Yes, the IP, Workstation name and user name all match up to the correct persons. The traffic is definitely coming from these areas and I suspect no malicious activity. It's just killing our event log.
Also, they are 529 and 680 errors.
Example of 680
-----------------
Logon attempt by: MICROSOFT_AUTHENTICATION_PACKAGE_V1_0
Logon account: SMITHXJA
Source Workstation: A111111
Error Code: 0xC0000064
Example of 529
-----------------
Logon Failure:
Reason: Unknown user name or bad...
Hello-
We have a remote 2003 server that is connected to our windows domain back at HQ. In the security log in event viewer we are getting 100's of failed login attempts per day from users within the company that we KNOW are not trying to contact the server. These users are not apart of this...
This site uses cookies to help personalise content, tailor your experience and to keep you logged in if you register.
By continuing to use this site, you are consenting to our use of cookies.