Monitor unlimited number of servers
Filter log events
Create email and web-based reports

Direct access to Microsoft articles
Customized keywords for major search engines
Access to premium content

Event ID: 20048 Source: RemoteAccess

The user <domain>\<username> connected on port <port> on <date> at <time> and disconnected on <date> at <time>. The user was active for <value> minutes <value> seconds. <value> bytes were sent and <value> bytes were received. The port speed was <value>. The reason for disconnecting was user request.
In my case, the problem was caused by the time difference between the RRAS server and the DC. After the time was syncronized the problem was resolved.
See ME282078 for information about this event.
A demand-dial Point-to-Point Tunneling Protocol (PPTP) connection between two Windows servers that use the Routing and Remote Access service may disconnect every 1 minute and 30 seconds. Also, if Log the maximum amount of information has been set on the Event Logging tab in the Routing and Remote Access MMC, this event is logged every time the PPTP tunnel disconnects. See ME831531 and ME834426 for details on this event.

Windows Event Log Analysis Splunk App

Build a great reporting interface using Splunk, one of the leaders in the Security Information and Event Management (SIEM) field, linking the collected Windows events to



Cisco ASA Log Analyzer Splunk App

Obtain enhanced visibility into Cisco ASA firewall logs using the free Firegen for Cisco ASA Splunk App. Take advantage of dashboards built to optimize the threat analysis process.