I'm having trouble finding information of where/when an account that was locked out today from my domain controller's Event viewer. I noticed it was locked out, went into the event viewer of the domain controller, in the Windows Logs/security logfile but
could not find any events that showed who/when the the account was unsuccessfully logged into to lock out the account. I checked the audit policy on my domain controller auditpol /get /category:* and I have Logon/Logoff = success and failure, and Account
lockout = success turned on. What am I doing wrong? I have three DC's in my domain.. Is it possible that the login attempts were handled by one of the other DC's and that's why I'm not finding anything on my DC?
William McConnell
William McConnell