Build a great reporting interface using Splunk, one of the leaders in the Security Information and Event Management (SIEM) field, linking the collected Windows events to www.eventid.net. The EventId.Net for Splunk Add-on assumes that Splunk is collecting information from Windows servers and workstation via the Splunk Universal Forwarder.
<Exchange server name> An unknown MTA has attempted to bind. The MTA name in bind is <other MTA host>. The MTA presentation address is <address> Association Index: 2354. [MTA XFER-IN 23 42] (14)
|English: Request a translation of the event description in plain English.|
|Concepts to understand:|
What is the role of the Exchange MTA Service?
What is the role of ESENT?
See ME152932 and ME166308 to fix this problem.
Elliott Fields Jr
This event means that a remote message transfer agent (MTA) has attempted to establish a messaging session and there has been a mismatch in the specified security information. This could be a typo or other mistake; however, this should be investigated immediateley because it could indicate a security breach.
|Private comment: Subscribers only. See example of private comment|
|Links: ME152932, ME166308|
|Search: Google - Bing - Microsoft - Yahoo - EventID.Net Queue (0) - More links...|
Send comments or solutions
- Notify me when updated