Build a great reporting interface using Splunk, one of the leaders in the Security Information and Event Management (SIEM) field, linking the collected Windows events to www.eventid.net. The EventId.Net for Splunk Add-on assumes that Splunk is collecting information from Windows servers and workstation via the Splunk Universal Forwarder.
|Type: Success Audit|
IKE security association ended.
Mode: Data Protection (Quick mode) Filter:
Source IP Address <IP address>
Source IP Address Mask <subnet mask>
Destination IP Address <IP address>
Destination IP Address Mask <subnet mask>
Source Port <value>
Destination Port <value>
Inbound SPI: <value>
Outbound SPI: <value>.
|English: Request a translation of the event description in plain English.|
This event indicates that an IPsec security association has ended. The ended security association may be hard or soft. See ME257225 for a situation in which this event may occur.
See ME265112 and MSW2KDB for details on this error.
|Private comment: Subscribers only. See example of private comment|
|Links: ME257225, ME265112, MSW2KDB|
|Search: Google - Bing - Microsoft - Yahoo - EventID.Net Queue (0) - More links...|
Send comments or solutions
- Notify me when updated