Event Id | 4625 |
Source | Microsoft-Windows-Security-Auditing |
Description | An account failed to log on. Subject: Security ID:<Security ID> Account Name:<Account Name> Account Domain:<Domain Name> Logon ID:<Logon ID> Logon Type:<Logon Type> Account For Which Logon Failed: Security ID:<Security ID> Account Name:<Account Name> Account Domain:<Domain Name> Failure Information: Failure Reason:<Failure Reason> Status:<Status> Sub Status:<Sub Status> Process Information: Caller Process ID:<Caller Process ID> Caller Process Name:<Caller Process Name> Network Information: Workstation Name:<Workstation Name> Source Network Address:<Source Network Address> Source Port:<Source Port> Detailed Authentication Information: Logon Process:<Logon Process> Authentication Package:<Authentication Package> Transited Services:<Transited Services> Package Name (NTLM only):<Package Name> Key Length:<Key Length> |
Event Information | Cause : This event is logged on when user failed attempt to logon to the local computer. It is generated on the computer where access was attempted. Resolution : These are the following reasons. 1. User name does not exist. 2.User name is correct but the password is wrong. 3.User is currently locked out. 4.Account is currently disabled. |
Reference Links |
Catch threats immediately
We work side-by-side with you to rapidly detect cyberthreats
and thwart attacks before they cause damage.