Monitor unlimited number of servers
Filter log events
Create email and web-based reports

Direct access to Microsoft articles
Customized keywords for major search engines
Access to premium content

Event ID: 1147 Source: ClusSvc

The Microsoft Clustering Service encountered a fatal error. The vital quorum log file 'Q:\MSCS\quolog.log' could not be found. If you have a backup of the quorum log file, you may try to start the cluster service by entering 'clussvc -debug -noquorumlogging' at a command window, copy the backed up quorum log file to the MSCS directory in the quorum drive, stop the cluster service, and restart the cluster service normally using the 'net start clussvc' command. If you do not have a backup of the quorum log file, you may try to start the cluster service as 'clussvc -debug -resetquorumlog' and this will attempt to create a new quorum log file based on possibly stale information in the cluster hive. You may then stop the cluster service and restart it normally using the 'net start clussvc' command.
As per Microsoft: "This error message occurs if the quorum log file (Quolog.log) cannot be found or read at Cluster service startup. It must be readable to confirm that the cluster configuration on the local node is up-to-date. If it cannot read the log, the Cluster service does not start to prevent potentially loading stale configuration data". See ME245762 for more details

Windows Event Log Analysis Splunk App

Build a great reporting interface using Splunk, one of the leaders in the Security Information and Event Management (SIEM) field, linking the collected Windows events to



Cisco ASA Log Analyzer Splunk App

Obtain enhanced visibility into Cisco ASA firewall logs using the free Firegen for Cisco ASA Splunk App. Take advantage of dashboards built to optimize the threat analysis process.