Thousands of failed login 4625 events, corresponding with 1003 events form Security-SSP


i've got server running server 2012 r2, it's got few services , such, lately there have been thousand of failed logins, seem happen every 30 minutes , there 10 or @ time. checked application logs , there seem corresponding events security-ssp @ same times, event id 1003,a s few different ones @ random times. these details 4625 events:

an account failed log on.

subject:
    security id:        system
    account name:        server$
    account domain:        myserver
    logon id:        0x3e7

logon type:            3

account logon failed:
    security id:        null sid
    account name:        
    account domain:        

failure information:
    failure reason:        unknown user name or bad password.
    status:            0xc000006d
    sub status:        0xc0000064

process information:
    caller process id:    0x2c4
    caller process name:    c:\windows\system32\lsass.exe

network information:
    workstation name:    server
    source network address:    -
    source port:        -

detailed authentication information:
    logon process:        schannel
    authentication package:    kerberos
    transited services:    -
    package name (ntlm only):    -
    key length:        0

- system
- provider
[ name] microsoft-windows-security-auditing
[ guid] {54849625-5478-4994-a5ba-3e3b0328c30d}
eventid 4625
version 0
level 0
task 12544
opcode 0
keywords 0x8010000000000000
- timecreated
[ systemtime] 2014-10-08t15:39:27.023566500z
eventrecordid 555922
correlation
- execution
[ processid] 708
[ threadid] 11356
channel security
computer server.myserver.local
security
- eventdata
subjectusersid s-1-5-18
subjectusername server$
subjectdomainname myserver
subjectlogonid 0x3e7
targetusersid s-1-0-0
targetusername
targetdomainname
status 0xc000006d
failurereason %%2313
substatus 0xc0000064
logontype 3
logonprocessname schannel
authenticationpackagename kerberos
workstationname server
transmittedservices -
lmpackagename -
keylength 0
processid 0x2c4
processname c:\windows\system32\lsass.exe
ipaddress -
ipport -

and 1003 events:

- system
- provider
[ name] microsoft-windows-security-spp
[ guid] {e23b33b0-c8c9-472c-a5f9-f2bdfea0f156}
[ eventsourcename] software protection platform service
- eventid 1003
[ qualifiers] 16384
version 0
level 4
task 0
opcode 0
keywords 0x80000000000000
- timecreated
[ systemtime] 2014-10-08t11:09:21.000000000z
eventrecordid 7230
correlation
- execution
[ processid] 0
[ threadid] 0
channel application
computer server.myserver.local
security
- eventdata
55c92734-d682-4d71-983e-d6ec3f16059f

1: e96022a1-3247-4125-9ddc-4c6068ab3bfc, 1, 1 [(0 [0x00000000, 1, 0], [(?)( 1 0x00000000)(?)( 2 0x00000000 0 0 msft:rm/algorithm/hwid/4.0 0x00000000 0)(?)(?)( 10 0x00000000 msft:rm/algorithm/flags/1.0)(?)])(1 )(2 )]

there few 900, 902, 903 events. ideas happening? seems running fine.




Windows Server  >  Windows Server 2012 General



Comments

Popular posts from this blog

CRL Revocation always failed

Failed to query the results of bpa xpath

0x300000d errors in Microsoft Remote Desktop client