
Chapter 2 Fault Management System 161
Business Communications Manager - Management User Guide
Security
Security Return to table: Component ID (alarm)/eventSource (trap) summary
Return to table: Component ID alarms/eventSource (Trap) by event ID
Service: EventLog
Event ID: 512 Message: Windows NT is starting up.
User action: No action required.
Alarm severity: Warning
Trap-type: Success / Audit
Logs: None
Event ID: 515 Message: A trusted logon process has registered with the Local Security
Authority. This logon process will be trusted to submit logon requests.
Logon Process Name: \inetinfo.exe
User action: No action required.
Alarm severity: Warning
Trap-type: Success / Audit
Logs: None
Event ID: 528 Message: Successful Logon: User Name: <user name> Domain: <domain>
Logon ID: <id> Logon Type: <type> Logon Process: User32
Authentication Package: <package version> Workstation Name:
<name>
User action: No action required.
Alarm severity: Warning
Trap-type: Success / Audit
Logs: None
Event ID: 529 Message: Logon Failure: Reason: Unknown user name or bad password User
Name: <user name> Domain: <domain> Logon Type: <type> Logon
Process: User32 Authentication Package: <package version>
Workstation Name: <name>
User action: No action required. However, this event may indicate an un-authorized
access attempt.
Alarm severity: Major
Trap-type: Failure / Audit
Logs: None
Event ID: 538 Message: User Logoff: User Name: <name> Domain: <domain> Logon ID: <id>
Logon Type: 3
User action: No action required.
Alarm severity: Warning
Trap-type: Success / Audit
Logs: None
Event ID: 577 Message: Privileged Service Called: Server: NT Local Security Authority /
Authentication Service Service: LsaRegisterLogonProcess() Primary
User Name: SYSTEM Primary Domain: NT AUTHORITY Primary
Logon ID: (0x0,0x3E7) Client User Name: <User> Client Domain:
<Domain> Client Logon ID: (0x0,0x1234) Privileges: SeTcbPrivilege
User action: No action required. This event does not indicate a security breach; you
can safely ignore it.
Comentários a estes Manuais