Event Details
User Activity->Logons->Successful Logons->Windows 2000-2003->EventID 680 - Account Used for Logon by: %1 [Win 2000]
EventID 680 - Account Used for Logon by: %1 [Win 2000]
 Sample:
        Event Type:     Success Audit
        Event Source:   Security
        Event Category: Account Logon
        Event ID:       680
        Date:           12/14/2009
        Time:           05:31:26
        User:           NT AUTHORITY\SYSTEM
        Computer:         SERVER01
        Description:       Account Used for Logon by: MICROSOFT_AUTHENTICATION_PACKAGE_V1_0
        Account Name:  administrator
        Workstation:      SERVER01
      
Log Type: Windows Event Log
 Uniquely Identified By:
Log Name: Security
Filtering Field Equals to Value
OSVersion Windows 2000
Category Account Logon
Source Security
EventId 680
Field Matching
FieldDescriptionStored inSample Value
When At what date and time a user activity originated in the system. DateTime 1/1/2000
Who Account or user name under which the activity occured. Account Name
What The type of activity occurred (e.g. Logon, Password Changed, etc.) "NTLM Authentication" NTLM Authentication
Where The name of the workstation/server where the activity was logged. Computer DC1
Where From The name of the workstation/server where the activity was initiated from. Workstation Name
Severity Specify the seriousness of the event. "Low" Low
WhoDomain -
WhereDomain -
Result Successful or Failed. "Successful" Successful
Failure Reason "Successful" Successful
Comments
You must be logged in to comment