Monitor unlimited number of servers
Filter log events
Create email and web-based reports

Direct access to Microsoft articles
Customized keywords for major search engines
Access to premium content

Event ID: 1812 Source: NTDSInter-siteMessaging

The description for Event ID ( 1812 ) in Source ( NTDS Inter-site Messaging ) cannot be found. The local computer may not have the necessary registry information or message DLL files to display messages from a remote computer. You may be able to use the /AUXSOURCE= flag to retrieve this description; see Help and Support for details. The following information is part of the event: [] 4294967295.
This occurred while repairing COM+ on a 2003 Enterprise machine. After making some repairs, I was trying to see if any services hung on starting. I inadvertently tried to start Inter-Site Messaging. ME246717 pointed me to HKLM\CurrentControlSet\Services\NTDS\Diagnostics.
The keys there were empty (not in a domain, Active Directory not installed). That explains the lack of details in the event’s description. I also found this response from a MS MVP in a thread: "You did not mention anything about running Active Directory. Is this machine a DC of a domain? If not, just set that particular service to manual or disabled as it is part of support for Active Directory".
In my case, the event was due to trying to start an AD service on a non-domain server. I do not know if the event can be logged on a server in a domain.

Windows Event Log Analysis Splunk App

Build a great reporting interface using Splunk, one of the leaders in the Security Information and Event Management (SIEM) field, linking the collected Windows events to



Cisco ASA Log Analyzer Splunk App

Obtain enhanced visibility into Cisco ASA firewall logs using the free Firegen for Cisco ASA Splunk App. Take advantage of dashboards built to optimize the threat analysis process.