Monitor unlimited number of servers
Filter log events
Create email and web-based reports

Direct access to Microsoft articles
Customized keywords for major search engines
Access to premium content

Event ID: 1862 Source: NTDSReplication

This is the replication status for the following directory partition on the local domain controller.

Directory partition: DC=ForestDnsZones,DC=mcsenetworks,DC=net

The local domain controller has not received replication information from a number of domain controllers in other sites within the configured latency intverval.

Number of domain controllers: 1
Latency Interval (Hours): 24

The latency interval can be modified with the following registry key.

Registry Key:  
HKLM\System\CurrentControlSet\Services\NTDS\Parameters\Replicator latency error interval (hours)

To identify the domain controllers by name, install the support tools included on the installation  CD and run dcdiag.exe. You can also use the support tool repadmin.exe to display the replication latencies of the domain controllers in the forest. The command is "repadmin /showvector /latency <partition-dn>".
See ME899148 if you have installed Service Pack 1 for Windows Server 2003.
The tools Repadmin.exe and DcDiag.exe are useful in troubleshooting this problem.
As per Microsoft: "Event ID 1862 is logged when we have domain controllers not replicating between sites. There is a specific misconfiguration where we created Active Directory sites but the site was not in the site link, and we now have a specific event that captures that misconfiguration". See the link to "Upgrading Windows NT 4.0 Domains to Windows Server 2003" for additional information on this issue.
This is a status report given in Windows 2003 to let you know if your Active Directory DNS partitions are replicating properly. This message also gives you statistics about the partition being replicated.

The domain controller has not been able to replicate other objects from another site within the forest. Ensure proper configuration by validating domain trusts throught domain.msc.

Windows Event Log Analysis Splunk App

Build a great reporting interface using Splunk, one of the leaders in the Security Information and Event Management (SIEM) field, linking the collected Windows events to



Cisco ASA Log Analyzer Splunk App

Obtain enhanced visibility into Cisco ASA firewall logs using the free Firegen for Cisco ASA Splunk App. Take advantage of dashboards built to optimize the threat analysis process.