Build a great reporting interface using Splunk, one of the leaders in the Security Information and Event Management (SIEM) field, linking the collected Windows events to www.eventid.net. The EventId.Net for Splunk Add-on assumes that Splunk is collecting information from Windows servers and workstation via the Splunk Universal Forwarder.
|Source: NTDS KCC|
The Directory Service consistency checker has noticed that <number> attempts to establish a replication link with CN=NTDS Settings,CN=<cn name>,CN=Servers,CN=Default-First-Site-Name,CN=Sites,CN=Configuration,DC=<domain name>,DC=<domain name postfix> have failed over a period of <number> minutes. The connection object for this server will be kept in place, and new a temporary connection will be established to ensure that replication continues. Once a connection with CN=NTDS Settings,CN=<cn name>,CN=Servers,CN=Default-First-Site-Name,CN=Sites,CN=Configuration,DC=<domain name>,DC=<domain postfix> is established the temporary connection will be removed.
|English: Request a translation of the event description in plain English.|
|Concepts to understand:|
What is NTDS and what are the roles of its components?
What is KCC?
What is a directory service?
Some newsgroup posts suggest that this may occur when there is a network communication problem between domain controllers.
|Private comment: Subscribers only. See example of private comment|
|Search: Google - Bing - Microsoft - Yahoo - EventID.Net Queue (0) - More links...|
Send comments or solutions
- Notify me when updated