|
|
|
Forum Newbie
      
Group: Forum Members
Last Login: 11/18/2011 4:58:41 PM
Posts: 4,
Visits: 4
|
|
What would cause the source address to be missing in 528 events from Windows 2003 servers? I see this constantly and it greatly diminishes the value of these logs.
Best Regards,
Paul
|
|
|
|
|
Forum Newbie
      
Group: Forum Members
Last Login: 11/18/2011 4:58:41 PM
Posts: 4,
Visits: 4
|
|
|
|
|
|
Expert
      
Group: Administrators
Last Login: 4/20/2009 7:57:33 AM
Posts: 326,
Visits: 0
|
|
| what is the logon type # in the event? if it is 2 then it is an interactive logon at local console and thus no IP
|
|
|
|
|
Forum Newbie
      
Group: Forum Members
Last Login: 11/18/2011 4:58:41 PM
Posts: 4,
Visits: 4
|
|
There are type 2's, but I'm also seeing plenty of event type 4 and 5. Interesting, most of the type 2's are not a human at the physical (or nowadays virtual) console. They are a service accounts logging in via some automated process.
Best Regards,
Paul
|
|
|
|