Monitor unlimited number of servers
Filter log events
Create email and web-based reports

Direct access to Microsoft articles
Customized keywords for major search engines
Access to premium content

Event ID: 1137 Source: ClusSvc

Event Log replication queue OUTQ is full. xxx event(s) is (are) discarded of (total) size xxx.
As per Microsoft: "The Cluster Service replicates events from the local node's event log to the event logs of other nodes in the same cluster. Events to be replicated are queued and replicated when possible. If a node cannot process events quickly or if the node is offline, this event may appear in the event log when the maximum queue length is exceeded. By default, event log replication is enabled". See the link to "Windows Cluster Service Troubleshooting and Maintenance" to download the original white paper.

See ME224969 for information on how to configure event log replication in Windows 2000 cluster servers.
See also ME320333.
As per Microsoft: "This issue occurs because server clusters send event log entries from each node to all other nodes in the cluster so that each node has all of the event log entries.". See the link below for more details and resolution.

Windows Event Log Analysis Splunk App

Build a great reporting interface using Splunk, one of the leaders in the Security Information and Event Management (SIEM) field, linking the collected Windows events to



Cisco ASA Log Analyzer Splunk App

Obtain enhanced visibility into Cisco ASA firewall logs using the free Firegen for Cisco ASA Splunk App. Take advantage of dashboards built to optimize the threat analysis process.