Monitor unlimited number of servers
Filter log events
Create email and web-based reports

Direct access to Microsoft articles
Customized keywords for major search engines
Access to premium content

Event ID: 1020 Source: DhcpServer

Source
Level
Description
Scope 192.168.1.0 is 81 percent utilized with only 11 IP addresses remaining.
Comments
 
As per Microsoft: "Internet Protocol (IP) addresses are leased by the Dynamic Host Configuration Protocol (DHCP) server to its clients. Each lease has an expiration date, which the client must renew if it is going to continue to use that IP address. The DHCP server cannot issue leases to clients if the number of available IP addresses in the scope is insufficient". See T726940 for more information.
See "JSI Tip 2987" and MSW2KDB to find out why this event occurs.
In my case, I had to expand the existing scope range from 192.168.1.100 - 192.168.1.199 to 192.168.1.100 - 192.168.1.220. After restarting the DHCP server, the database had been cleared and showed the correct actualized values.
A client server reported 25 addresses in use and 1 free on the statistics pane, but only 4 items in Active Leases. Refreshing did not change the listing. After restarting the DHCP Server service and then refreshing the window, all the other leases appeared and were deleted. This stopped the events and corrected the statistics.
Message triggered by the DHCP server when the number of available IP addresses within the specified scope is reaching a certain level. See ME165006 and ME261964 for more details.


Windows Event Log Analysis Splunk App

Build a great reporting interface using Splunk, one of the leaders in the Security Information and Event Management (SIEM) field, linking the collected Windows events to www.eventid.net.

Read more...

 

Cisco ASA Log Analyzer Splunk App

Obtain enhanced visibility into Cisco ASA firewall logs using the free Firegen for Cisco ASA Splunk App. Take advantage of dashboards built to optimize the threat analysis process.

Read more...