Create a Post
cancel
Showing results for 
Search instead for 
Did you mean: 
Moudar
Advisor

IDC logs always "failed log in" or always "log in"

Hi

on a lab environment the logs are always and only "Log in" so no "log out" or "failed log in" logs:

collector7.JPG

Wireshark between the AD and the machine where IDC is installed shows this when trying wrong password, log in and log out:

a1.JPG

a2.JPG

a3.JPG

 

In production environment the logs are "failed log in" or "log out" and no "log in" logs:

a5.JPG

running wireshark between AD and the machine where IDC is installed shows no LDAP or kerberos packets between these machines, it shows only DCERPC packets!

the machine where IDC is installed is 10.32.0.166, same machine i run wireshark:

ip.addr == 10.8.0.12 and ldap shows nothing

ip.addr == 10.8.0.12 and kerberos shows nothing

only ip.addr == 10.8.0.12 and dcerpc shows this:

a6.JPG

 

The question is why on lab environment I get only "log in" logs and why on production I get only "failed log in" or "log out"  By the way the "failed log in" logs are not accurate because my environment is running with no problem.

0 Kudos
0 Replies

Leaderboard

Epsum factorial non deposit quid pro quo hic escorol.

Upcoming Events

    CheckMates Events