Monitor unlimited number of servers
Filter log events
Create email and web-based reports

Direct access to Microsoft articles
Customized keywords for major search engines
Access to premium content

Event ID: 2604 Source: MSExchangeADAccess

Process <process name> (PID=<process id>). When updating security for a remote procedure call (RPC) access for the Microsoft Exchange Active Directory Topology service Exchange could not retrieve the security descriptor for Exchange server object <server name> - Error code=<error code>.
The Microsoft Exchange Active Directory Topology service will continue starting with limited permissions.
According to ME2025528, this can be caused by TCP/IP network problems such as:
- Transient DNS failures
- Transient issues with Domain Controllers
- Transient network connectivity issues
- Network switches that have the PortFast functionality disabled on the ports to which the Exchange servers connect

See the article for resolution.
In my case, I was getting events 2080, 2601, 2604 and 2501 from the same source on a clustered Exchange 2007 server approximately every 15 minutes. It was a permissions error. The names of both the pieces of the cluster were in the Exchange Servers group but the virtual name of the cluster itself was not. Adding it to the group and rebooting both servers corrected the issue.

Windows Event Log Analysis Splunk App

Build a great reporting interface using Splunk, one of the leaders in the Security Information and Event Management (SIEM) field, linking the collected Windows events to



Cisco ASA Log Analyzer Splunk App

Obtain enhanced visibility into Cisco ASA firewall logs using the free Firegen for Cisco ASA Splunk App. Take advantage of dashboards built to optimize the threat analysis process.