I'm trying to understand my event-viewer entries (please make it stop!).

I keep seeing ANONYMOUS LOGON events being logged to my systems. The event is 538/type 3 and 540/type 3. Which, according to M$ is: "A user or computer logged on to this computer from the network." But I have both systems locked down (no anonymous enum, additional restrictions, etc.). I know it's not an actual person attaching to the system, but what is it? A service?

I'm seeing this in both 2K and XP.

As I'm writing this, two more entries (538) popped up, one after the other (110 seconds), which, according to M$: "This event record indicates that a user has logged off."


Oh, and while were at it can anyone remind me the difference in auditing settings between "Audit account logon events" and "Audit logon events"? Both explanations appear to be pretty much the same

Thanks!