Monitor unlimited number of servers
Filter log events
Create email and web-based reports

Direct access to Microsoft articles
Customized keywords for major search engines
Access to premium content

Event ID: 1052 Source: DHCP

Source
Level
Description
The DHCP/BINL service on this workgroup server has encountered another server with IP Address, <address>, belonging to the domain <domain>.
Comments
 
As per Microsoft: "This event message indicates the possibility of an unauthorized server on the network. For the directory authorization process to work properly, it is assumed and necessary that the first DHCP server introduced on to your network participate in the Active Directory service. This requires that the server be installed as either a domain controller or a member server. Where you are either planning for or actively deploying Active Directory services, it is important that you do not select to install your first DHCP server computer as a stand-alone server". See MSW2KDB for more information.

Windows Event Log Analysis Splunk App

Build a great reporting interface using Splunk, one of the leaders in the Security Information and Event Management (SIEM) field, linking the collected Windows events to www.eventid.net.

Read more...

 

Cisco ASA Log Analyzer Splunk App

Obtain enhanced visibility into Cisco ASA firewall logs using the free Firegen for Cisco ASA Splunk App. Take advantage of dashboards built to optimize the threat analysis process.

Read more...