Security Event Log: Event ID 681
The information in this article applies to:
- GFI EventsManager 7
- GFI EventsManager 8
- GFI LANguard Security Event Log Monitor 3
- GFI LANguard Security Event Log Monitor 4
- GFI LANguard Security Event Log Monitor 5
Article ID: KBID001740
Query keywords: account, event, log
Description:
- The logon to account: %2 by: %1 from workstation: %3 failed. The error code was: %4
Importance:
- Medium/High
- Someone tried to logon to a machine remotely and failed. Known error codes and their meanings can be found here.
Detailed Description:
When auditing logon events on a Windows 2000-based domain controller (DC) and a failed logon attempt is made from a down-level client or through a trust with a down-level domain, a "Failure Audit" event with this ID may be logged.
This event is logged when an attempt to log on to a Microsoft Windows 2000-based domain network fails. In that case you should re-start the machine.
This event is generally caused by IIS Kerberos-related operations.
Note that the error codes in the Event Log message are in decimal form, but they are actually hexadecimal values. You can translate the values from decimal to hexadecimal by using the Calculator tool in Windows 2000 or see the following table here.
Possible causes for this event are:
(1) Failed Logon attempts to Windows 2000 domain or Domain Controller.
(2) This event may be caused by IIS Kerberos-related issues.
More Information:
Legend: Logon Failure Error Codes
Related Links:
Microsoft Support Article: Problems Logging On to a Windows 2000-Based Server
Microsoft Support Article: HOW TO: Troubleshoot Kerberos-Related Issues in IIS