Tek-Tips is the largest IT community on the Internet today!

Members share and learn making Tek-Tips Forums the best source of peer-reviewed technical information on the Internet!

  • Congratulations IamaSherpa on being selected by the Tek-Tips community for having the most helpful posts in the forums last week. Way to Go!

Event ID: 538 on security audit

Status
Not open for further replies.

jfrasier

Technical User
Apr 5, 2000
33
US
I get the following entry in the event viewer of a server on our WAN. It is not a DC. Why would a computer be logging on to this server? We are getting thousands of these entries in various servers throughout the system.

Event Type: Success Audit
Event Source: Security
Event Category: Logon/Logoff
Event ID: 538
Date: 1/11/2005
Time: 4:31:47 PM
User: ADMIN\ADBUSXX$
Computer: xxSRVNT
Description:
User Logoff:
User Name: ADBUSXX$
Domain: ADMIN
Logon ID: (0x0,0x1361262)
Logon Type: 3

Thanks.
 
What exactly is the server? Is it a file server? Is it a web server?
 
I looked at this article but still don't understand why a computer (not a user, but a COMPUTER) would be logging onto a fileserver in another building.
 
This could be nothing more than a CAL verification. It could also be a timeout (the user logs off, but a connection to the server remains until the keep-alive time has surpassed).
 
I wouldn't think that this file server would be the one that CAL verification would be on and this log shows a computername, but not an associated user using that computer. It is computers in a totally different building.
 
Do any of the computers/users connect to the file server? If not, I would start looking at setting up some more access permissions on your file server.

A CAL will be verified any time that a computer tries to connect to another computer. One of those interesting little tidbits Microsoft puts out there.

 
Yes, some users have access to that file server and map drives to their user folders. However, the log shows that it is not PEOPLE logging on to that server, but computers and computers that are physically located miles away. I still don't know why a computer in one location would be logging on to a file server in another location, especially when the user of that computer is not logging on to the file server.
 
Status
Not open for further replies.

Part and Inventory Search

Sponsor

Back
Top