Skip to main content
Skip table of contents

V 2.0 : EVID 4768-4771 : Kerberos TGT Failure Msg

Vendor Documentation

Classification

Rule Name

Rule Type

Common Event

Classification

V 2.0 : EVID 4768-4771 : Kerberos TGT Failure MsgBase RuleGeneral Authentication EventOther Audit
V 2.0 : EVID 4768 : Computer Logon SuccessSub RuleComputer LogonAuthentication Success
V 2.0 : EVID 4768 : User Logon SuccessSub RuleUser LogonAuthentication Success
V 2.0 : EVID 4768 : Computer Logon Failure -Bad UsSub RuleComputer Logon FailureAuthentication Failure
V 2.0 : EVID 4768 : Computer Logon Failure - ClockSub RuleComputer Logon FailureAuthentication Failure
V 2.0 : EVID 4768 : Computer Logon Failure-UnsprtSub RuleComputer Logon FailureAuthentication Failure
V 2.0 : EVID 4768 : Computer Logon Failure InvaldSub RuleComputer Logon FailureAuthentication Failure
V 2.0 : EVID 4768 : Computer Logon Flr  CredentialSub RuleComputer Logon FailureAuthentication Failure
V 2.0 : EVID 4768 : Computer Logon Failure PswrdSub RuleComputer Logon FailureAuthentication Failure
V 2.0 : EVID 4768 : Computer Logon Failure Bad PasSub RuleComputer Logon FailureAuthentication Failure
V 2.0 : EVID 4768 : Computer Logon Failure - ExpirSub RuleComputer Logon FailureAuthentication Failure
V 2.0 : EVID 4768 : Computer Logon Failure - TktSub RuleComputer Logon FailureAuthentication Failure
V 2.0 : EVID 4768 : Computer Logon Failure-DuplkteSub RuleComputer Logon FailureAuthentication Failure
V 2.0 : EVID 4768 : Computer Logon Failure - ClockSub RuleComputer Logon FailureAuthentication Failure
V 2.0 : EVID 4768 : User Logon Failure- Bad UserSub RuleUser Logon Failure : Bad UsernameAuthentication Failure
V 2.0 : EVID 4768 : User Logon Failure - Clock OutSub RuleUser Logon FailureAuthentication Failure
V 2.0 : EVID 4768 : User Logon Failure - UnsupportSub RuleUser Logon FailureAuthentication Failure
V 2.0 : EVID 4768 : User Logon Failure- Invalid CeSub RuleUser Logon FailureAuthentication Failure
V 2.0 : EVID 4768 : User Logon Failure - CredentiaSub RuleUser Logon Failure : Account DisabledAuthentication Failure
V 2.0 : EVID 4768 : User Logon Failure- Password ESub RuleUser Logon Failure : Bad PasswordAuthentication Failure
V 2.0 : EVID 4768 : User Logon Failure- Bad PswrdSub RuleUser Logon Failure : Bad PasswordAuthentication Failure
V 2.0 : EVID 4768 : User Logon Failure Expired TktSub RuleUser Logon FailureAuthentication Failure
V 2.0 : EVID 4768 : User Logon Failure Ticket NotSub RuleUser Logon FailureAuthentication Failure
V 2.0 : EVID 4768 : User Logon Failure DuplicatedSub RuleUser Logon FailureAuthentication Failure
V 2.0 : EVID 4768 : User Logon Failure - Clock OutSub RuleUser Logon FailureAuthentication Failure
V 2.0 : EVID 4771 : Computer Logon Failure - InvldSub RuleComputer Logon FailureAuthentication Failure
V 2.0 : EVID 4771 : Computer Logon Failure- PaswrdSub RuleComputer Logon FailureAuthentication Failure
V 2.0 : EVID 4771 : Computer Logon Fail Bad PswrdSub RuleComputer Logon FailureAuthentication Failure
V 2.0 : EVID 4771 : User Logon Failure Invalid CerSub RuleUser Logon FailureAuthentication Failure
V 2.0 : EVID 4771 : User Logon Fail Password ExprdSub RuleUser Logon Failure : Bad PasswordAuthentication Failure
V 2.0 : EVID 4771 : User Logon Failure Bad PswrdSub RuleUser Logon Failure : Bad PasswordAuthentication Failure
