Eventcombmt


all,

i have domain account , has been used can't information account has been used.

i try use eventcombmt eventid 4740 adn result:

4740,audit success,microsoft-windows-security-auditing,wed jan 11 21:22:54 2017,no user,a user account locked out.    subject:   security id:  s-1-5-18   account name:  myserver$   account domain:  mydomain   logon id:  0x3e7    account locked out:   security id:  s-1-5-21-726029600-928544927-885539844-500   account name:  useraccount    additional information:   caller computer name:   
c:\temp\myserver-security_log.txt contains 1 parsed events.

does have idea computer name or used else information.

i need advice or support ideas welcome.

kind regards,

deliyurek007

this 1 might help.

https://blogs.technet.microsoft.com/poshchap/2014/05/16/tracing-the-source-of-account-lockouts/

 

 



regards, dave patrick ....
microsoft certified professional
microsoft mvp [windows server] datacenter management

disclaimer: posting provided "as is" no warranties or guarantees, , confers no rights.



Windows Server  >  Management



Comments

Popular posts from this blog

WIMMount (HSM) causing cluster storage to go redirected (2012r2 DC)

Failed to delete the test record dcdiag-test-record in zone test.com

Azure MFA with Azure AD and RDS