Event Log Security Failure Message

M

MJ

Hello, I hope someone can help me. The Security Log on our W2K DC is chock
full of this message - at least 100 of these messages appear in the log
every day!

Date: 2/25/2004 Source: Security
Time: 9:00:40 AM Category: Logon/Logoff
Type: Failure Aud Event ID: 537
User: NT AUTHORITY\SYSTEM
Computer: SERVER_NTP2


Description:
Logon Failure:
Reason: An unexpected error occurred during logon
User Name:
Domain:
Logon Type: 3
Logon Process: Kerberos
Authentication Package: Kerberos
Workstation Name: -

For more information, see Help and Support Center at
http://go.microsoft.com/fwlink/events.asp.

There is no information available when I click on that link. I should also
mention that the log is "peppered" with the following Success Audit messages
(approx 1 Success Audit message for every 20-25 Failure Audit messages):

Date: 2/24/2004 Source: Security
Time: 6:34:46 PM Category: Policy Change
Type: Success Audit Event ID: 617
User: NT AUTHORITY\SYSTEM
Computer: SERVER_NTP2

Description:

Kerberos Policy Changed:
Changed By:
User Name: MATRIX_NTP2$
Domain Name: MICNET
Logon ID: (0x0,0x3E7)
Changes made:
('--' means no changes, otherwise each change is shown as:
<ParameterName>: <new value> (<old value>))
--

I don't understand what either of these event log messages mean, so I'm
turning here for some help!!!

Thanks in advance for any/all replies.

MJ
 

Ask a Question

Want to reply to this thread or ask your own question?

You'll need to choose a username for the site, which only take a couple of moments. After that, you can post your question and our members will help you out.

Ask a Question

Top