Monitor unlimited number of servers
Filter log events
Create email and web-based reports

Direct access to Microsoft articles
Customized keywords for major search engines
Access to premium content

Event ID: 409 Source: DNS

Source
Level
Description
The DNS server list of restricted interfaces contains IP addresses that are not configured for use at the server computer. Use the DNS manager server properties, interfaces dialog, to verify and reset the IP addresses the DNS server should listen on. For more information, see "To restrict a DNS server to listen only on selected addresses" in the online Help.
Comments
 
As per Microsoft: "If you are using database files that have been imported from a non-Microsoft DNS server, you must install these files in the Systemroot\System32\Dns folder. Before importing the files, use a text editor to edit the files so that the directory command identifies the DNS directory". See MSW2KDB for more details on this event.
This indicates that the DNS interface is configured with more than one IP address, and that one of the addresses is no longer valid. In the DNS console, open the properties for the server, select the Interfaces tab, and review the IP addresses listed. Remove any old or invalid IP addresses to prevent this message from re-appearing.
As per ME326911 "An incorrect IP address is listed in the listeners section of your DNS server's settings".

Windows Event Log Analysis Splunk App

Build a great reporting interface using Splunk, one of the leaders in the Security Information and Event Management (SIEM) field, linking the collected Windows events to www.eventid.net.

Read more...

 

Cisco ASA Log Analyzer Splunk App

Obtain enhanced visibility into Cisco ASA firewall logs using the free Firegen for Cisco ASA Splunk App. Take advantage of dashboards built to optimize the threat analysis process.

Read more...