The problem:
A Microsoft Windows Server 2003-based member computer is joined to a domain
controller. In the member server, the audit policy is turned on for logon
failures. When a local user on the member computer logs off, the following
event is logged in the Security log.
Event Type: Failure Audit
Event Source: Security
Event Category: Logon/Logoff
Event ID: 529
Date: date
Time: time
User: NT AUTHORITY\SYSTEM
Computer: domain controller computer name
Description:
Logon Failure:
Reason: Unknown user name or bad password
User Name: user name
Domain: client computer name
Logon Type: 3
Logon Process: NtLmSsp
Authentication Package: NTLM
Workstation Name: client computer name
For more information, see Help and Support Center at
http://support.microsoft.com.
I have found this error in KB article 811082 which has a Hotfix to resolve
it. I tried to install it and receive a message that says the service pack
level installed is newer then the Hot Fix. I am still receiving the error and
it is becoming a large problem since I have hundreds of these failed audits a
day. I can not turn off auditing on the server since it is a requirement.