My security logs (2 servers) are full of success audits for event id 836 and
837. I have not been able to find any useful information as what these
events actually are or why they are occuring so often. Can someone shed some
light on this for me?
Event Type: Success Audit
Event Source: Security
Event Category: Directory Service Access
Event ID: 836
Date: 3/16/2006
Time: 11:37:36 AM
User: NT AUTHORITY\SYSTEM
Computer: <servername1>
Description:
Destination DRA: CN=NTDS
Settings,CN=<servername1>,CN=Servers,CN=Default-First-Site-Name,CN=Sites,CN=Configuration,DC=<domainname>,DC= local
Source DRA: CN=NTDS
Settings,CN=<servername2>,CN=Servers,CN=Default-First-Site-Name,CN=Sites,CN=Configuration,DC=<domainname>,DC= local
Naming Context: DC=<domainname>,DC=local
Options: 19
Session ID: 36103
Start USN: 1741917
event 837 contains similar information