An Error Occurred During Logon Event Id 537 Kerberos
Contents |
(עברית)المملكة العربية السعودية (العربية)ไทย (ไทย)대한민국 (한국어)中华人民共和国 (中文)台灣 (中文)日本 (日本語) HomeWindows Server 2012Windows Server 2008 R2Windows Server 2003LibraryForums Ask a question event id 537 0xc000005e Quick access Forums home Browse forums users FAQ
Event Id 537 Status Codes
Search related threads Remove From My Forums Answered by: Event ID: 537 status code: 0xc000006d substatus code: 0x0 logged repeatedly by one workstation Windows Server > Windows Server General Forum Question 0 Sign in to vote We an error occured during logon 0xc000006d have a problem with only one of the eight workstations in our domain; it generates many 537 (60 - 80 per day) and a few 673 security failures each day. The events are logged at all hours, often at night
Windows Event 537
and early morning. Some of these are copied below. I can find no useful information about these in the Microsoft Knowledge base. Can anyone shed some light on this problem? Thanks! David ------------------------------ Event Type: Failure AuditEvent Source: SecurityEvent Category: Account Logon Event ID: 673Date: 7/9/2009Time: 12:53:33 AMUser: NT AUTHORITY\SYSTEMComputer: SBSERVERDescription:Service Ticket Request: User Name: User Domain: Service Name: Service ID: - Ticket Options: 0x40800000 Ticket Encryption Type: - Client Address: 192.168.1.75 Failure Code: 0x25 Logon GUID: - Transited Services: - For more information, see Help and Support Center at http://go.microsoft.com/fwlink/events.asp. ------------------------------ Event Type: Failure AuditEvent Source: SecurityEvent Category: Logon/Logoff Event ID: 537Date: 7/9/2009Time: 12:53:33 AMUser: NT AUTHORITY\SYSTEMComputer: SBSERVERDescription:Logon Failure: Reason: An error occurred during logon User Name: Domain: Logon Type: 3 Logon Process: Kerberos Authentication Package: Kerberos Workstation Name: - Status code: 0xC000006D Substatus code: 0xC0000133 Caller User Name: - Caller Domain: - Caller Logon ID: - Caller Process ID: - Transited Services: - Source Network Address: 192.168.1.75 Source Port: 4909 For more information, see Help and Support Center at http://go.microsoft.com/fwlink/events.asp. ------------------------------ Event Type: Failure AuditEvent Source: SecurityEvent Category: Logon/Logoff Event ID: 537Da
replace 2 aging physical hardware with server 2003 - with esxi 5.5 hosting 2 VMs, opportunity to upgrade the server OS to 2012, separate site (IP) so can utilise some improvements in GP etc. Replacement of Site Servers Replacement of servers at security:529 Practices. Redesign of Classroom Rewired a classroom and added Six new Client computers and reconfigured 24 an error occurred during logon 0xc00005e others software for a larger class of Medical Assistant students. IN THIS DISCUSSION Join the Community! Creating your account only takes a few minutes. Join
Event Viewer Failed Logon
Now Hi Everyone, Having a bit of problem here on a Server 2003 box that is a member server hosting WSUS and Sharepoint. I keep getting 2 Logon Failures in the security log every minute or so. One minute it says: Logon https://social.technet.microsoft.com/Forums/windowsserver/en-US/2df4c103-f01a-40c2-978d-39bea6b53a31/event-id-537-logged-repeatedly-by-one-workstation?forum=winservergen Failure: Reason: Unknown user name or bad password User Name: Domain: Logon Type: 3 Logon Process: Kerberos Authentication Package: Kerberos Workstation Name: - Caller User Name: - Caller Domain: - Caller Logon ID: - Caller Process ID: - Transited Services: - Source Network Address: - Source Port: - Next minute it says: Logon Failure: Reason: An error occurred during logon User Name: Domain: Logon Type: 3 https://community.spiceworks.com/topic/211923-event-id-537-logon-failure-every-minute Logon Process: Schannel Authentication Package: Schannel Workstation Name: - Status code: 0xC000006D Substatus code: 0x80090325 Caller User Name: - Caller Domain: - Caller Logon ID: - Caller Process ID: - Transited Services: - Source Network Address: 10.62.171.110 Source Port: 1284 I recently changed the lan manger authentication settings in the domain to level 5 Send