Build a great reporting interface using Splunk, one of the leaders in the Security Information and Event Management (SIEM) field, linking the collected Windows events to www.eventid.net. The EventId.Net for Splunk Add-on assumes that Splunk is collecting information from Windows servers and workstation via the Splunk Universal Forwarder.
|Source: NTDS KCC|
The replication topology update task terminated abnormally with code <error code>.
|English: Request a translation of the event description in plain English.|
|Concepts to understand:|
What is NTDS and what are the roles of its components?
What is KCC?
See the link to "EventID 1014 from source Active Directory" for information about this event.
Peter Van Gils
If these errors occur during a domain controller demotion, you can ignore them. Just like promoting a server to DC gives some errors, demoting one gives errors too.
Happened when I was demoting one of two DC. Event 1568 also shown in directory service log. Follow ME250874 and ME269417 to manually create a site connection between the two DC and add the Administrator group to the local security policy (Enable computer and users accounts to be trusted for delegation). Retry dcpromo - worked for me this time.
Look at time on you Domain Controllers. They must be with the same hour and minute.
|Private comment: Subscribers only. See example of private comment|
|Links: EventID 1014 from source Active Directory|
|Search: Google - Bing - Microsoft - Yahoo - EventID.Net Queue (0) - More links...|
Send comments or solutions
- Notify me when updated