Monitor unlimited number of servers
Filter log events
Create email and web-based reports

Direct access to Microsoft articles
Customized keywords for major search engines
Access to premium content

Event ID: 1864 Source: ActiveDirectory_DomainService

Level
Description
This is the replication status for the following directory partition on this directory server.

Directory partition:
CN=SchemaCN=ConfigurationDC=domainDC=com

This directory server has not recently received replication information from a number of directory servers.  The count of directory servers is shown divided into the following intervals.

More than 24 hours:
2
More than a week:
2
More than one month:
0
More than two months:
0
More than a tombstone lifetime:
0
Tombstone lifetime (days):
180

Directory servers that do not replicate in a timely manner may encounter errors. They may miss password changes and be unable to authenticate. A DC that has not replicated in a tombstone lifetime may have missed the deletion of some objects and may be automatically blocked from future replication until it is reconciled.

To identify the directory servers by name use the dcdiag.exe tool.
You can also use the support tool repadmin.exe to display the replication latencies of the directory servers.   The command is "repadmin /showvector /latency <partition-dn>".
Comments
 
From a support forum:
I have two Domain Controllers (Windows 2008 core, running Windows 2008 functional level) in a child domain called test.domain.com and the parent domain is domain.com. I was getting this message. Running repadmin /showrepl on both domain controllers did not reveal any problem. However, once I used:

dcdiag /test:replications

I could see the troubled domain controller and I was able to fix it. See T776210 on how to verify replication with other domain controllers.
If this is caused by a failed DC, see EV100515 (Delete Failed DCs from Active Directory).

Windows Event Log Analysis Splunk App

Build a great reporting interface using Splunk, one of the leaders in the Security Information and Event Management (SIEM) field, linking the collected Windows events to www.eventid.net.

Read more...

 

Cisco ASA Log Analyzer Splunk App

Obtain enhanced visibility into Cisco ASA firewall logs using the free Firegen for Cisco ASA Splunk App. Take advantage of dashboards built to optimize the threat analysis process.

Read more...