Event 4624, wrong WorkstationName

2020-12-25T10:34:43.63+00:00

Hello!

Windows Server 2016\2019, Active Directory

I see in some 4624 events wrong WorkstationName (my DC's name). For example:

  • Real host is server1.main.contoso.com, IP 192.168.1.50
  • Real DC is DC-01.main.contoso.com, IP 192.168.1.10

In event 4624 when I login in server1 i see

{ "text": "DC-01", "Name": "WorkstationName" },
..................................
{ "text": "C:\Windows\System32\lsass.exe", "Name": "ProcessName" },
{ "text": "192.168.1.50", "Name": "IpAddress" },

In most events 4624 field WorkstationName is correct. Why this field is wrong in some events?

Active Directory
Active Directory
A set of directory-based technologies included in Windows Server.
6,456 questions
{count} votes

3 answers

Sort by: Most helpful
  1. Anonymous
    2020-12-25T13:48:33.183+00:00

    I'd check that domain health is 100% also check the domain controller event logs for related errors.

    --please don't forget to Accept as answer if the reply is helpful--

    0 comments No comments

  2. Thameur-BOURBITA 32,831 Reputation points
    2020-12-26T11:42:08.443+00:00

    Hi,

    In most events 4624 field WorkstationName is correct. Why this field is wrong in some events?

    I invite you to read this this article talking about the definition of each information provided on this event 4624 , it can explain this behavior : event-4624

    Workstation Name is the machine name to which logon attempt was performed. (it's the domain controller DC-01 in your case )

    Source Network Address is the IP address of machine from which logon attempt was performed. ( The server in your case)

    Please Don't forget to mark this reply asn answer if it help you to fix your issue


  3. Hannah Xiong 6,276 Reputation points
    2020-12-28T06:36:04.82+00:00

    Hello,

    Thank you so much for posting here.

    Did we check the event 4624 on Domain Controllers?

    Event ID 4624 (viewed in Windows Event Viewer) documents every successful attempt at logging on to a local computer. This event is generated on the computer that was accessed, in other words, where the logon session was created.

    This Network Information section identifies WHERE the user was when he logged on. Of course if logon is initiated from the same computer this information will either be blank or reflect the same local computers.

    Workstation Name: the computer name of the computer where the user is physically present in most cases unless this logon was intitiated by a server application acting on behalf of the user. Workstation may also not be filled in for some Kerberos logons since the Kerberos protocol doesn't really care about the computer account in the case of user logons and therefore lacks any field for carrying workstation name in the ticket request message.

    Source Network Address: the IP address of the computer where the user is physically present in most cases unless this logon was intitiated by a server application acting on behalf of the user. If this logon is initiated locally the IP address will sometimes be 127.0.0.1 instead of the local computer's actual IP address. This field is also blank sometimes because Microsoft says "Not every code path in Windows Server 2003 is instrumented for IP address, so it's not always filled out."

    Reference: https://www.ultimatewindowssecurity.com/securitylog/encyclopedia/event.aspx?eventID=4624

    Please note: Information posted in the given link is hosted by a third party. Microsoft does not guarantee the accuracy and effectiveness of information.

    Best regards,
    Hannah Xiong

    ============================================

    If the Answer is helpful, please click "Accept Answer" and upvote it.
    Note: Please follow the steps in our documentation to enable e-mail notifications if you want to receive the related email notification for this thread.

    0 comments No comments

Your answer

Answers can be marked as Accepted Answers by the question author, which helps users to know the answer solved the author's problem.