We have PRTG in our global Active Directory, Server is in AUS, one PROBE (in DC in BOS site). Only PRTG software uses domain\administrator account in BOS server. We see monthly multiple "Bad password" event 4771 (kerberos pre-authentication failed) in BOS server trying to logon to BOS-DC, another multiple saying bad password while trying to logon to from BOS-DC to AUS-DC, number of event 4771 seems like matching the number of Windows servers (with Disk/Memory sensors)
After update version 188.8.131.528 on 8/13, this become daily 7am EDT, or 9pm Australia time
Is there any way we can test to make sure that event 4771 come from PRTG system? -- stop the service without causing error alerts, then wait next morning to see if those event 4771 still come or not
Is there other way to check?
Thank you very much! Xiaolin