Monitor unlimited number of servers
Filter log events
Create email and web-based reports

Direct access to Microsoft articles
Customized keywords for major search engines
Access to premium content

Event ID: 514 Source: Security

An authentication package has been loaded by the Local Security Authority.
This authentication package will be used to authenticate logon attempts.

Authentication Package Name: <authentication package name>
As per Microsoft: "This event record indicates that the Local Security Authority (LSA) has loaded an authentication package used for authenticating logon requests.Authentication packages are responsible for validating user identification and authentication information collected by logon processes during log on. A single system can simultaneously support multiple authentication packages". See MSW2KDB for additional information about this event.
Windows can use different authentication packages, depending on how it was configured. Loading multiple authentication packages permits the LSA (Local Security Authority) to support multiple logon processes and multiple security protocols.

Depending on what type of resource is accessed and from where, these packages are loaded accordingly. 514 just records this process. Of course, one may build custom auth. packages and they will be recorded accordingly.

See the link to Windows Authentication Packages for information about the <authentication package> field.

Windows Event Log Analysis Splunk App

Build a great reporting interface using Splunk, one of the leaders in the Security Information and Event Management (SIEM) field, linking the collected Windows events to



Cisco ASA Log Analyzer Splunk App

Obtain enhanced visibility into Cisco ASA firewall logs using the free Firegen for Cisco ASA Splunk App. Take advantage of dashboards built to optimize the threat analysis process.