Monitor unlimited number of servers
Filter log events
Create email and web-based reports

Direct access to Microsoft articles
Customized keywords for major search engines
Access to premium content

Event ID: 1136 Source: NTDSGeneral

Active Directory failed to create an index for the following attribute.

Attribute identifier: <value>
Attribute name: <name>

A schema cache update will occur 5 minutes after the logging of this event and will attempt to create an index for the attribute.

Additional Data
Error value: -1403 JET_errIndexDuplicate, Index is already defined.
Additional Data
Error value:
-1403 JET_errIndexDuplicate, Index is already defined

From Microsoft support:
The reason for this error is the msExchRoleEntries attribute is marked for containerized indexing and we have multi language installed on the server. By default, when operation system is installed, we select language, but English US is also installed by default.

We can try these steps to fix this issue:
1. Run command regsvr32 schmmgmt.dll on domain controller to register schema management console.
2. Run command mmc to open console window.
3. Add snap-in Active Directory Schema.
4. Expand node: Console Root\Active Directory\Attributes, search attribute msExchRoleEntries.
5. Open the properties windows of attribute msExchRoleEntries.
6. Unclick the option Index this attribute for containerized searches.
7. Remove the multilanguage from the server by going to control panel\regional options

If the event message still appears after we perform the above operations, we can update ntdsa.dll file to fix this issue.
This event can occur after you install the BitLocker Drive Encryption schema updates in a Windows Server 2003 domain. See ME932862 for details.
See the link to "EventID 1136 from source Active Directory" for details on this event.

Windows Event Log Analysis Splunk App

Build a great reporting interface using Splunk, one of the leaders in the Security Information and Event Management (SIEM) field, linking the collected Windows events to



Cisco ASA Log Analyzer Splunk App

Obtain enhanced visibility into Cisco ASA firewall logs using the free Firegen for Cisco ASA Splunk App. Take advantage of dashboards built to optimize the threat analysis process.