When you look for these events in nDepth, what is populated in the SourceLogonID field? I'm not sure that the Windows logs on the DC actually send that information to the LEM, but I don't have an AD DC to play with in my lab to confirm. Can you capture a sample event?
↧