This is an automated archive.
The original was posted on /r/sysadmin by /u/Tx_Drewdad on 2024-01-18 22:34:18+00:00.
Need to rant for a moment....
Had a user report repeated account lockouts. Cool. Checked my report, and it shows the server causing the lockout. Directed the user to the SME for that service for further help.
This was a week or more ago.
SME for that service finally asks for help. He shows me the log on the server with the time/date stamp of the failed logon(s). Event happens every five minutes like clockwork.
Literally, all I did was look at the event log timestamp and then the IIS logs for that time to see the source IP and the user agent string. The SME says, oh yeah!
I mean... is this some esoteric skill? Reading logs? Help me understand.