Build a great reporting interface using Splunk, one of the leaders in the Security Information and Event Management (SIEM) field, linking the collected Windows events to www.eventid.net. The EventId.Net for Splunk Add-on assumes that Splunk is collecting information from Windows servers and workstation via the Splunk Universal Forwarder.
Authentication attempt from <IP address> to <user>@<domain>.com has failed with error <error code>.
|English: Request a translation of the event description in plain English.|
|Concepts to understand:|
What is IMAP?
What is the role of a POP3/IMAP virtual server?
- Error code: 0x274c - In my case, the IMAP service was disabled on back end server.
- Error code: 0x52e - In my case, this problem was caused by a stopped IMAP service on a Back-End server in a BE/FE scenario (SSL forced on FE).
- Error code: 0x533 - In my case, the IMAP4 protocol was disabled for this user in the Exchange Features tab of the user's Properties window in Active Directory Users and Computers.
- Error code: 0x274d - We received this event, with Error code 0x274d when trying to test IMAP with test accounts. We are using a FE/BE configuration and it turned out that the Microsoft Exchange IMAP service was not started on the BE server.
This problem is similar to the POP3 logon issue. I modified the Exchange alias to match the pre-windows 2000 logon attribute and then I was able to logon successfully.
|Private comment: Subscribers only. See example of private comment|
|Links: EventID 1011 from source POP3SVC|
|Search: Google - Bing - Microsoft - Yahoo - EventID.Net Queue (0) - More links...|
Send comments or solutions
- Notify me when updated