Monitor unlimited number of servers
Filter log events
Create email and web-based reports

Direct access to Microsoft articles
Customized keywords for major search engines
Access to premium content

Event ID: 1006 Source: TermService

Source
Level
Description
The terminal server received large number of incomplete connections.  The system may be under attack.
Comments
 
From a newsgroup post: "If somebody repeatedly connects to your terminal server with an attacking tool and starts writing random data to the socket, this is the sort of thing you will see. The terminal server will typically see pretty shortly the protocol is all wrong and disconnect the client, but the client can then just reconnect and spew more garbage. If you see this sort of thing, I recommend using "Netmon" to track when connections are being made and from where, and correlate them with the Event log to see what is going on. It could be anything from a malicious user to a poorly written or misused utility somewhere. Once you figure that out you can make further decisions, like to have your firewall filter connections from that source, or make that user stop, or whatever.
After a socket connection has been accepted, it gets associated with a session. If a terminal server gets too many (something like 5) sockets that are waiting in line to be connected with a session, it logs this event to the event log. So really I think you could see this message if you were under attack, or if you had a situation where a sufficient number of people tried to connect in very short period of time. So the event is not indicative of an imminent crash, it's simply logging for the above describes circumstances, and probably needs to be worded better to indicate the ambiguity of the situation: The TS may or may not be under attack. It might just be 9 am, and everybody tried to connect at the same time".

From a newsgroup post: "Do you see that the machine has an unusual amount of memory utilization when these errors occur? If so, you might want to read the following article: ME216783 "Unable to completely disconnect a Terminal Server connection". The registry settings in the article will help the server account for the disconnected sessions in a more efficient manner".

Windows Event Log Analysis Splunk App

Build a great reporting interface using Splunk, one of the leaders in the Security Information and Event Management (SIEM) field, linking the collected Windows events to www.eventid.net.

Read more...

 

Cisco ASA Log Analyzer Splunk App

Obtain enhanced visibility into Cisco ASA firewall logs using the free Firegen for Cisco ASA Splunk App. Take advantage of dashboards built to optimize the threat analysis process.

Read more...