Tek-Tips is the largest IT community on the Internet today!

Members share and learn making Tek-Tips Forums the best source of peer-reviewed technical information on the Internet!

  • Congratulations SkipVought on being selected by the Tek-Tips community for having the most helpful posts in the forums last week. Way to Go!

Repetitive security event 528 538...

Status
Not open for further replies.

vectorw16

Technical User
Jan 21, 2002
54
0
0
CA
I have a problem on my network or server !
My server is full of security event 528 & 538 ??? (Logon/logoff message)

This is not a problem but the problem is sometime I get 50 of them in 6 minutes ... for the same USER ... !

& I'm behind a router firewall !

I'm quite sure this is not normal but where should I search ?

+ I have workstation loosing conncetion when they log and leave their computer for a few minutes and comeback to continue their work on the network... they need to relog to get access to network drive again ??

& some account are locking with no reason I set the retry to 3 but the account are locking on account you can't really miss the password ! Like if someone is trying to log from the internet on my server ! I recently add the firewall to prevent that !

I need some help I'm new in a company that before me had no antivirus for exchange, no firewall, was an open relay for spam ! I'm working hard but any tip or Int would be appreciate

Thanks


 
I'm not sure if this is normal, but all 425 of my users log 1000's of these everyday. Every resource that a user accesses on the server will gernerate two of these messages, one logon one logoff.
 
Check your audit settings- you are likely auditing logon/logoff for both success and failure. Generally speaking I only audit for failure on systems that see lots of traffic.
 
Status
Not open for further replies.

Part and Inventory Search

Sponsor

Back
Top