Monitor unlimited number of servers
Filter log events
Create email and web-based reports

Direct access to Microsoft articles
Customized keywords for major search engines
Access to premium content

Event ID: 509 Source: NTDSISAM

Source
Level
Description
NTDS (<PID>) NTDSA: A request to write to the file "<file>" at offset <offset> (<offset>) for <value> (<value>) bytes succeeded but took an abnormally long time (<value> seconds) to be serviced by the OS. In addition <value> other I/O requests to this file have also taken an abnormally long time to be serviced since the last message regarding this problem was posted <value> seconds ago. This problem is likely due to faulty hardware. Please contact your hardware vendor for further assistance diagnosing the problem.
Comments
 
This error occurred when a physical drive failed in a SCSI RAID array. The performance of the array decreased significantly until the raid controller finished rebuilding the array using an online spare; therefore, Active Directory had a difficult time writing to the database. Rebuilding the array solved this issue.

Windows Event Log Analysis Splunk App

Build a great reporting interface using Splunk, one of the leaders in the Security Information and Event Management (SIEM) field, linking the collected Windows events to www.eventid.net.

Read more...

 

Cisco ASA Log Analyzer Splunk App

Obtain enhanced visibility into Cisco ASA firewall logs using the free Firegen for Cisco ASA Splunk App. Take advantage of dashboards built to optimize the threat analysis process.

Read more...