I have a SBS 08 with 50 users on my domain. In Event Viewer : Windows Logs > Security, I've got nearly 300,000 events about EventID 4624 Logon, 4634 Logoff, 4776 Credential Validation, 4769 Kerberos Service Ticket Operations in only… 2 days !!!
I want to simply disable it. I tried disabling the audit in the Local Policy or Group Policy but everything is greyed:
Security Settings > Local Policies > Audit Policy > Audit logon events : No Auditing
Best Answer
Look for an HP printer that loads up an apache web service.
I had 50,000 Kerb errors on my DC with that funky printer client on one of my workstations.
Like others have said, find the underlying cause, don't mask what's going on.