|
|
Forum Newbie
      
Group: Forum Members
Last Login: 6/26/2013 11:23:50 AM
Posts: 6,
Visits: 11
|
|
What would cause the source address to be missing in 528 events from Windows 2003 servers? I see this constantly and it greatly diminishes the value of these logs.
Best Regards,
Paul
|
|
|
|
Forum Newbie
      
Group: Forum Members
Last Login: 6/26/2013 11:23:50 AM
Posts: 6,
Visits: 11
|
|
|
|
|
Expert
      
Group: Administrators
Last Login: 4/20/2009 7:57:33 AM
Posts: 329,
Visits: 0
|
|
what is the logon type # in the event? if it is 2 then it is an interactive logon at local console and thus no IP
|
|
|
|
Forum Newbie
      
Group: Forum Members
Last Login: 6/26/2013 11:23:50 AM
Posts: 6,
Visits: 11
|
|
There are type 2's, but I'm also seeing plenty of event type 4 and 5. Interesting, most of the type 2's are not a human at the physical (or nowadays virtual) console. They are a service accounts logging in via some automated process.
Best Regards,
Paul
|
|
|
|