Hi
I have a Scheduled Eventlog Scanning task against my Domain Controllers (W2008 R2) each 15 minutes, and I enabled the option "Scan Success audit events" in Server Options. After that, although I began to receive events from my DCs, I can't see the EventID 4740 (Source: Microsoft Windows security) that tells me when an user account was locked out in Active Directory.
I don't understad what happen because the event 4740 is a Sucess Audit Event too.
Any idea?
Thanks a lot !!!