Build a great reporting interface using Splunk, one of the leaders in the Security Information and Event Management (SIEM) field, linking the collected Windows events to www.eventid.net. The EventId.Net for Splunk Add-on assumes that Splunk is collecting information from Windows servers and workstation via the Splunk Universal Forwarder.
|Source: Active Directory|
An index on the attribute <attribute> (<attribute>) could not be created because the Windows Directory Service database (NTDS) failed with error <error code>. A schema cache update will be done again after 5 minutes to retry the index creation.
|English: Request a translation of the event description in plain English.|
|Concepts to understand:|
What is a directory service?
As per T756561, the first step to attempt to fix this problem is to restart the computer. If the error persists, you should compact and restore the database, and undo the index change. See the article for details.
As per Microsoft: "Active Directory was unable to create an index for the attribute specified in the message. A schema cache update will occur five minutes after this event is logged and will attempt to create an index for the attribute. A schema cache update will continue every five minutes until an index is created for the attribute". See MSW2KDB for more details.
|Private comment: Subscribers only. See example of private comment|
|Search: Google - Bing - Microsoft - Yahoo - EventID.Net Queue (0) - More links...|
Send comments or solutions
- Notify me when updated