Problem reading Event Log

Forum Windows 2000/NT : Windows 2000/NT General Discussion - Problem reading Event Log

Tom's Hardware: Over 1.4 million members in 6 different countries available to answer all your high-tech questions. Sign up now! Its free!
Word :    Username :           
 

Archived from groups: microsoft.public.win2000.security (More info?)

 

I'm reading the event log on a 2k3 domain controller using the
ReadEventLog API call from a C program. One of the events of interest is
Security event 540 - network logon - generated by Win2k clients.
According to the MSDN documentation the parameters returned should be:

User name
Domain
Logon ID
Logon type
Logon process
Auth package
Workstation name

However the Event Log Viewer on the server also reports these items for
event 540:

Logon GUID
Caller user name
Caller domain
Caller logon ID
Transited services
Source IP address
Source port

Looking at a binary dump of the event log entry there is no sign of
these extra items in the log. Does anyone know where they are coming
from and how I can retrieve them?

(The particular problem I have is that the 'workstation' field is blank
so I need the IP address field to do a reverse-lookup).
--
Dave

Sponsored Links
Register or log in to remove.
Tom's Hardware > Forum > Windows 2000/NT > Windows 2000/NT General Discussion > Problem reading Event Log
Go to:

There are 1167 identified and unidentified users. To see the list of identified users, Click here.

Please mind

You are about to answer a thread that has been inactive for more than 6 months.
If you still wish to proceed, please ensure that your posting is original and does not duplicate or overlap any prior responses to this thread.

Add a reply Cancel
Sponsored links
  • Ask the community now
  • Publish
Ad
They won a badge
Join us in greeting them