madman070578
IS-IT--Management
Can anyone help me? My event viewer on my Windows 2003 Server keeps filling up the SECURITY log with events 540, and 578. The event log message for the 2 events are below. Hope someone can help me resolve the problem!
Event Type: Success Audit
Event Source: Security
Event Category: Logon/Logoff
Event ID: 540
Date: 07/10/2003
Time: 10:59:43
User: NT AUTHORITY\SYSTEM
Computer: SERVER
Description:
Successful Network Logon:
User Name: SERVER$
Domain: DEW
Logon ID: (0x0,0x6E85BE)
Logon Type: 3
Logon Process: Kerberos
Authentication Package: Kerberos
Workstation Name:
Logon GUID: {b4842bf0-9127-40e6-4327-b3cfd1d5bf3c}
Caller User Name: -
Caller Domain: -
Caller Logon ID: -
Caller Process ID: -
Transited Services: -
Source Network Address: 10.22.1.1
Source Port: 3424
For more information, see Help and Support Center at
Event Type: Success Audit
Event Source: Security
Event Category: Privilege Use
Event ID: 576
Date: 07/10/2003
Time: 10:59:41
User: NT AUTHORITY\SYSTEM
Computer: SERVER
Description:
Special privileges assigned to new logon:
User Name: SERVER
Domain: DEW
Logon ID: (0x0,0x6E84B7)
Privileges: SeBackupPrivilege
SeRestorePrivilege
SeDebugPrivilege
SeChangeNotifyPrivilege
For more information, see Help and Support Center at
d.philpin@dewisant.pembroke.sch.uk
Event Type: Success Audit
Event Source: Security
Event Category: Logon/Logoff
Event ID: 540
Date: 07/10/2003
Time: 10:59:43
User: NT AUTHORITY\SYSTEM
Computer: SERVER
Description:
Successful Network Logon:
User Name: SERVER$
Domain: DEW
Logon ID: (0x0,0x6E85BE)
Logon Type: 3
Logon Process: Kerberos
Authentication Package: Kerberos
Workstation Name:
Logon GUID: {b4842bf0-9127-40e6-4327-b3cfd1d5bf3c}
Caller User Name: -
Caller Domain: -
Caller Logon ID: -
Caller Process ID: -
Transited Services: -
Source Network Address: 10.22.1.1
Source Port: 3424
For more information, see Help and Support Center at
Event Type: Success Audit
Event Source: Security
Event Category: Privilege Use
Event ID: 576
Date: 07/10/2003
Time: 10:59:41
User: NT AUTHORITY\SYSTEM
Computer: SERVER
Description:
Special privileges assigned to new logon:
User Name: SERVER
Domain: DEW
Logon ID: (0x0,0x6E84B7)
Privileges: SeBackupPrivilege
SeRestorePrivilege
SeDebugPrivilege
SeChangeNotifyPrivilege
For more information, see Help and Support Center at
d.philpin@dewisant.pembroke.sch.uk