I have a small R&D domain setup. With about 250 systems and 40 user. There is only one DC so it should make finding what computer locked a user out easy.
Normally i would just look for EventID 4740 entries. I even have a scheduled task that will trigger and email alert me.
But my problem is that I see lots of entries in my security log. But i don't see a single 4740 User locked out error. Even when i create a test user account and then enter it's password incorrectly 5 times.
what am i missing? Server 2008 64bit.