Monitor unlimited number of servers
Filter log events
Create email and web-based reports

Direct access to Microsoft articles
Customized keywords for major search engines
Access to premium content

Event ID: 1104 Source: NTDSKCC

Source
Level
Description
The Knowledge Consistency Checker (KCC) successfully terminated the following change notifications.

Directory partition:
CN=Configuration,DC=mcsenetworks,DC=net
Destination network address:
16c6788b-dc2f-43f9-8abf-9d8f29f643c0._msdcs.mcsenetworks.net
Destination domain controller (if available):
CN=NTDS Settings,CN=MCSA-DC-01,CN=Servers,CN=ALEXANDRIA-VA,CN=Sites,CN=Configuration,DC=mcsenetworks,DC=net

This event can occur if either this domain controller or the destination domain controller has been moved to another site.
Comments
 
In one case, this Event ID appeared when metadata for a domain controller that was no longer in the domain was cleaned up using NTDSUTIL.
See the link to "EventID 1104 from source Active Directory" for information on this event.
This event can occur if either this domain controller or the destination domain controller has been moved to another site.

Windows Event Log Analysis Splunk App

Build a great reporting interface using Splunk, one of the leaders in the Security Information and Event Management (SIEM) field, linking the collected Windows events to www.eventid.net.

Read more...

 

Cisco ASA Log Analyzer Splunk App

Obtain enhanced visibility into Cisco ASA firewall logs using the free Firegen for Cisco ASA Splunk App. Take advantage of dashboards built to optimize the threat analysis process.

Read more...