Event Id | 4769 |
Source | Microsoft-Windows-Security-Auditing |
Description | A Kerberos service ticket was requested. Account Information: Account Name:<Account Name> Account Domain:<Domain Name> Logon GUID:<Logon GUID> Service Information: Service Name:<Service Name> Service ID: <Service ID> Network Information: Client Address:<Client Address> Client Port: <Client Port> Additional Information: Ticket Options:<Ticket Options> Ticket Encryption Type:<Ticket Encryption Type> Failure Code:<Failure Code> Transited Services:<Transited Services> |
Event Information | Cause : This event is generated every time access is requested to a resource such as a computer or a Windows service. The service name indicates the resource to which access was requested. This event can be correlated with Windows logon events by comparing the Logon GUID fields in each event. The logon event occurs on the machine that was accessed, which is often a different machine than the domain controller which issued the service ticket. Resolution : No user action is required. |
Reference Links |
Catch threats immediately
We work side-by-side with you to rapidly detect cyberthreats
and thwart attacks before they cause damage.