NtLmSsp Authentication Package: NTLM Workstation Name&lt;/STRONG&gt;: &lt;STRONG&gt;Htf1&lt;/STRONG&gt;&lt;/P&gt;&lt;P&gt;Here I can not see the same in the server :&lt;/P&gt;&lt;P&gt;"Successful Network Logon: User Name: &lt;STRONG&gt;$nrddu&lt;/STRONG&gt; Domain: sdap Logon ID: (0x0,0x5F669D39) Logon Type: 3 Logon Process: &lt;STRONG&gt;Kerberos Authentication Package: Kerberos Workstation Name&lt;/STRONG&gt;:&lt;/P&gt;&lt;P&gt;Is there any differnace in this  NtLmSsp Authentication Package and Kerberos Authentication Package in capturing the logs...&lt;/P&gt;&lt;P&gt;Kishore&lt;/P&gt;&lt;P&gt;&lt;A href="mailto:kishoressk@rediffmail.com"&gt;&lt;/A&gt; </description><pubDate>Fri, 14 Aug 2009 03:18:41 GMT</pubDate><dc:creator>kitchu25</dc:creator></item></channel></rss>
