Skip to main content
Skip table of contents

V 2.0 : EVID 4768, 4771 : Kerberos TGT Failure Message

Vendor Documentation

Classification

Rule Name

Rule Type

Common Event

Classification

V 2.0 : EVID 4768, 4771 : Kerberos TGT Failure MessageBase RuleGeneral Authentication EventOther Audit
V 2.0 : EVID 4768 : Computer Logon SuccessSub RuleComputer LogonAuthentication Success
V 2.0 : EVID 4768 : User Logon SuccessSub RuleUser LogonAuthentication Success
V 2.0 : EVID 4768 : Computer Logon Failure - Bad UsernameSub RuleComputer Logon FailureAuthentication Failure
V 2.0 : EVID 4768 : Computer Logon Failure - ClockSub RuleComputer Logon FailureAuthentication Failure
V 2.0 : EVID 4768 : Computer Logon Failure - UnsupportedSub RuleComputer Logon FailureAuthentication Failure
V 2.0 : EVID 4768 : Computer Logon Failure - InvalidSub RuleComputer Logon FailureAuthentication Failure
V 2.0 : EVID 4768 : Computer Logon Failure - CredentialSub RuleComputer Logon FailureAuthentication Failure
V 2.0 : EVID 4768 : Computer Logon Failure - PasswordSub RuleComputer Logon FailureAuthentication Failure
V 2.0 : EVID 4768 : Computer Logon Failure - Bad PasswordSub RuleComputer Logon FailureAuthentication Failure
V 2.0 : EVID 4768 : Computer Logon Failure - ExpiredSub RuleComputer Logon FailureAuthentication Failure
V 2.0 : EVID 4768 : Computer Logon Failure - TicketSub RuleComputer Logon FailureAuthentication Failure
V 2.0 : EVID 4768 : Computer Logon Failure - DuplicateSub RuleComputer Logon FailureAuthentication Failure
V 2.0 : EVID 4768 : Computer Logon Failure - ClockSub RuleComputer Logon FailureAuthentication Failure
V 2.0 : EVID 4768 : User Logon Failure - Bad UserSub RuleUser Logon Failure : Bad UsernameAuthentication Failure
V 2.0 : EVID 4768 : User Logon Failure - Clock OutSub RuleUser Logon FailureAuthentication Failure
V 2.0 : EVID 4768 : User Logon Failure - UnsupportedSub RuleUser Logon FailureAuthentication Failure
V 2.0 : EVID 4768 : User Logon Failure- Invalid CeSub RuleUser Logon FailureAuthentication Failure
V 2.0 : EVID 4768 : User Logon Failure - CredentialSub RuleUser Logon Failure : Account DisabledAuthentication Failure
V 2.0 : EVID 4768 : User Logon Failure - Password ExpiredSub RuleUser Logon Failure : Bad PasswordAuthentication Failure
V 2.0 : EVID 4768 : User Logon Failure - Bad PasswordSub RuleUser Logon Failure : Bad PasswordAuthentication Failure
V 2.0 : EVID 4768 : User Logon Failure - Expired TicketSub RuleUser Logon FailureAuthentication Failure
V 2.0 : EVID 4768 : User Logon Failure - Ticket NotSub RuleUser Logon FailureAuthentication Failure
V 2.0 : EVID 4768 : User Logon Failure - DuplicatedSub RuleUser Logon FailureAuthentication Failure
V 2.0 : EVID 4768 : User Logon Failure - Clock OutSub RuleUser Logon FailureAuthentication Failure
V 2.0 : EVID 4771 : Computer Logon Failure - InvalidSub RuleComputer Logon FailureAuthentication Failure
V 2.0 : EVID 4771 : Computer Logon Failure- PasswordSub RuleComputer Logon FailureAuthentication Failure
V 2.0 : EVID 4771 : Computer Logon Failure - Bad PasswordSub RuleComputer Logon FailureAuthentication Failure
V 2.0 : EVID 4771 : User Logon Failure - Invalid CertSub RuleUser Logon FailureAuthentication Failure
V 2.0 : EVID 4771 : User Logon Failure - Password ExpiredSub RuleUser Logon Failure : Bad PasswordAuthentication Failure
V 2.0 : EVID 4771 : User Logon Failure Bad PasswordSub RuleUser Logon Failure : Bad PasswordAuthentication Failure