V 2.0 : EVID 4768 : Client Database Entry Has ExprSub RuleUser Logon FailureAuthentication Failure
V 2.0 : EVID 4768 : KDC Has No Suprt For TransitedSub RuleUser Logon FailureAuthentication Failure
V 2.0 : EVID 4768 : Client Not Yet ValidSub RuleUser Logon FailureAuthentication Failure
V 2.0 : EVID 4768 : KDC Has No Suprt For TransitedSub RuleUser Logon FailureAuthentication Failure
V 2.0 : EVID 4768 : Additional Pre-auth RequiredSub RuleUser Logon FailureAuthentication Failure
V 2.0 : EVID 4768 : Server Database Entry Has ExprSub RuleUser Logon FailureAuthentication Failure
V 2.0 : EVID 4768 : The Tkt Is Not Fr UserSub RuleUser Logon FailureAuthentication Failure
V 2.0 : EVID 4768 : Ticket & Authenticator Do NotSub RuleUser Logon FailureAuthentication Failure
V 2.0 : EVID 4768 : Incorrect Net AddressSub RuleUser Logon FailureAuthentication Failure
V 2.0 : EVID 4768 : Protocol Version MismatchSub RuleUser Logon FailureAuthentication Failure
V 2.0 : EVID 4768 : Specified Ver Of Key Is Not AvSub RuleUser Logon FailureAuthentication Failure
V 2.0 : EVID 4768 : Service Key Not AvailableSub RuleUser Logon FailureAuthentication Failure
V 2.0 : EVID 4768 : Mutual Authentication FailedSub RuleUser Logon FailureAuthentication Failure
V 2.0 : EVID 4768 : Alternative Auth MethodSub RuleUser Logon FailureAuthentication Failure
V 2.0 : EVID 4768 : Client Key Encypted In Old MstSub RuleUser Logon FailureAuthentication Failure
V 2.0 : EVID 4768 : Server Key Encrypted In Old MsSub RuleUser Logon FailureAuthentication Failure
V 2.0 : EVID 4768 : Client Nt Found In Kerberos DBSub RuleUser Logon FailureAuthentication Failure
V 2.0 : EVID 4768 : Server Nt Found In Kerberos DBSub RuleUser Logon FailureAuthentication Failure
V 2.0 : EVID 4768 : Multiple Principal Entrs In DbSub RuleUser Logon FailureAuthentication Failure
V 2.0 : EVID 4768 : Client Or Server Has Null KeySub RuleUser Logon FailureAuthentication Failure
V 2.0 : EVID 4768 : KDC Policy Rejects RequestSub RuleUser Logon FailureAuthentication Failure
V 2.0 : EVID 4768 : KDC Cannot Accomodate Req OptnSub RuleUser Logon FailureAuthentication Failure
V 2.0 : EVID 4768 : KDC Has No Support For ChecksmSub RuleUser Logon FailureAuthentication Failure
V 2.0 : EVID 4768 : Cred For Server Have Been RvkdSub RuleAccess Revoked ActivityAccess Revoked
V 2.0 : EVID 4768 : TGT Has Been RevokedSub RuleAccess Revoked ActivityAccess Revoked
V 2.0 : EVID 4768 : Integrity Chk On Decrypt FieldSub RuleIntegrity Check On Decrypted Field FailedWarning
V 2.0 : EVID 4768 : Invalid Message TypeSub RuleInvalid Message TypeError
V 2.0 : EVID 4768 : Message Stream ModifiedSub RuleMessage Stream ModifiedInformation
V 2.0 : EVID 4768 : Message Out Of OrderSub RuleMessage Out Of OrderError
V 2.0 : EVID 4768 : Incorrect Message DirectionSub RuleIncorrect Message DirectionError
V 2.0 : EVID 4768 : Unsupported ProtocolSub RuleReconnaissance ActivityReconnaissance
V 2.0 : EVID 4768 : Incorrect Seq No In MessageSub RuleIncorrect Sequence NumberError
V 2.0 : EVID 4768 : Inapt Typ Of Chcksum In MsgSub RuleInappropriate Type Of ChecksumError
V 2.0 : EVID 4768 : Generic ErrorSub RuleGeneric ErrorError
V 2.0 : EVID 4768 : Field Is Too Long For This ImpSub RuleField Is Too LongError
V 2.0 : EVID 4768 : Ticket Not Eligible For PostdaSub RuleModify Object Attribute FailureAccess Failure

