After installing a new Coordinator/Broker and deploying Change Auditor agents to several Domain Controllers, the DCs begin generating an extremely high volume of security events as soon as the agent starts running.
Within seconds of service startup, the following event types repeat continuously:
4625 – An account failed to log on
4768 – A Kerberos authentication ticket (TGT) was requested
These events are logged repeatedly in rapid succession until the Change Auditor agent is manually stopped. On‑Demand auditing continues to receive events.
We have identified a defect in the Change Auditor Agent processing logic that is responsible for generating the repeated 4625 (An account failed to log on) and 4768 (Kerberos TGT request) audit events.
Defect ID: 629247 – [Hybrid Audit] Many Kerberos event name‑lookup failures
This defect causes the agent to repeatedly perform Kerberos‑related name lookups, resulting in a continuous stream of authentication events on the Domain Controllers where the agent is installed.
The issue is currently under active investigation by Engineering, and a fixed agent build is not yet available. At this time, there are no agent‑side workarounds to mitigate the behavior.
To check whether this defect is included in future releases, please review the release notes for newly published product versions.
To receive product update notifications, sign in with an account that has an active maintenance contract and enable email alerts under My Subscriptions: https://support.quest.com/manageprofile
You may also subscribe to the RSS feed for product updates: https://support.quest.com/kb/4316478/how-to-subscribe-to-rss-feeds-product-notifications