NTLMv2 only I dont know if this log event was there prior to this change Any ideas? Reply Subscribe View Best Answer RELATED TOPICS: Spiceworks Logon Failure logon failure as A.D. Administrator Logon Failure : Uknown User name or bad password   10 Replies Mace OP molan Mar 29, 2012 at 3:38 UTC Source Network Address: 10.62.171.110 this is the device that is failing to login. I would start with that 0 Mace OP molan Mar 29, 2012 at 3:39 UTC I recently changed the lan manger authentication settings in the domain to level 5 Send NTLMv2 only or try rolling the setting you changed back and see if the error clears up 0 Anaheim OP Jubei Mar 29, 2012 at 3:45 UTC the .110 is the server. I have tried rolling back lan man setting with no luck. I found something in regards to the trust password of the machine account being broken and to try resetting the machine account or rejoin the domain. 0 Habanero OP pchiodo Mar
90% of the time the user name in description field is blank. This event comes in 2 forms, the workstation version and the an error DC version. First I’m going to show the workstation version followed by the DC version. As seen in the security log from Wrkstation1: Event Type: Failure Audit Event Source: Security Event ID: event id 537 537 User: NT AUTHORITY\SYSTEM Computer: Wrkstation1 Description: Logon Failure: Reason: An error occurred during logon User Name: Domain: Logon Type: 3 Logon Process: Kerberos Authentication Package: Kerberos Workstation Name: - Status code: 0xC000006D Substatus code: 0xC0000133 As seen in the security log on DC1: Event Type: Failure Audit Event Source: Security Event ID: 537 User: NT AUTHORITY\SYSTEM Computer: DC1 Description: Logon Failure: Reason: An error occurred during logon User Name: Domain: Logon Type: 3 Logon Process: Kerberos
tech Search Tags: Builds Cases Cooling CPUs Graphics Laptops Memory Monitors Motherboards more Peripherals PSUs Storage VR ForumWindows 2000/NT Logon/Logoff Failure Audit - Event 537 in Windows Server 2.. AnonymousJul 4, 2005, 5:26 AM Archived from groups: microsoft.public.win2000.security (More info?)I have a W2k3 RTM member server (2003 domain) running IIS, Microsoft Operations Manager 2005 and CA Unicenter Automation Point v4 SP3 + HP Proliant Essentials (compaq support paq) 7.3. I am seeing event 537 logon failure audits twice per minute in the Secuirty Log. All the events look the same:Logon Failure: Reason: An error occurred during logon User Name: Domain: Logon Type: 3 Logon Process: Kerberos Authentication Package: Kerberos Workstation Name: - Status code: 0xC000009A Substatus code: 0x0 Caller User Name: - Caller Domain: - Caller Logon ID: - Caller Process ID: - Transited Services: - Source Network Address: - Source Port: -There's not a lot to go on. I tried MSKB and EventID and there were no obvious references. Article 318922 talks about domain controllers and NT4, and 327889 talks about using local accounts in WinXP but implies that a user name should be logged as part of the event. I am not sure if 0xC000009A is related to the error "STATUS_INSUFFICIENT_RESOURCES" or not but a quick perfmon shows 19.8 Mb of Pool Nonpaged Bytes which seems OK compared to my other servers.Any ideas? Thanks- Adam 4 answers Last reply Jul 30, 2008 More about logon logoff failure audit event windows server AnonymousJul 4, 2005, 10:37 PM Archived from groups: microsoft.public.win2000.security (More info?)"" wrote: > I have a W2k3 RTM member server (2003 domain) running IIS, > Microsoft > Operations Manager 2005 and CA Unicenter Automation Point v4 > SP3 + HP > Proliant Essentials (compaq support paq) 7.3. > > I am seeing event 537 logon failure audits twice per minute in > the Secuirty > Log. All the events look the same: > > Logon Failure: > Reason: An error occurred during logon > User Name: > Domain: > Logon Type: 3 > Logon Process: Kerberos > Authentication Package: Kerberos > Workstation Name: - > Status code: 0xC000009A > Substatus code: 0x0 > Caller User Name: - > Caller Domain: - > Caller Logon ID: - > Caller Process ID: - > Transited Services: - > Source Network Address: - > Source Port: - > > There's not a lot to go on. I tried MSKB and Eve