Eventcombmt


all,

i have domain account , has been used can't information account has been used.

i try use eventcombmt eventid 4740 adn result:

4740,audit success,microsoft-windows-security-auditing,wed jan 11 21:22:54 2017,no user,a user account locked out.    subject:   security id:  s-1-5-18   account name:  myserver$   account domain:  mydomain   logon id:  0x3e7    account locked out:   security id:  s-1-5-21-726029600-928544927-885539844-500   account name:  useraccount    additional information:   caller computer name:   
c:\temp\myserver-security_log.txt contains 1 parsed events.

does have idea computer name or used else information.

i need advice or support ideas welcome.

kind regards,

deliyurek007

this 1 might help.

https://blogs.technet.microsoft.com/poshchap/2014/05/16/tracing-the-source-of-account-lockouts/

 

 



regards, dave patrick ....
microsoft certified professional
microsoft mvp [windows server] datacenter management

disclaimer: posting provided "as is" no warranties or guarantees, , confers no rights.



Windows Server  >  Management



Comments

Popular posts from this blog

Azure MFA with Azure AD and RDS

Failed to setup initiator portal. Error status is given in the dump data.

Invalid pointer on gpresult /h gpreport.html