VMware Cloud Community
Silent_Knight
Contributor
Contributor

Authentication failure in vCenter logs.

We have a problem currently where a user account from a person that has left the company is trying to authenticate every 5 minutes to vCenter. The problem is the logs doesn't show you where the account is trying to authenticate from. I suspect it's possibly a script or an applet that's configured to run somewhere...

All that the logs show are:

Error 1331 authenticating user %username%.

Failed to authenticate user <%username%>

Anyone have any ideas on how I can try and trace where the authentication attempts is originating from? Is that possibly hidden away in some other logs?

Cheers,

Hanré

0 Kudos
4 Replies
ProPenguin
Hot Shot
Hot Shot

Have you checked the services on that server to see if there account is tied to that. I remember making that mistake once and changed my password. Needless to say I kept getting my account locked out. Hope this helps.

0 Kudos
Silent_Knight
Contributor
Contributor

Thanks, but none of the services are configured to run with those credentials.

0 Kudos
AndreTheGiant
Immortal
Immortal

You can try to use the Windows Firewall to log the request.

Or a sniffer to see if the attach is from the network.

If is locally you can see in the process or in the scheduled tasks.

Andre

Andrew | http://about.me/amauro | http://vinfrastructure.it/ | @Andrea_Mauro
0 Kudos
NinjaAx
Contributor
Contributor

if you know the account name use account lockout tools from microsoft to see if its stuck on a pc or server anywhere,

http://www.microsoft.com/en-gb/download/details.aspx?id=18465

Is the account still in AD or is it a local account within VMware?

I also presume you've checked the session manager in vcenter?

If the account is still logged into a host i believe that stays there until the host is rebooted but may be wrong...maybe someone else could confirm that or Google Smiley Wink

Hope that helps

Alex

0 Kudos