Monitor unlimited number of servers
Filter log events
Create email and web-based reports

Direct access to Microsoft articles
Customized keywords for major search engines
Access to premium content

Event ID: 16652 Source: SAM

The domain controller is booting to directory services restore mode.
This event is self-explanatory. The event is very useful for troubleshooting, and it seems to have been introduced with Windows 2003 SP1. Other Event IDs that appear around the same time can generally be ignored if they do not appear again when Windows is started normally. This is also the case when Windows was started in some other form of Safe Mode (there is no equivalent Event ID to this one for Safe Mode).

Windows Event Log Analysis Splunk App

Build a great reporting interface using Splunk, one of the leaders in the Security Information and Event Management (SIEM) field, linking the collected Windows events to



Cisco ASA Log Analyzer Splunk App

Obtain enhanced visibility into Cisco ASA firewall logs using the free Firegen for Cisco ASA Splunk App. Take advantage of dashboards built to optimize the threat analysis process.