I get the following entry in the event viewer of a server on our WAN. It is not a DC. Why would a computer be logging on to this server? We are getting thousands of these entries in various servers throughout the system.
Event Type: Success Audit
Event Source: Security
Event Category: Logon/Logoff
Event ID: 538
Date: 1/11/2005
Time: 4:31:47 PM
User: ADMIN\ADBUSXX$
Computer: xxSRVNT
Description:
User Logoff:
User Name: ADBUSXX$
Domain: ADMIN
Logon ID: (0x0,0x1361262)
Logon Type: 3
Thanks.
Event Type: Success Audit
Event Source: Security
Event Category: Logon/Logoff
Event ID: 538
Date: 1/11/2005
Time: 4:31:47 PM
User: ADMIN\ADBUSXX$
Computer: xxSRVNT
Description:
User Logoff:
User Name: ADBUSXX$
Domain: ADMIN
Logon ID: (0x0,0x1361262)
Logon Type: 3
Thanks.