I am receiving huge number of 4625 events in Win 2012 server. Below is the event details. Account name and the workstation name are the same and is the hostname of the machine in which I am receiving "An account failed to log on" events. Could someone please help me fix this.
Log Name: Security
Source: Microsoft-Windows-Security-Auditing
Date: 05/01/2017 6:47:08 AM
Event ID: 4625
Task Category: Logon
Level: Information
Keywords: Audit Failure
User: N/A
Computer: http://(ServerHostname).example.com
Description:
An account failed to log on.
Subject:
Security ID: NULL SID
Account Name: -
Account Domain: -
Logon ID: 0x0
Logon Type: 3
Account For Which Logon Failed: Security ID: NULL SID
Account Name: ServerHostname
Account Domain: example
Failure Information:
Failure Reason: Unknown user name or bad password.
Status: 0xC000006D
Sub Status: 0xC0000064
Process Information:
Caller Process ID: 0x0
Caller Process Name: -
Network Information:
Workstation Name: ServerHostname
Source Network Address: ::1
Source Port: 50364
Detailed Authentication Information:
Logon Process: NtLmSsp
Authentication Package: NTLM
Transited Services: -
Package Name (NTLM only): -
Key Length: 0
User contributions licensed under CC BY-SA 3.0