If you're using a NT4.0 domain, you can go to User Manager, then Policies -> Audit and change your logging preferences. Add auditing for unsuccessful logons and they will show up in Event Viewer
Jason Weirauch -----Original Message----- From: Harish Gondavale [mailto:[EMAIL PROTECTED]] Sent: Wednesday, June 12, 2002 3:17 AM To: [EMAIL PROTECTED] Subject: NT Domain - unsucessful login attepmts Hi, We have got a NT domain which is used as a resource domain. Recently we found that there are few unsucessful attempts tried with some strange domain name and user id. (from security eveent logs) My question is 1. Is there any way to identify these machines - form where it was tried ? 2. Is there any way to monitor these servers and alert generated if any unsucessful attaepmt? ( I know we can implement IDS and acieve this. But any special tool for NT other than IDS. Also if IDS is the only solution then which is the best IDS)? Thanks in advance for help. Bye. Harish __________________________________________________ Do You Yahoo!? Everything you'll ever need on one web page from News and Sport to Email and Music Charts http://uk.my.yahoo.com