V 2.0 : EVID 4768 : Client Database Entry Has ExpiredSub RuleUser Logon FailureAuthentication Failure
V 2.0 : EVID 4768 : KDC Has No Support for TransitedSub RuleUser Logon FailureAuthentication Failure
V 2.0 : EVID 4768 : Client Not Yet ValidSub RuleUser Logon FailureAuthentication Failure
V 2.0 : EVID 4768 : KDC Has No Support for TransitedSub RuleUser Logon FailureAuthentication Failure
V 2.0 : EVID 4768 : Additional Pre-auth RequiredSub RuleUser Logon FailureAuthentication Failure
V 2.0 : EVID 4768 : Server Database Entry Has ExpiredSub RuleUser Logon FailureAuthentication Failure
V 2.0 : EVID 4768 : The Ticket Is Not From UserSub RuleUser Logon FailureAuthentication Failure
V 2.0 : EVID 4768 : Ticket & Authenticator Do NotSub RuleUser Logon FailureAuthentication Failure
V 2.0 : EVID 4768 : Incorrect Net AddressSub RuleUser Logon FailureAuthentication Failure
V 2.0 : EVID 4768 : Protocol Version MismatchSub RuleUser Logon FailureAuthentication Failure
V 2.0 : EVID 4768 : Specified Version of Key Is Not AvailableSub RuleUser Logon FailureAuthentication Failure
V 2.0 : EVID 4768 : Service Key Not AvailableSub RuleUser Logon FailureAuthentication Failure
V 2.0 : EVID 4768 : Mutual Authentication FailedSub RuleUser Logon FailureAuthentication Failure
V 2.0 : EVID 4768 : Alternative Auth MethodSub RuleUser Logon FailureAuthentication Failure
V 2.0 : EVID 4768 : Client Key Encrypted in Old MstSub RuleUser Logon FailureAuthentication Failure
V 2.0 : EVID 4768 : Server Key Encrypted in Old MsSub RuleUser Logon FailureAuthentication Failure
V 2.0 : EVID 4768 : Client Nt Found in Kerberos DBSub RuleUser Logon FailureAuthentication Failure
V 2.0 : EVID 4768 : Server Nt Found in Kerberos DBSub RuleUser Logon FailureAuthentication Failure
V 2.0 : EVID 4768 : Multiple Principal Enters in DBSub RuleUser Logon FailureAuthentication Failure
V 2.0 : EVID 4768 : Client Or Server Has Null KeySub RuleUser Logon FailureAuthentication Failure
V 2.0 : EVID 4768 : KDC Policy Rejects RequestSub RuleUser Logon FailureAuthentication Failure
V 2.0 : EVID 4768 : KDC Cannot Accommodate Req OptnSub RuleUser Logon FailureAuthentication Failure
V 2.0 : EVID 4768 : KDC Has No Support for ChecksumSub RuleUser Logon FailureAuthentication Failure
V 2.0 : EVID 4768 : Credentials for Server Have Been RevokedSub RuleAccess Revoked ActivityAccess Revoked
V 2.0 : EVID 4768 : TGT Has Been RevokedSub RuleAccess Revoked ActivityAccess Revoked
V 2.0 : EVID 4768 : Integrity Check on Decrypt FieldSub RuleIntegrity Check On Decrypted Field FailedWarning
V 2.0 : EVID 4768 : Invalid Message TypeSub RuleInvalid Message TypeError
V 2.0 : EVID 4768 : Message Stream ModifiedSub RuleMessage Stream ModifiedInformation
V 2.0 : EVID 4768 : Message Out of OrderSub RuleMessage Out Of OrderError
V 2.0 : EVID 4768 : Incorrect Message DirectionSub RuleIncorrect Message DirectionError
V 2.0 : EVID 4768 : Unsupported ProtocolSub RuleReconnaissance ActivityReconnaissance
V 2.0 : EVID 4768 : Incorrect Sequence Number in MessageSub RuleIncorrect Sequence NumberError
V 2.0 : EVID 4768 : Inapt Type of Checksum in MsgSub RuleInappropriate Type Of ChecksumError
V 2.0 : EVID 4768 : Generic ErrorSub RuleGeneric ErrorError
V 2.0 : EVID 4768 : Field Is Too Long for This ImpSub RuleField Is Too LongError
V 2.0 : EVID 4768 : Ticket Not Eligible for PostdaSub RuleModify Object Attribute FailureAccess Failure

