lachesis09
IS-IT--Management
Hi
Really desparate for help here in tracking down the problem. I've recently added a new WSUS Server and new DC, and across the domain controllers am getting the following message in the security log under a 'failure audit':
Event Type: Failure Audit
Event Source: Security
Event Category: Logon/Logoff
Event ID: 537
Date: 15/07/2008
Time: 09:56:00
User: NT AUTHORITY\SYSTEM
Computer: xxxx
Description:
Logon Failure:
Reason: An error occurred during logon
User Name:
Domain:
Logon Type: 3
Logon Process: Kerberos
Authentication Package: Kerberos
Workstation Name: -
Status code: 0xC000006D
Substatus code: 0xC0000133
Caller User Name: -
Caller Domain: -
Caller Logon ID: -
Caller Process ID: -
Transited Services: -
Source Network Address: xxx.xxx.xxx.xxx
Source Port: 0
For more information, see Help and Support Center at
Now, I'm stuck on where to go - the ip address keeps changing to different clients on the network in each message. WSUS reports that all updates are successful to the groups I've allocated them to, and I can't really think of whats causing this, I've also moved over roles to the new DC including PDC Emu, RID, Infrastructure manager, WINS and DNS.
Can anyone offer any insight here on where to check/what to do to track this down?
Really desparate for help here in tracking down the problem. I've recently added a new WSUS Server and new DC, and across the domain controllers am getting the following message in the security log under a 'failure audit':
Event Type: Failure Audit
Event Source: Security
Event Category: Logon/Logoff
Event ID: 537
Date: 15/07/2008
Time: 09:56:00
User: NT AUTHORITY\SYSTEM
Computer: xxxx
Description:
Logon Failure:
Reason: An error occurred during logon
User Name:
Domain:
Logon Type: 3
Logon Process: Kerberos
Authentication Package: Kerberos
Workstation Name: -
Status code: 0xC000006D
Substatus code: 0xC0000133
Caller User Name: -
Caller Domain: -
Caller Logon ID: -
Caller Process ID: -
Transited Services: -
Source Network Address: xxx.xxx.xxx.xxx
Source Port: 0
For more information, see Help and Support Center at
Now, I'm stuck on where to go - the ip address keeps changing to different clients on the network in each message. WSUS reports that all updates are successful to the groups I've allocated them to, and I can't really think of whats causing this, I've also moved over roles to the new DC including PDC Emu, RID, Infrastructure manager, WINS and DNS.
Can anyone offer any insight here on where to check/what to do to track this down?