﻿<?xml version='1.0' encoding='UTF-8'?><rss version="2.0" xmlns:dc="http://purl.org/dc/elements/1.1/"><channel><title>UltimateWindowsSecurity.com Forum / Ultimate Windows Security Forum / Security Log / 540 - Successful Network Logon  / machine accounts in code 540, 538 events / Latest Posts</title><generator>InstantForum.NET v4.1.4</generator><description>UltimateWindowsSecurity.com Forum</description><link>http://forum.ultimatewindowssecurity.com/</link><webMaster>noreply@ultimatewindowssecurity.com</webMaster><lastBuildDate>Tue, 07 Feb 2012 12:09:49 GMT</lastBuildDate><ttl>20</ttl><item><title>RE: machine accounts in code 540, 538 events</title><link>http://forum.ultimatewindowssecurity.com/Topic80-34-1.aspx</link><description>So it is true then that there is no way to effectively "stop" the vast numbers of these from being logged if you have auditing enabled?   That is unfortunate.&lt;br&gt;&lt;br&gt;For example we have several hundred systems logging to several different AD's and on average in an hour we generate 270K logs, of which 89k are Event ID 540, breaking out the Type3 and Type8 we find that about 88.5k of them are Type3 with the remaining ~500 being Type8.&lt;br&gt;&lt;br&gt;Looking closer at the Type3 we find that 50.5k of them are "ANONYMOUS LOGON"&lt;br&gt;&lt;br&gt;Such as below:&lt;br&gt;&lt;br&gt;NT AUTHORITY,ANONYMOUS LOGON,vb2k0056,Aug 27 17:59:03 2009,security,Security,"Successful Network Logon: &lt;br&gt; User Name:  Domain:  Logon ID:(0x0,0x4F6DE22B)  Logon Type:3  Logon Process:NtLmSsp   Authentication Package:NTLM  Workstation Name:VB0409237  Logon GUID:-  Caller&lt;br&gt; User Name:-  Caller Domain:-  Caller Logon ID:-  Caller Process ID: -  Transited Services: -  Source Network Address:10.153.152.154  Source Port:0 &lt;br&gt;&lt;br&gt;So no one has devised a way to no log this sort of behavior?</description><pubDate>Thu, 27 Aug 2009 19:06:51 GMT</pubDate><dc:creator>riz</dc:creator></item><item><title>RE: machine accounts in code 540, 538 events</title><link>http://forum.ultimatewindowssecurity.com/Topic80-34-1.aspx</link><description>I assume you are describing the log on a domain controller?  If so, yes that's normal.  Each computer in the domain checks in with a domain controller every 90 minutes or so to refresh group policy which causes a network logon (540) and logoff (538).  It would be nice if that auditing could just be turned off since it's noise but Windows lacks that kind of granularity.</description><pubDate>Tue, 28 Apr 2009 09:10:17 GMT</pubDate><dc:creator>RandyFranklinSmith</dc:creator></item><item><title>machine accounts in code 540, 538 events</title><link>http://forum.ultimatewindowssecurity.com/Topic80-34-1.aspx</link><description>Our WS2003 Event Viewer Security log contains many more machine log-ins than user account logins.  Is this a normal, useful configuration, or have we bollixed something?</description><pubDate>Mon, 27 Apr 2009 10:45:59 GMT</pubDate><dc:creator>Clay</dc:creator></item></channel></rss>
