Monitor unlimited number of servers
Filter log events
Create email and web-based reports

Direct access to Microsoft articles
Customized keywords for major search engines
Access to premium content

Event ID: 531 Source: Security

Source
Description
Logon Failure:
Reason: Account currently disabled
User Name: <user name>
Domain: <domain name>
Logon Type: 3
Logon Process: KSecDD
Authentication Package: MICROSOFT_AUTHENTICATION_PACKAGE_V1_0
Workstation Name: <workstation name>
Comments
 
This issue usually occurs because the administrator did not use the default administrator account during the Trend VCS agent installation. See the link to "Trend Micro Support Solution ID: 13335" for a solution to this problem.

See ME321448 for additional information about this event.
The logon attempt failed because the user account used to log on is currently disabled. See MSW2KDB and ME889505 for information on this problem.
Event genereated by a logon failure due to a disabled account (A logon attempt was made using a disabled account.)

Windows Event Log Analysis Splunk App

Build a great reporting interface using Splunk, one of the leaders in the Security Information and Event Management (SIEM) field, linking the collected Windows events to www.eventid.net.

Read more...

 

Cisco ASA Log Analyzer Splunk App

Obtain enhanced visibility into Cisco ASA firewall logs using the free Firegen for Cisco ASA Splunk App. Take advantage of dashboards built to optimize the threat analysis process.

Read more...