Hi
We are using AD 2003 on Windows 2003 servers.
There is an account - domain\account1 - that keeps locking out. I suspect that either someone is trying to continously authenticate using a wrong password or, more likely, there is an application that is set to use this account which has an old password.
I've run EventComb with the following parameters:
Security, Failure Audit, All DC's in domain, Event ID 528
Text: domain\account1
But I'm getting no results.
Can anyone tell me what I'm doing wrong?