Monitor unlimited number of servers
Filter log events
Create email and web-based reports

Direct access to Microsoft articles
Customized keywords for major search engines
Access to premium content

Event ID: 4304 Source: DFSR

The DFS Replication service has been repeatedly prevented from replicating a file due to consistent sharing violations encountered on the file. The service failed to stage a file for replication due to a sharing violation.

Additional Information:
File Path: <Local File Path>
Replicated Folder Root: <Folder Root>
File ID: <File ID>
Replicated Folder Name: <Folder Name>
Replicated Folder ID: <Floder ID>
Replication Group Name: <Group name>
Replication Group ID: <Group ID>
Member ID: <Member ID>
This is a new Event ID for Windows Server 2003 R2 SP1 found in a new DFS Replication log. Always backup the Dfs replicas before reconfiguring Dfs. Get users to log off first, particularly if Folder Redirection or Roaming Profiles are configured to use Dfs. Examine and compare the drive letter path for each Dfs replica using Windows Explorer. Look for any of these paths that are empty or do not match the other paths for the same replica. Also look for odd looking folders (e.g. folder names ending in "_NTFRS_xxxxxxxx", where "x" is a random hexadecimal number). Rebuild Dfs using Dfs Manager and restore missing files if necessary. Ensure that the right replica is selected as the primary source of the folder content.
If a file under a DFSR folder is open, the lock on that file prevents DFSR from replicating it. DFSR will check if the file has been closed every 15 minutes. If the file is still open during the following attempts, this event will be written to the event log. This is by design.

Windows Event Log Analysis Splunk App

Build a great reporting interface using Splunk, one of the leaders in the Security Information and Event Management (SIEM) field, linking the collected Windows events to



Cisco ASA Log Analyzer Splunk App

Obtain enhanced visibility into Cisco ASA firewall logs using the free Firegen for Cisco ASA Splunk App. Take advantage of dashboards built to optimize the threat analysis process.