How to Interpret ID 4624 Type 3 Events on a Domain Controller

active-directorydomain-controllerwindows-event-logwindows-server-2012windows-server-2012-r2

I'm seeing a lot of ID 4624 Events (Logon Type 3) on a domain controller (Windows Server 2012) and I'm wondering what those events want to to tell me.

I've read that 4624 Type 3 events on a domain controller say that there was a network logon on the AD domain but I don't understand what Source Network Address means.
Is it where the login came from or is it the target where the user wants to login?

enter image description here

Best Answer

The source network address would be the address the request originated from, but that could be local host or a means by which the source information isn't included.

You may have come across it already but the following includes plenty of detail along with some useful auditing approaches:

https://docs.microsoft.com/en-us/windows/security/threat-protection/auditing/event-4624

Hope that helps