Monitor unlimited number of servers
Filter log events
Create email and web-based reports

Direct access to Microsoft articles
Customized keywords for major search engines
Access to premium content

Event ID: 1023 Source: MSExchangeISPrivate

Description
<User name> was validated as <user name> but was unable to log on to <server name>.
Comments
 
This event is generated when you delete a mailbox or a public folder without first removing a published Event Script from the mailbox or the public folder. See ME281683 for details.
As per Microsoft: "This event is logged when you run MBClean from a server where the user mailboxes do not reside. This event is informational only and does not result in any failures in running MBCLean. The event can be ignored". See ME188594 for more details.

From a newsgroup post: "I have seen this happen when a mailbox has been deleted and recreated under the same name, and an existing Outlook profile that used to access the original mailbox is modified to access the recreated mailbox. To clean up, simply create brand new Outlook profiles for those generating the errors, and setting the new profile as the default startup profile for Outlook".

See the link to "EventID 1023 from source MSExchangeIS" for additional information on this event.
As per Microsoft: "Event ID 11 is logged in the application event log soon after you start the Microsoft Exchange Event Service. Event ID 1023 is logged immediately after the Event Service starts. It may take approximately one minute for the Event ID 11 to appear in the application event log. In some cases, the Event 1023 and (or) 11 does not appear at all. The events are harmless and are generated when you delete a mailbox or public folder without first removing a published Event Script from the mailbox or public folder." For more details see ME259578.

Windows Event Log Analysis Splunk App

Build a great reporting interface using Splunk, one of the leaders in the Security Information and Event Management (SIEM) field, linking the collected Windows events to www.eventid.net.

Read more...

 

Cisco ASA Log Analyzer Splunk App

Obtain enhanced visibility into Cisco ASA firewall logs using the free Firegen for Cisco ASA Splunk App. Take advantage of dashboards built to optimize the threat analysis process.

Read more...