Monitor unlimited number of servers
Filter log events
Create email and web-based reports

Direct access to Microsoft articles
Customized keywords for major search engines
Access to premium content

Event ID: 11645 Source: SAM

The maximum account identifier allocated to this domain controller has been assigned. The domain controller has failed to obtain a new identifier pool. A possible reason for this is that the domain controller has been unable to contact the master domain controller. Account creation on this controller will fail until a new pool has been allocated. There may be network or connectivity problems in the domain, or the master domain controller may be offline or missing from the domain. Verify that the master domain controller is running and connected to the domain.
I had this problem once a Domain had grown quite large. When trying to talk to Active Directory/SAM in anyway, ie adding a new user, it wouldn't work. If you look at the error message it says it's trying to contact the master domain controller, except in my case it was.
However I had a dead backup domain controller which I reckon was the cause of the problem. Once I had removed the occurences, as described in ME216498, the SAM started working again (event id 16648 - The request for a new account-identifier pool has completed successfully).

Windows Event Log Analysis Splunk App

Build a great reporting interface using Splunk, one of the leaders in the Security Information and Event Management (SIEM) field, linking the collected Windows events to



Cisco ASA Log Analyzer Splunk App

Obtain enhanced visibility into Cisco ASA firewall logs using the free Firegen for Cisco ASA Splunk App. Take advantage of dashboards built to optimize the threat analysis process.