Monitor unlimited number of servers
Filter log events
Create email and web-based reports

Direct access to Microsoft articles
Customized keywords for major search engines
Access to premium content

Event ID: 2601 Source: MSExchangeADAccess

Level
Description
Process <process name> (PID=<process id>). When initializing a remote procedure call (RPC) to the Microsoft Exchange Active Directory Topology service, Exchange could not retrieve the SID for account <account name> - Error code=<error code>.
The Microsoft Exchange Active Directory Topology service will continue starting with limited permissions.
Comments
 
According to ME2025528, this may be recorded when network connectivity is affected such as:
- Transient DNS failures
- Transient issues with Domain Controllers
- Transient network connectivity issues
- Network switches that have the PortFast functionality disabled on the ports to which the Exchange servers connect

See the article for workaround.
In my case, I was getting events 2080, 2601, 2604 and 2501 from the same source on a clustered Exchange 2007 server approximately every 15 minutes. It was a permissions error. The names of both the pieces of the cluster were in the Exchange Servers group but the virtual name of the cluster itself was not. Adding it to the group and rebooting both servers corrected the issue.
This problem occurs because the domain controller and other Exchange-Server-dependent services do not start completely when Exchange 2007 tries to start. See ME940845 for information on solving this problem.

This event may occur if one or more of the following conditions are true:
1. The Active Directory Topology service could not connect to the Active Directory configuration container.
2. The Active Directory Topology service could not read configuration information from the Active Directory configuration container.
See MSEX2K3DB for additional information about this event.

Windows Event Log Analysis Splunk App

Build a great reporting interface using Splunk, one of the leaders in the Security Information and Event Management (SIEM) field, linking the collected Windows events to www.eventid.net.

Read more...

 

Cisco ASA Log Analyzer Splunk App

Obtain enhanced visibility into Cisco ASA firewall logs using the free Firegen for Cisco ASA Splunk App. Take advantage of dashboards built to optimize the threat analysis process.

Read more...