Question : infrastructure analyst

Some of my client PCs (windows XP) getting security event log full.  This started after Microsoft tech support assisted with a confllicter virus problem.  Microsoft Technical support turned on a group policy to audit failed logon attempts.  I have set it back to not configurated, but the event log continue to fill up.  We have configuration manager clients along with forefront with MOM clients install on these PCs.  
How can I determine why there are so many sucessful logons and from who?

Answer : infrastructure analyst

If you look in the event logs, it should have an IP source for the attempt
Random Solutions  
 
programming4us programming4us