Monitor unlimited number of servers
Filter log events
Create email and web-based reports

Direct access to Microsoft articles
Customized keywords for major search engines
Access to premium content

Event ID: 1568 Source: NTDSKCC

Source
Level
Description
None of the domain controllers in the following site that replicate the following directory partition are configured to use the following transport, even though the site itself is configured to allow replication over this transport.

Site:
CN=ALEXANDRIA-VA,CN=Sites,CN=Configuration,DC=mcsenetworks,DC=net
Directory partition:
DC=mcsanetworks,DC=net
Transport:
CN=IP,CN=Inter-Site Transports,CN=Sites,CN=Configuration,DC=mcsenetworks,DC=net

User Action
Using Active Directory Sites and Services, do one of the following:

- Configure the site to not allow replication using this transport by modifying the appropriate siteLink objects.
- Enable one or more domain controllers to use this transport. For the SMTP transport, this requires installation of the SMTP service and configuration of the mailAddress attribute on the corresponding Server object.
Comments
 
I was getting events 1311, 1568 and 1566 from source NTDS KCC. I used DCdiag to troubleshoot this problem. I had to add an alias to the DNS Forward lookup zones, _msdcs as one of the DCs wasn't listed. I did this on all DCs and restarted the DNS service. In addition, I had to start the Distributed Link Tracking Client and Distributed Link Tracking Server services as they were stopped on the DC. Errors went away after these changes.
This message is is referring to the fact that your site is configured to use IP (and or SMTP) as its transport but your Active Directory Connections are using RPC.

Windows Event Log Analysis Splunk App

Build a great reporting interface using Splunk, one of the leaders in the Security Information and Event Management (SIEM) field, linking the collected Windows events to www.eventid.net.

Read more...

 

Cisco ASA Log Analyzer Splunk App

Obtain enhanced visibility into Cisco ASA firewall logs using the free Firegen for Cisco ASA Splunk App. Take advantage of dashboards built to optimize the threat analysis process.

Read more...