What is 'NT AUTHORITY\ANONYMOUS LOGON' every 15 secs
I am a second administrator on a Windows Server 2003 and when I go into Event Viewer then it is showing me Security events 538 and 540 every now and then. Can I stop 'Success Audit....Logon/Logoff....ANONYMOUS LOGON', is it ok or should i just disable this events not to show up? Thanks for any reply.
RE: What is 'NT AUTHORITY\ANONYMOUS LOGON' every 15 secs
I just found out that it is coming from only a single workstation and have been happening from a very long time. Below are its details:
Event Type: Success Audit
Event Source: Security
Event Category: Logon/Logoff
Event ID: 540
Date: 6/11/2008
Time: 11:59:44 AM
User: NT AUTHORITY\ANONYMOUS LOGON
Computer: MMPA-WS1
Description:
Successful Network Logon:
User Name:
Domain:
Logon ID: (0x0,0x37E8C04)
Logon Type: 3
Logon Process: NtLmSsp
Authentication Package: NTLM
Workstation Name: JUSTIN
Logon GUID: -
Caller User Name: -
Caller Domain: -
Caller Logon ID: -
Caller Process ID: -
Transited Services: -
Source Network Address: 192.168.1.103
Source Port: 0
For more information, see Help and Support Center at
http://go.microsoft.com/fwlink/events.asp.