Build a great reporting interface using Splunk, one of the leaders in the Security Information and Event Management (SIEM) field, linking the collected Windows events to www.eventid.net. The EventId.Net for Splunk Add-on assumes that Splunk is collecting information from Windows servers and workstation via the Splunk Universal Forwarder.
The user <user> has connected and failed to authenticate on port <port>. The line has been disconnected.
|English: Request a translation of the event description in plain English.|
This event can also be caused if the Routing and Remote Access service cannot create the log file for some reason. One reason may be that the folder that has been set for the log files does not actually exist yet.
As per Microsoft: "The connection attempt failed because the system could not authenticate the user. Possible causes include:
- The user provided incorrect credentials.
- The connection request did not match any connection request policy". See MSW2KDB for more details.
If you encounter this problem on Windows NT 4.0, the latest Service Pack should fix it. See ME159352 for details on this issue.
|Private comment: Subscribers only. See example of private comment|
|Links: ME159352, MSW2KDB|
|Search: Google - Bing - Microsoft - Yahoo - EventID.Net Queue (0) - More links...|
Send comments or solutions
- Notify me when updated