Monitor unlimited number of servers
Filter log events
Create email and web-based reports

Direct access to Microsoft articles
Customized keywords for major search engines
Access to premium content

Event ID: 1863 Source: NTDSReplication

Level
Description
This is the replication status for the following directory partition on the local domain controller.

Directory partition:
DC=ForestDnsZonesDC=atlDC=local

The local domain controller has not received replication information from a number of domain controllers within the configured latency interval.

Latency Interval (Hours): <value>
Number of domain controllers in all sites: <value>
Number of domain controllers in this site: <value>

The latency interval can be modified with the following registry key.

Registry Key: "HKLM\System\CurrentControlSet\Services\NTDS\Parameters\Replicator" latency error interval (hours)

To identify the domain controllers by name install the support tools included on the installation CD and run dcdiag.exe. You can also use the support tool repadmin.exe to display the replication latencies of the domain controllers in the forest. The command is "repadmin /showvector /latency <partition-dn>".
Comments
 
This event may be an indication that the Active Directory may contain lingering objects (objects that are deleted from the Active Directory directory service when the domain controller is offline). These can occur if a domain controller does not replicate for an interval of time that is longer than the tombstone lifetime (TSL). See ME910205 for more information about lingering objects and how to remove them.

If you attempt a domain controller demotion and for some reason it fails, ME216498 provides details on how to remove the server manually.

Windows Event Log Analysis Splunk App

Build a great reporting interface using Splunk, one of the leaders in the Security Information and Event Management (SIEM) field, linking the collected Windows events to www.eventid.net.

Read more...

 

Cisco ASA Log Analyzer Splunk App

Obtain enhanced visibility into Cisco ASA firewall logs using the free Firegen for Cisco ASA Splunk App. Take advantage of dashboards built to optimize the threat analysis process.

Read more...