We have a problem currently where a user account from a person that has left the company is trying to authenticate every 5 minutes to vCenter. The problem is the logs doesn't show you where the account is trying to authenticate from. I suspect it's possibly a script or an applet that's configured to run somewhere...
All that the logs show are:
Error 1331 authenticating user %username%.
Failed to authenticate user <%username%>
Anyone have any ideas on how I can try and trace where the authentication attempts is originating from? Is that possibly hidden away in some other logs?
Cheers,
Hanré