Hi, We have the following Advanced Audit policies configured for our domain, but still we dont see the event logs with machine & user logon details. your help is very much appreciated.
Log Name: SecuritySource: Microsoft-Windows-Security-Auditing
Date: 9/30/2016 10:48:37 PM
Event ID: 4624
Task Category: Logon
Level: Information
Keywords: Audit Success
User: N/A
Computer: DC
Description:
An account was successfully logged on.
Subject:
Security ID: NULL SID
Account Name: -
Account Domain:-
Logon ID: 0x0
Logon Type:3
Impersonation Level:Delegation
New Logon:
Security ID: S-1-5-21-3803837968-1534464277-3267097699-47311
Account Name: L-3PLHH92$
Account Domain:CORP
Logon ID: 0x15B72B10B
Logon GUID: {07261433-bae2-c8ef-34e8-4aa451c95ab9}
Process Information:
Process ID: 0x0
Process Name: -
Network Information:
Workstation Name:
Source Network Address:10.20.111.50
Source Port: 55026
Detailed Authentication Information:
Logon Process:Kerberos
Authentication Package:Kerberos
Transited Services:-
Package Name (NTLM only):-
Key Length: 0