Based on the following ID, can help us quickly identify by http://www.aliyun.com/zixun/aggregation/11208.html ">microsoft"? The security events generated by the Windows Server 2003 operating system mean what happened.
Account logon events
The security events generated by the Audit account logon events security template settings are shown below.
672: The Authentication Service (as) ticket was successfully issued and validated.
673: The Authorization Ticket Service (TGS) ticket is authorized. TGS is a ticket issued by the Kerberos V5 ticket Authorization Service (TGS), allowing users to authenticate specific services in the domain.
674: The security principal has updated the as ticket or TGS ticket.
675: Pre-authentication failed. The Key Distribution Center (KDC) generates this event when the user types the wrong password.
676: Authentication ticket request failed. This event is not generated in Windows XP Professional or members of the Windows Server family.
677:TGS ticket is not authorized. This event is not generated in Windows XP Professional or members of the Windows Server family.
678: The account was successfully mapped to a domain account.
681: Login failed. Attempt to log on to a domain account. This event is not generated in Windows XP Professional or members of the Windows Server family.
682: The user has reconnected to a disconnected Terminal Server session.
683: The user disconnects the Terminal Server session without logging off.