Event Details
User Activity->Logons->Failed Logons->Windows 2008->EventID 4675 - SIDs were filtered.
EventID 4675 - SIDs were filtered.
 Sample:
        SIDs were filtered.

        Target Account:
        Security ID:		%1
        Account Name:		%2
        Account Domain:		%3

        Trust Information:
        Trust Direction:	%4
        Trust Attributes:	%5
        Trust Type:	%6
        TDO Domain SID:	%7

        Filtered SIDs:	%8
      
Log Type: Windows Event Log
 Uniquely Identified By:
Log Name: Security
Filtering Field Equals to Value
OSVersion Windows Vista (2008)
Windows 7 (2008 R2)
Windows 8 (2012)
Windows 8.1 (2012 R2)
Windows 10 (2016)
Category Logon/Logoff
Source Microsoft-Windows-Security-Auditing
TaskCategory Logon
EventId 4675
Field Matching
FieldDescriptionStored inSample Value
When At what date and time a user activity originated in the system. - 1/1/2000
Who Account or user name under which the activity occured. Target Account: Security ID
What The type of activity occurred (e.g. Logon, Password Changed, etc.) "SIDs were filtered" SIDs were filtered
Where The name of the workstation/server where the activity was logged. - 10.10.10.10
Where From The name of the workstation/server where the activity was initiated from. - 10.10.10.10
Severity Specify the seriousness of the event. - High
WhoDomain -
WhereDomain -
Result Successful or Failed. "Failed" Failed
Failure Reason Failure Reason - Bad user name or password, not enough privileges, etc. - Bad user name or password
Comments
You must be logged in to comment