| TABLE 1: Logon Event Detail Field Descriptions |
| Event Detail Field Name |
Description |
| Date |
The date on which the event occurred. |
| Time |
The time at which the event occurred. |
| User |
The user account performing the logon. |
| Computer |
The account name of the computer on which the event occurred. |
| Event ID |
The identifier for the event. For an overview of NT 4.0 event IDs, see the Microsoft article "Security Event Descriptions" (http://support.microsoft.com/directory/article.asp?id=kb;en-us;q174074). |
| Source |
The source of the event. |
| Type |
The type of event: success (Success Audit) or failure (Failure Audit). |
| Category |
The category of the event. |
| Description |
A short description of the event. This field holds the following user authenticationrelated information:
- Reason An explanation of why the authentication failed (applies only to authentication failures).
- User Name The name of the user account that tried to log on.
- Domain The NT domain of the user account that tried to log on.
- Logon ID The unique identifier for a logon session.
- Logon Type A numeric value that indicates the NT logon type.
- Logon Process The name of the process that performed the logon.
- Authentication Package The name of the authentication package used for the logon.
- Workstation Name The account name of the workstation that the user account used for logon.
|