Event Details
User Activity->Logons->Successful Logons->Windows 2000-2003->EventID 674 - Service Ticket Renewed [Win 2003]
EventID 674 - Service Ticket Renewed [Win 2003]
 Sample:
        Event Type:     Success Audit
        Event Source:   Security
        Event Category: Account Logon
        Event ID:       674
        Date:           11/13/2009
        Time:           11:32:59
        User:           NT AUTHORITY\SYSTEM
        Computer:       DC1
        Description:
        Service Ticket Renewed:
        User Name:		Paul@RESEARCH.CORP
        User Domain:	RESEARCH.CORP
        Service Name:		krbtgt
        Service ID:		{S-1-5-21-746137067-343818398-839522115-502}
        Ticket Options:		0x40810010
        Ticket Encryption Type:	0x17
        Client Address:		127.0.0.1
      
Log Type: Windows Event Log
 Uniquely Identified By:
Log Name: Security
Filtering Field Equals to Value
OSVersion Windows 2003
Category Account Logon
Source Security
EventId 674
Field Matching
FieldDescriptionStored inSample Value
When At what date and time a user activity originated in the system. DateTime 1/1/2000
Who Account or user name under which the activity occured. User Name Paul@RESEARCH.CORP
What The type of activity occurred (e.g. Logon, Password Changed, etc.) "Kerberos Authentication" Kerberos Authentication
Where The name of the workstation/server where the activity was logged. Computer
Where From The name of the workstation/server where the activity was initiated from. Client Address 127.0.0.1
Severity Specify the seriousness of the event. "High" High
WhoDomain User Domain RESEARCH.CORP
WhereDomain -
Result Successful or Failed. "Successful" Successful
Failure Reason "Successful" Successful
Comments
You must be logged in to comment