G
Guest
I have a win2k terminal server with citrix installed
I have auditing setup on this server for successful and unsuccessful logon
events
In my event viewer I have this
Event Type: Success Audit
Event Source: Security
Event Category: Logon/Logoff
Event ID: 540
Date: 6/1/2005
Time: 6:36:40 AM
User: RMH\ecoombs
Computer: RMH-CITRIX-1
Description:
Successful Network Logon:
User Name: xxxxxxx
Domain: xxxxx
Logon ID: (0x0,0xE5CD350)
Logon Type: 3
Logon Process: NtLmSsp
Authentication Package: NTLM
Workstation Name: xxxxxxxx
This user doesnt show a profile on the server so I am wondering how to track
down what type of activity it was
This user shouldnt be accessing this server
Thanks in advance
I have auditing setup on this server for successful and unsuccessful logon
events
In my event viewer I have this
Event Type: Success Audit
Event Source: Security
Event Category: Logon/Logoff
Event ID: 540
Date: 6/1/2005
Time: 6:36:40 AM
User: RMH\ecoombs
Computer: RMH-CITRIX-1
Description:
Successful Network Logon:
User Name: xxxxxxx
Domain: xxxxx
Logon ID: (0x0,0xE5CD350)
Logon Type: 3
Logon Process: NtLmSsp
Authentication Package: NTLM
Workstation Name: xxxxxxxx
This user doesnt show a profile on the server so I am wondering how to track
down what type of activity it was
This user shouldnt be accessing this server
Thanks in advance