Windows Vista Tips

Windows Vista Tips > Newsgroups > Windows Server > Server Security > Re: The security log is getting quickly filled

Reply
Thread Tools Display Modes

Re: The security log is getting quickly filled

 
 
Special Access
Guest
Posts: n/a

 
      10-22-2009
On Wed, 21 Oct 2009 08:36:20 -0700 (PDT), linux
<> wrote:

>Hi Team,
>
>On couple of machines running on 2003 server. We find security log
>file getting quickly filled.
>In our enviroment we have to preserve 90 days of log, but it gets
>filled up by 3 - 4 days and it have been diffcult to backup it very
>frequently.
>
>We notice security log file is getting filled with 10 -15 failed Audit
>every second.
>Event Description
>Source: Security
>Category: Account Logon
>Type: Failure Aud
>Event ID: 680
>User NT AUTHORITY\SYSTEM
>Logon attempt by: MICROSOFT_AUTHENTICATION_PACKAGE_V1_0
>Logon account: Administrator
>Error Code: 0xC000006A
>
>Another Type
>
>Event Description
>Source: Security
>Category: Logon/Logoff
>Type: Failure Aud
>Event ID: 529
>User: NT AUTHORITY\SYSTEM
>Logon Failure:
>Reason: Unknown user name or bad password
>User Name: Administrator
>logon Type: 3
>Logon Process: NtLmSsp
>Authentication Package: NTLM
>
>By these event we got to know the Workstation Name causing this
>problem.
>
> There was continues attempt made to access 445 and 139 port. Process
>ID was 0
>
>Need help to identify and fix this threat.
>



Maybe check the services to see if any are using "administrator"
rather than "system".... If the "administrator" password was changed
for the user but not the service, this can happen.

or look here:
http://www.eventid.net/display.asp?e...curity&phase=1
for other suggestions on what can cause the 680.

Mike
 
Reply With Quote
 
 
 
Reply

Thread Tools
Display Modes

Posting Rules
You may not post new threads
You may not post replies
You may not post attachments
You may not edit your posts

BB code is On
Smilies are On
[IMG] code is On
HTML code is Off
Trackbacks are On
Pingbacks are On
Refbacks are Off


Similar Threads
Thread Thread Starter Forum Replies Last Post
Vista Accounts issue davey_griffo Windows Vista Administration 32 02-27-2008 09:12 PM
Files on D from XP have strange user under Security. Trond Windows Vista Administration 6 03-04-2007 02:57 AM
Files on D: from XP have strange user under Security. Trond Windows Vista Administration 0 02-25-2007 12:49 AM
set security level back to the same as XP possible ???? m j o Windows Vista Performance 3 02-18-2007 09:48 PM
set security level back to the same as XP possible ???? m j o Windows Vista Installation 1 02-14-2007 02:14 AM



1 2 3 4 5 6 7 8 9 10 11 12 13 14 15 16 17 18 19 20 21 22 23 24 25 26 27 28 29 30 31 32 33 34 35 36 37 38 39 40 41 42 43 44 45 46 47 48 49 50 51 52 53 54 55 56 57 58 59