Build a great reporting interface using Splunk, one of the leaders in the Security Information and Event Management (SIEM) field, linking the collected Windows events to www.eventid.net. The EventId.Net for Splunk Add-on assumes that Splunk is collecting information from Windows servers and workstation via the Splunk Universal Forwarder.
The user <domain>\<username> connected on port <port> on <date> at <time> and disconnected on <date> at <time>. The user was active for <value> minutes <value> seconds. <value> bytes were sent and <value> bytes were received. The port speed was <value>. The reason for disconnecting was user request.
|English: Request a translation of the event description in plain English.|
In my case, the problem was caused by the time difference between the RRAS server and the DC. After the time was syncronized the problem was resolved.
See ME282078 for information about this event.
A demand-dial Point-to-Point Tunneling Protocol (PPTP) connection between two Windows servers that use the Routing and Remote Access service may disconnect every 1 minute and 30 seconds. Also, if Log the maximum amount of information has been set on the Event Logging tab in the Routing and Remote Access MMC, this event is logged every time the PPTP tunnel disconnects. See ME831531 and ME834426 for details on this event.
|Private comment: Subscribers only. See example of private comment|
|Links: ME282078, ME831531, ME834426|
|Search: Google - Bing - Microsoft - Yahoo - EventID.Net Queue (0) - More links...|
Send comments or solutions
- Notify me when updated