i've got server running server 2012 r2, it's got few services , such, lately there have been thousand of failed logins, seem happen every 30 minutes , there 10 or @ time. checked application logs , there seem corresponding events security-ssp @ same times, event id 1003,a s few different ones @ random times. these details 4625 events:
an account failed log on.
subject:
security id: system
account name: server$
account domain: myserver
logon id: 0x3e7
logon type: 3
account logon failed:
security id: null sid
account name:
account domain:
failure information:
failure reason: unknown user name or bad password.
status: 0xc000006d
sub status: 0xc0000064
process information:
caller process id: 0x2c4
caller process name: c:\windows\system32\lsass.exe
network information:
workstation name: server
source network address: -
source port: -
detailed authentication information:
logon process: schannel
authentication package: kerberos
transited services: -
package name (ntlm only): -
key length: 0
| | | | | [ name] | microsoft-windows-security-auditing | | | | [ guid] | {54849625-5478-4994-a5ba-3e3b0328c30d} | |
| | | keywords | 0x8010000000000000 | |
| | | | | [ systemtime] | 2014-10-08t15:39:27.023566500z | |
| | | computer | server.myserver.local | |
| | subjectdomainname | myserver |
| | logonprocessname | schannel |
| | authenticationpackagename | kerberos |
| | processname | c:\windows\system32\lsass.exe |
and 1003 events:
| | | | | [ name] | microsoft-windows-security-spp | | | | [ guid] | {e23b33b0-c8c9-472c-a5f9-f2bdfea0f156} | | | | [ eventsourcename] | software protection platform service | |
| | | keywords | 0x80000000000000 | |
| | | | | [ systemtime] | 2014-10-08t11:09:21.000000000z | |
| | | computer | server.myserver.local | |
| | | 55c92734-d682-4d71-983e-d6ec3f16059f |
| | | 1: e96022a1-3247-4125-9ddc-4c6068ab3bfc, 1, 1 [(0 [0x00000000, 1, 0], [(?)( 1 0x00000000)(?)( 2 0x00000000 0 0 msft:rm/algorithm/hwid/4.0 0x00000000 0)(?)(?)( 10 0x00000000 msft:rm/algorithm/flags/1.0)(?)])(1 )(2 )] |
there few 900, 902, 903 events. ideas happening? seems running fine.
Windows Server > Windows Server 2012 General
Comments
Post a Comment