Tek-Tips is the largest IT community on the Internet today!

Members share and learn making Tek-Tips Forums the best source of peer-reviewed technical information on the Internet!

  • Congratulations Wanet Telecoms Ltd on being selected by the Tek-Tips community for having the most helpful posts in the forums last week. Way to Go!

Security event 565 every 20 minutes

Status
Not open for further replies.

fenstrat

Technical User
Nov 5, 2002
226
US
I am getting this same security event from this server only, about every 20 minutes. Does anyone know what this is about.
Thanks

Event Type: Failure Audit
Event Source: Security
Event Category: Directory Service Access
Event ID: 565
Date: 3/10/2003
Time: 8:08:59 PM
User: SJC\WEREWOLF$
Computer: ULYSSES
Description:
Object Open:
Object Server: DS
Object Type: dnsNode
Object Name: DC=7.104,DC=16.172.in-addr.arpa,CN=MicrosoftDNS,CN=System,DC=sjc,DC=sjca,DC=edu
New Handle ID: -
Operation ID: {0,135079876}
Process ID: 284
Primary User Name: ULYSSES$
Primary Domain: SJC
Primary Logon ID: (0x0,0x3E7)
Client User Name: WEREWOLF$
Client Domain: SJC
Client Logon ID: (0x0,0x80D27B6)
Accesses Write Self

Privileges -

Properties:
Write Property
%{00000000-0000-0000-0000-000000000000}
---
dnsRecord
ACCESS_SYS_SEC
dNSTombstoned


 
it appears it's trying to access a DNS server, maybe syncronizing. It might not have access to the DNS server it is trying to sync with.
 
I have something very close to this issue above, what do you think is the problem? Is there a way to derrive from the object name what this error is referring to?
How can I get it resolved.

Here is the security event failure:
Object Open:
Object Server: DS
Object Type: container
Object Name: %{d5300749-0b5a-4983-9784-e1d5d4cf46d2}
New Handle ID: -
Operation ID: {0,27260191}
Process ID: 244
Primary User Name: ADMIN$
Primary Domain: ADMIN
Primary Logon ID: (0x0,0x3E7)
Client User Name: MAIL$
Client Domain: ADMIN
Client Logon ID: (0x0,0x176DBE9)
Accesses Read Property

Privileges -

Properties:
READ_CONTROL
SYNCHRONIZE
Read Property
Write Property
%{00000000-0000-0000-0000-000000000000}
DELETE
READ_CONTROL
WRITE_DAC
SYNCHRONIZE
Delete Child
List Contents
Read Property
Write Property
uSNChanged
 
Status
Not open for further replies.

Part and Inventory Search

Sponsor

Back
Top