Build a great reporting interface using Splunk, one of the leaders in the Security Information and Event Management (SIEM) field, linking the collected Windows events to www.eventid.net. The EventId.Net for Splunk Add-on assumes that Splunk is collecting information from Windows servers and workstation via the Splunk Universal Forwarder.
The SAM database attempted to clear the directory C:\WINNT\ntds in order to remove files that were once used by the Directory Service. The error is in record data. Please have an admin delete these files.
|English: Request a translation of the event description in plain English.|
|Concepts to understand:|
What is a directory service?
This message is generated when DCPROMO is used to demote a Domain Controller to member server status. Manually delete the files specified.
|Private comment: Subscribers only. See example of private comment|
|Search: Google - Bing - Microsoft - Yahoo - EventID.Net Queue (0) - More links...|
Send comments or solutions
- Notify me when updated