Mapping with LogRhythm Schema  

Device Key in Log MessageLogRhythm SchemaData TypeSchema Description
Provider N/AN/AIdentifies the provider that logged the event. The Name and GUID attributes are included if the provider used an instrumentation manifest to define its events. The EventSourceName attribute is included if a legacy event provider (using the Event Logging API) logged the event.
EventID<vmid>NumberThe identifier that the provider used to identify the event.
VersionN/AN/AThe version number of the event's definition.
Level<severity>Text/StringThe severity level defined in the event.
Task<vendorinfo>Text/StringThe task defined in the event. Task and Opcode are typically used to identify the location in the application from where the event was logged.
OpcodeN/A N/AThe opcode defined in the event. Task and Opcode are typically used to identify the location in the application from where the event was logged.
Keywords

<result>

<tag3>

Text/StringA bitmask of the keywords defined in the event. Keywords are used to classify types of events (for example, events associated with reading data).
TimeCreatedN/A N/AThe time stamp that identifies when the event was logged. The time stamp will include either the SystemTime attribute or the RawTime attribute.
EventRecordIDN/A N/AThe record number assigned to the event when it was logged.
CorrelationN/A N/AThe activity identifiers that consumers can use to group related events together.
ExecutionN/A N/AContains information about the process and thread that logged the event.
ChannelN/A N/AThe channel to which the event was logged.
Computer<dname>Text/StringThe name of the computer on which the event occurred.
TargetUserName<login>Text/StringThe name of account, for which (TGT) ticket was requested. Computer account name ends with $ character.
TargetDomainName<domainorigin>Text/StringThe name of the Kerberos Realm that Account Name belongs to. This can appear in a variety of formats, including the following:
  • Domain NETBIOS name example: CONTOSO
  • Lowercase full domain name: contoso.local
  • Uppercase full domain name: CONTOSO.LOCAL
TargetSidN/A N/AThe SID of account for which (TGT) ticket was requested.
ServiceName<process>Text/StringThe name of the service in the Kerberos Realm to which TGT request was sent. Typically has value krbtgt for TGT requests, which means Ticket Granting Ticket issuing service.

For Failure events Service Name typically has the following format: krbtgt/REALM_NAME.
ServiceSidN/A N/AThe SID of the service account in the Kerberos Realm to which TGT request was sent.
TicketOptions<command>Text/StringThis is a set of different ticket flags in hexadecimal format.
Status<responsecode>
<tag2>
NumberA hexadecimal result code of TGT issue operation.
TicketEncryptionType<policy>Text/String/NumberThe cryptographic suite that was used for issued TGT.
PreAuthType<sessiontype>NumberThe code number of pre-Authentication type which was used in TGT request.
IpAddress<sip>NumberIP address of the computer from which the TGT request was received. Formats vary, and include the following:
  • IPv6 or IPv4 address.
  • ::ffff:IPv4_address.
  • ::1 - localhost.
IpPort<sport>NumberThe source port number of client network connection (TGT request connection).

0 for local (localhost) requests.
CerIssuerName<subject>Text/StringThe name of the Certification Authority that issued the smart card certificate. Populated in Issued by field in certificate.
CertSerialNumberN/A N/AThe smart card certificate’s serial number. Can be found in Serial number field in the certificate.
CertThumbprintN/A N/AThe smart card certificate’s thumbprint. Can be found in Thumbprint field in the certificate.
JavaScript errors detected

Please note, these errors can depend on your browser setup.

If this problem persists, please contact our support.