Build a great reporting interface using Splunk, one of the leaders in the Security Information and Event Management (SIEM) field, linking the collected Windows events to www.eventid.net. The EventId.Net for Splunk Add-on assumes that Splunk is collecting information from Windows servers and workstation via the Splunk Universal Forwarder.
|Type: Failure Audit|
Reason: The specified account's password has expired
User Name: %1
Logon Type: %3
Logon Process: %4
Authentication Package: %5
Workstation Name: %6
|English: Request a translation of the event description in plain English.|
|Concepts to understand:|
What is an authentication protocol?
See MSW2KDB for information about this event.
Event generated by as logon failure due to an account with expired password.
|Private comment: Subscribers only. See example of private comment|
|Links: ME174074, Online Analysis of Security Event Log, MSW2KDB|
|Search: Google - Bing - Microsoft - Yahoo - EventID.Net Queue (0) - More links...|
Send comments or solutions
- Notify me when updated