NT security event logger not showing failed attempts

This is a discussion about NT security event logger not showing failed attempts in the Windows Networking category; Our PDC is not logging all failed logon attempts any longer. It used to log any attempt by anyone to logon to the network if it failed due to bad user name or bad password. Now it only logs failed attempts if you try to logon to the network at the PDC, but not for clients who try to logon.

Windows Networking 2246 This topic was started by ,


data/avatar/default/avatar26.webp

21 Posts
Location -
Joined 2002-01-17
Our PDC is not logging all failed logon attempts any longer. It used to log any attempt by anyone to logon to the network if it failed due to bad user name or bad password. Now it only logs failed attempts if you try to logon to the network at the PDC, but not for clients who try to logon. I can't see anywhere that this setting can be changed--it used to be all users at all PCs showed up in this log. It still logs successful logons from all users, but not unsuccessful logons, and it logs it if the user account gets locked out due to too many bad attempts. Is it possible that the system has been hacked to turn this off, if so, how to fix it?
 
Thanks

Participate in our website and join the conversation

You already have an account on our website? To log in, use the link provided below.
Login
Create a new user account. Registration is free and takes only a few seconds.
Register
This subject has been archived. New comments and votes cannot be submitted.
Feb 2
Created
Feb 3
Last Response
0
Likes
1 minute
Read Time
User User
Users

Responses to this topic


data/avatar/default/avatar03.webp

581 Posts
Location -
Joined 2002-04-27
Goto user manager and under policies make sure the appropriate logging is set "on unsuccessful"
You say that successful loggin gets logged so this means your logging is enabled, so redoing this setting should workx0r.

data/avatar/default/avatar26.webp

21 Posts
Location -
Joined 2002-01-17
OP
That has been the audit policy all along in user manager. It's checked, but still no record in the security event log.