Event ID - 14072

Event Id14072
SourcePOP Intrusion Detection Filter
DescriptionThe alert feature of the ISA Server Control service failed to logon as user 2 to run the command 3 specified for the alert '1'. For more information about this event, see ISA Server Help.
Event InformationAccording To Microsoft:
The ISA Server Control service generates this alert when an alert command action fails to use the provided credentials. The parameters of the alerts hold the name of the alert that failed, the user name that failed logon, and the command line that was supposed to run as this user. This alert may be generated for one of the following reasons: Incorrect credentials were used. This can be caused by a misspelled user name, password, or domain name. It is also possible that the Windows password has changed and the password that is stored in ISA Server is now incorrect or that the domain name changed. The user does not have the necessary permissions on the ISA Server computer.

Resolution:
Verify that all the credentials for this alert are set correctly. You may need to change the specified user credentials. Or, use the default ???Local Service??? account credentials, by providing no user credentials for the action. For more information about ISA Server alerts see ???Alerts??? topic in ISA Server Help.
Reference LinksMicrosoft product: Internet Security and Acceleration Server Version: 4.0.3443.594 Event Source: POP Intrusion Detection Filter Event ID: 14072

Catch threats immediately

We work side-by-side with you to rapidly detect cyberthreats
and thwart attacks before they cause damage.

See what we caught

Did this information help you to resolve the problem?

Yes: My problem was resolved.
No: The information was not helpful / Partially helpful.