We have seen a few Windows events with parsing issues. We get tons of DNS queries with our Wincollect servers as the source, but that seems pretty unlikely given the queries. It appears that some of the client requests end up with the Wincollect server as the source for some reason.
Also, like you, user names are absent from where you would expect (hope?) to see them.
BTW, we are just using the standard Windows security log parser, no customizations that I am aware of.
------------------------------
_____________________
Daniel Sichel
------------------------------