I receive these event #529 in the security log every 2 to 5 minutes. The user is always NT Authority\System, the computer is always server-10, the source ip is always for the server-9, but the source port changes every 1-3 times. From the server-9 I receive the exact same events that relate to the ip for server-10.
Event Type: Failure Audit
Event Source: Security
Event Category: Logon/Logoff
Event ID: 529
Date: 6/29/2007
Time: 9:12:58 AM
User: NT AUTHORITY\SYSTEM
Computer: server-10
Description:
Logon Failure:
Reason: Unknown user name or bad password
User Name:
Domain:
Logon Type: 3
Logon Process: Kerberos
Authentication Package: Kerberos
Workstation Name: -
Caller User Name: -
Caller Domain: -
Caller Logon ID: -
Caller Process ID: -
Transited Services: -
Source Network Address: (IP for server-9)
Source Port: 2031
There are no duplicate computer names or user names in the AD.
Thanks for any help with this,
David.
Event Type: Failure Audit
Event Source: Security
Event Category: Logon/Logoff
Event ID: 529
Date: 6/29/2007
Time: 9:12:58 AM
User: NT AUTHORITY\SYSTEM
Computer: server-10
Description:
Logon Failure:
Reason: Unknown user name or bad password
User Name:
Domain:
Logon Type: 3
Logon Process: Kerberos
Authentication Package: Kerberos
Workstation Name: -
Caller User Name: -
Caller Domain: -
Caller Logon ID: -
Caller Process ID: -
Transited Services: -
Source Network Address: (IP for server-9)
Source Port: 2031
There are no duplicate computer names or user names in the AD.
Thanks for any help with this,
David.