Mapping with LogRhythm Schema  

Device Key in Log MessageLogRhythm SchemaData TypeSchema Description
ProviderN/AN/AIdentifies the provider that logged the event. The Name and GUID attributes are included if the provider used an instrumentation manifest to define its events. The EventSourceName attribute is included if a legacy event provider (using the Event Logging API) logged the event.
EventID<vmid>

NumberThe identifier that the provider used to identify the event.
VersionN/A N/AThe version number of the event's definition.
Level<severity>Text/StringThe severity level defined in the event.
Task<vendorinfo>Text/StringThe task defined in the event. Task and Opcode are typically used to identify the location in the application from where the event was logged.
OpcodeN/A N/AThe opcode defined in the event. Task and Opcode are typically used to identify the location in the application from where the event was logged.
Keywords<result>, <tag3>Text/StringA bitmask of the keywords defined in the event. Keywords are used to classify types of events (for example, events associated with reading data).
TimeCreatedN/A N/AThe time stamp that identifies when the event was logged. The time stamp will include either the SystemTime attribute or the RawTime attribute.
EventRecordIDN/A N/AThe record number assigned to the event when it was logged.
CorrelationN/A N/AThe activity identifiers that consumers can use to group related events together.
ExecutionN/A N/AContains information about the process and thread that logged the event.
ChannelN/A N/AThe channel to which the event was logged.
Computer<dname>Text/StringThe name of the computer on which the event occurred.
TargetUserName<login>, <tag1>Text/StringThe user name of the account that requested the ticket in the User Principal Name (UPN) syntax. Computer account name ends with $ character in the user name part. This field typically has the following value format: user_account_name@FULL\_DOMAIN\_NAME.
  • User account example: dadmin@CONTOSO.LOCAL
  • Computer account example: WIN81$@CONTOSO.LOCAL
TargetDomainName<domainorigin>Text/StringThe name of the Kerberos Realm that Account Name belongs to. This can appear in a variety of formats, including the following:
  • Domain NETBIOS name example: CONTOSO
  • Lowercase full domain name: contoso.local
  • Uppercase full domain name: CONTOSO.LOCAL

This parameter in this event is optional and can be empty in some cases.
ServiceName<process>Text/String

The name of the account or computer for which the TGS ticket was requested.

This parameter in this event is optional and can be empty in some cases.

ServiceSidN/AN/ASID of the account or computer object for which the TGS ticket was requested.
TicketOptions<command>NumberThis is a set of different Ticket Flags in hexadecimal format.
Status<responsecode>,
<tag2>
NumberA hexadecimal result code of TGS issue operation.
TicketEncryptionType<policy>NumberThe cryptographic suite that was used for issued TGS.
PreAuthType<sessiontype>Numberthe code number of pre-Authentication type which was used in TGT request.
IpAddress<sip>IP AddressIP address of the computer from which the TGS request was received. Formats vary, and include the following:
  • IPv6 or IPv4 address.
  • ::ffff:IPv4_address.
  • ::1 - localhost.
IpPort<sport>Number

The source port number of client network connection (TGS request connection).

0 for local (localhost) requests.

CerIssuerName<subject>Text/Stringthe name of the Certification Authority that issued the smart card certificate. Populated in Issued by field in certificate.
LogonGuidN/A N/AA GUID that can help you correlate this event (on a domain controller) with other events (on the target computer for which the TGS was issued) that can contain the same Logon GUID.
TransmittedServicesN/A N/AThis field contains a list of SPNs which were requested if Kerberos delegation was used.
JavaScript errors detected

Please note, these errors can depend on your browser setup.

If this problem persists, please contact our support.