Monitor unlimited number of servers
Filter log events
Create email and web-based reports

Direct access to Microsoft articles
Customized keywords for major search engines
Access to premium content

Event ID: 144 Source: Time-Service

The time service has stopped advertising as a good time source.
1. Open the Registry Editor. To open the registry editor click Start. In Start Search type regedit and then press ENTER. If the User Account Control dialog box appears confirm that the action it displays is what you want and then click Continue.
2. Navigate to the following location in the registry: HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\W32Time\Config
3. In the right pane double-click the AnnounceFlags attribute. By default this value is decimal 10 (value "a" in hexadecimal). Correct the value as necessary.

If this value is correct and you've received this warning after changing the timesource of the Windows Time Service restart the time server again. You should now see the following events:

Severity: Info
Source: Time-Service

Severity: Info
Source: Kernel-General
(Possibly multi)

Severity: Info
Source: Time-Service

Severity: Info
Source: Time-Service

Windows Event Log Analysis Splunk App

Build a great reporting interface using Splunk, one of the leaders in the Security Information and Event Management (SIEM) field, linking the collected Windows events to



Cisco ASA Log Analyzer Splunk App

Obtain enhanced visibility into Cisco ASA firewall logs using the free Firegen for Cisco ASA Splunk App. Take advantage of dashboards built to optimize the threat analysis process.