事件查看器Windows 2003中有许多login/注销事件

我似乎在安全事件查看器中获得了很多这些条目。 每小时8-12左右。 我想知道a)我应该担心吗? 或者b)究竟是怎么回事,谁能帮忙?

Type: Success Audit Source: Security Category: Logon/Logoff User: Network Service or IUSR_WIN2003 Logon attempt using explicit credentials: Logged on user: User Name: NETWORK SERVICE Domain: NT AUTHORITY Logon ID: (0x0,0x3E4) Logon GUID: - User whose credentials were used: Target User Name: IUSR_WIN2003 Target Domain: WILDEBB1 Target Logon GUID: - Target Server Name: localhost Target Server Info: localhost Caller Process ID: 13224 Source Network Address: - Source Port: - 

也就在这之后,loggingiis停止接受连接,我不得不重新启动服务器。 与此不同的是,login过程使用ADVAPI …

 Event Type: Success Audit Event Source: Security Event Category: Logon/Logoff Event ID: 540 Date: 05/06/2012 Time: 13:59:10 User: WILDEAA1\IUSR_WIN2003 Computer: WILDEAA1 Description: Successful Network Logon: User Name: IUSR_WIN2003 Domain: WILDEAA1 Logon ID: (0x0,0x5FDB22D) Logon Type: 8 Logon Process: Advapi Authentication Package: Negotiate Workstation Name: WILDEAA1 Logon GUID: - Caller User Name: NETWORK SERVICE Caller Domain: NT AUTHORITY Caller Logon ID: (0x0,0x3E4) Caller Process ID: 13224 Transited Services: - Source Network Address: - Source Port: - 

IUSR帐户是安装IIS时创build的匿名用户帐户。 你是否在该服务器上运行任何网站? 只要IIS尝试为匿名用户login帐户,就会看到login事件。