Windows-Server-2003

事件查看器視窗 2003 中有很多登錄/註銷事件

  • June 6, 2012

我似乎在安全事件查看器中獲得了很多這些條目。大約每小時8-12點。我想知道a)我應該擔心嗎?或b)實際發生了什麼,有人可以幫忙嗎?

Type: Success Audit
Source: Security
Category: Logon/Logoff
User: Network Service or IUSR_WIN2003


Logon attempt using explicit credentials:
Logged on user:
   User Name:  NETWORK SERVICE
   Domain:     NT AUTHORITY
   Logon ID:       (0x0,0x3E4)
   Logon GUID: -
User whose credentials were used:
   Target User Name:   IUSR_WIN2003
   Target Domain:  WILDEBB1
   Target Logon GUID: -

Target Server Name:    localhost
Target Server Info:    localhost
Caller Process ID: 13224
Source Network Address:    -
Source Port:   -

同樣在錄製完這個之後,iis停止接受連接,我不得不重新啟動伺服器。與此不同的是,登錄過程使用了 ADVAPI…

Event Type: Success Audit
Event Source:   Security
Event Category: Logon/Logoff 
Event ID:   540
Date:       05/06/2012
Time:       13:59:10
User:       WILDEAA1\IUSR_WIN2003
Computer:   WILDEAA1
Description:
Successful Network Logon:
   User Name:  IUSR_WIN2003
   Domain:     WILDEAA1
   Logon ID:       (0x0,0x5FDB22D)
   Logon Type: 8
   Logon Process:  Advapi  
   Authentication Package: Negotiate
   Workstation Name:   WILDEAA1
   Logon GUID: -
   Caller User Name:   NETWORK SERVICE
   Caller Domain:  NT AUTHORITY
   Caller Logon ID:    (0x0,0x3E4)
   Caller Process ID: 13224
   Transited Services: -
   Source Network Address: -
   Source Port:    -

IUSR 帳戶是安裝 IIS 時創建的匿名使用者帳戶。您是否在該伺服器上執行任何網站?每當 IIS 嘗試為匿名使用者登錄帳戶時,您都會看到一個登錄事件。

引用自:https://serverfault.com/questions/395961