Hi, I recently signed up a Windows 2008 R2 SP1 server. I have then come to notice at the event logs, "Audit success" successful logon attempts from the Microsoft Windows Security Auditing,, specifically 4624(4), 4634(1), 4648(1), 4672(4) and
4776(3) within the last hour. However I have only logged on once to the said server!!! I am now wondering if they are or have been attempts to infiltrate my server and what these entries mean and how I can ensure that my server is safe from any would be attacks.
Kindly assist as I am not very familiar with server security. Thanks.
↧