Monitor unlimited number of servers
Filter log events
Create email and web-based reports

Direct access to Microsoft articles
Customized keywords for major search engines
Access to premium content

Event ID: 597 Source: Security

Recovery of data protection master key.
Key Identifier: <value>
Recovery Reason: <value>
Recovery Server: <value>
Recovery Key ID: <value>
Failure Reason: <value>.
As per Microsoft: "A key that is used by the Data Protection application programming interface (DPAPI) is being recovered. Because the DPAPI keys are backed up on Active Directory, the computer can automatically recover a key when necessary. This message is logged for informational purposes only. It usually follows a Security 596 message, which indicates that the DPAPI key was backed up. There may be a period of days or weeks between the messages". See MSW2KDB for more details.

Windows Event Log Analysis Splunk App

Build a great reporting interface using Splunk, one of the leaders in the Security Information and Event Management (SIEM) field, linking the collected Windows events to



Cisco ASA Log Analyzer Splunk App

Obtain enhanced visibility into Cisco ASA firewall logs using the free Firegen for Cisco ASA Splunk App. Take advantage of dashboards built to optimize the threat analysis process.