Monitor unlimited number of servers
Filter log events
Create email and web-based reports

Direct access to Microsoft articles
Customized keywords for major search engines
Access to premium content

Event ID: 13563 Source: NtFrs

The File Replication service has detected that the staging path for the replica set DOMAIN SYSTEM VOLUME (SYSVOL SHARE) has changed.

Current staging path = E:\Windows\Sysvol\Staging\Domain
New staging path = E:\Frsstage

The service will start using the new staging path after it restarts. The service is set to restart after every restart.

It is recommended that you manually restart the service to prevent loss of data in the staging folder.

To manually restart the service do the following:

[1] Run "net stop ntfrs" or use the Services snap-in to stop File Replication service.
[2] Move all the staging files corresponding to replica set DOMAIN SYSTEM VOLUME (SYSVOL SHARE) to the new staging location. If more than one replica set are sharing the current staging folder then it is safer to copy the staging files to the new staging folder.
[3] Run "net start ntfrs" or use the Services snap-in to start File Replication service, followed by "net start ntfrs".

For more information, visit Help and Support Services at
This event occurs during the procedure for reseting the File Replication service staging folder to a different logical drive. See the link to "Relocating the Staging Area" for details.
See ME291823 for more information.

Windows Event Log Analysis Splunk App

Build a great reporting interface using Splunk, one of the leaders in the Security Information and Event Management (SIEM) field, linking the collected Windows events to



Cisco ASA Log Analyzer Splunk App

Obtain enhanced visibility into Cisco ASA firewall logs using the free Firegen for Cisco ASA Splunk App. Take advantage of dashboards built to optimize the threat analysis process.