Hi
I've recently noticed many 529 events in the security log. I've searched and read many other topics on this event but they seem to have a different process id than what I am seeing.
Some information:
SBS2003R2 (windows update says no updates are available)
Watchguard Firebox x20e. Port 443 has been open since the server was setup in 2007. I recently opened 4125 for RWW but since closed it due to the 529 events (just in case)
McAfee SAAS is installed and used on the server and client systems.
Stong passwords were put in place as of yesterday.
The user name below varies, none of which are actual user names in use on this system.
Event Type: Failure Audit
Event Source: Security
Event Category: Logon/Logoff
Event ID: 529
Date: 10/9/2012
Time: 8:44:17 AM
User: NT AUTHORITY\SYSTEM
Computer: ServerName
Description:
Logon Failure:
Reason: Unknown user name or bad password
User Name: 1234
Domain:
Logon Type: 3
Logon Process: Advapi
Authentication Package: MICROSOFT_AUTHENTICATION_PACKAGE_V1_0
Workstation Name: ServerName
Caller User Name: ServerName$
Caller Domain: OurDomainName
Caller Logon ID: (0x0,0x3E7)
Caller Process ID: 1688
Transited Services: -
Source Network Address: -
Source Port: -
What can I do to stop this event?
Thank you.