S
Shannon Moyer
Can anyone help with this event log error?
Log Name: Security
Source: Microsoft-Windows-Security-Auditing
Date: 7/21/2019 2:00:01 PM
Event ID: 4768
Task Category: Kerberos Authentication Service
Level: Information
Keywords: Audit Failure
User: N/A
Computer: FS01.POPPOFF.local
Description:
A Kerberos authentication ticket (TGT) was requested.
Account Information:
Account Name: @@CyBAAAAUBQYAMHArBwUAMGAoBQZAQGA1BAbAUGAyBgOAQFAhBwcAsGA6AweAEEAFBANAQEAEBQQAIDA5AQLAMEAEBQRAADAtAANAMDA1AQRA0CABBwMAYDA1AQLAIDAGBARAUEA4AQQAQDACBgRAYEAGBQNA0HA
Supplied Realm Name: POPPOFF.LOCAL
User ID: NULL SID
Service Information:
Service Name: krbtgt/POPPOFF.LOCAL
Service ID: NULL SID
Network Information:
Client Address: ::ffff:192.168.1.13
Client Port: 49925
Additional Information:
Ticket Options: 0x40810010
Result Code: 0x6
Ticket Encryption Type: 0xFFFFFFFF
Pre-Authentication Type: -
Certificate Information:
Certificate Issuer Name:
Certificate Serial Number:
Certificate Thumbprint:
Certificate information is only provided if a certificate was used for pre-authentication.
Pre-authentication types, ticket options, encryption types and result codes are defined in RFC 4120.
Event Xml:
<Event xmlns="http://schemas.microsoft.com/win/2004/08/events/event">
<System>
<Provider Name="Microsoft-Windows-Security-Auditing" Guid="{54849625-5478-4994-A5BA-3E3B0328C30D}" />
<EventID>4768</EventID>
<Version>0</Version>
<Level>0</Level>
<Task>14339</Task>
<Opcode>0</Opcode>
<Keywords>0x8010000000000000</Keywords>
<TimeCreated SystemTime="2019-07-21T21:00:01.790004400Z" />
<EventRecordID>58434053</EventRecordID>
<Correlation />
<Execution ProcessID="776" ThreadID="3328" />
<Channel>Security</Channel>
<Computer>FS01.POPPOFF.local</Computer>
<Security />
</System>
<EventData>
<Data Name="TargetUserName">@@CyBAAAAUBQYAMHArBwUAMGAoBQZAQGA1BAbAUGAyBgOAQFAhBwcAsGA6AweAEEAFBANAQEAEBQQAIDA5AQLAMEAEBQRAADAtAANAMDA1AQRA0CABBwMAYDA1AQLAIDAGBARAUEA4AQQAQDACBgRAYEAGBQNA0HA</Data>
<Data Name="TargetDomainName">POPPOFF.LOCAL</Data>
<Data Name="TargetSid">S-1-0-0</Data>
<Data Name="ServiceName">krbtgt/POPPOFF.LOCAL</Data>
<Data Name="ServiceSid">S-1-0-0</Data>
<Data Name="TicketOptions">0x40810010</Data>
<Data Name="Status">0x6</Data>
<Data Name="TicketEncryptionType">0xffffffff</Data>
<Data Name="PreAuthType">-</Data>
<Data Name="IpAddress">::ffff:192.168.1.13</Data>
<Data Name="IpPort">49925</Data>
<Data Name="CertIssuerName">
</Data>
<Data Name="CertSerialNumber">
</Data>
<Data Name="CertThumbprint">
</Data>
</EventData>
</Event>
Shannon Moyer Parsec Computer Corporation
Continue reading...
Log Name: Security
Source: Microsoft-Windows-Security-Auditing
Date: 7/21/2019 2:00:01 PM
Event ID: 4768
Task Category: Kerberos Authentication Service
Level: Information
Keywords: Audit Failure
User: N/A
Computer: FS01.POPPOFF.local
Description:
A Kerberos authentication ticket (TGT) was requested.
Account Information:
Account Name: @@CyBAAAAUBQYAMHArBwUAMGAoBQZAQGA1BAbAUGAyBgOAQFAhBwcAsGA6AweAEEAFBANAQEAEBQQAIDA5AQLAMEAEBQRAADAtAANAMDA1AQRA0CABBwMAYDA1AQLAIDAGBARAUEA4AQQAQDACBgRAYEAGBQNA0HA
Supplied Realm Name: POPPOFF.LOCAL
User ID: NULL SID
Service Information:
Service Name: krbtgt/POPPOFF.LOCAL
Service ID: NULL SID
Network Information:
Client Address: ::ffff:192.168.1.13
Client Port: 49925
Additional Information:
Ticket Options: 0x40810010
Result Code: 0x6
Ticket Encryption Type: 0xFFFFFFFF
Pre-Authentication Type: -
Certificate Information:
Certificate Issuer Name:
Certificate Serial Number:
Certificate Thumbprint:
Certificate information is only provided if a certificate was used for pre-authentication.
Pre-authentication types, ticket options, encryption types and result codes are defined in RFC 4120.
Event Xml:
<Event xmlns="http://schemas.microsoft.com/win/2004/08/events/event">
<System>
<Provider Name="Microsoft-Windows-Security-Auditing" Guid="{54849625-5478-4994-A5BA-3E3B0328C30D}" />
<EventID>4768</EventID>
<Version>0</Version>
<Level>0</Level>
<Task>14339</Task>
<Opcode>0</Opcode>
<Keywords>0x8010000000000000</Keywords>
<TimeCreated SystemTime="2019-07-21T21:00:01.790004400Z" />
<EventRecordID>58434053</EventRecordID>
<Correlation />
<Execution ProcessID="776" ThreadID="3328" />
<Channel>Security</Channel>
<Computer>FS01.POPPOFF.local</Computer>
<Security />
</System>
<EventData>
<Data Name="TargetUserName">@@CyBAAAAUBQYAMHArBwUAMGAoBQZAQGA1BAbAUGAyBgOAQFAhBwcAsGA6AweAEEAFBANAQEAEBQQAIDA5AQLAMEAEBQRAADAtAANAMDA1AQRA0CABBwMAYDA1AQLAIDAGBARAUEA4AQQAQDACBgRAYEAGBQNA0HA</Data>
<Data Name="TargetDomainName">POPPOFF.LOCAL</Data>
<Data Name="TargetSid">S-1-0-0</Data>
<Data Name="ServiceName">krbtgt/POPPOFF.LOCAL</Data>
<Data Name="ServiceSid">S-1-0-0</Data>
<Data Name="TicketOptions">0x40810010</Data>
<Data Name="Status">0x6</Data>
<Data Name="TicketEncryptionType">0xffffffff</Data>
<Data Name="PreAuthType">-</Data>
<Data Name="IpAddress">::ffff:192.168.1.13</Data>
<Data Name="IpPort">49925</Data>
<Data Name="CertIssuerName">
</Data>
<Data Name="CertSerialNumber">
</Data>
<Data Name="CertThumbprint">
</Data>
</EventData>
</Event>
Shannon Moyer Parsec Computer Corporation
Continue reading...