Monitor unlimited number of servers
Filter log events
Create email and web-based reports

Direct access to Microsoft articles
Customized keywords for major search engines
Access to premium content

Event ID: 7 Source: KDC

The Security Account Manager failed a KDC request in an unexpected way. The error is in the data field. The account name was <user name> and lookup type <lookup type code>.

0000: <bytes of the error code>
ME325850 on how to use Netdom.exe to reset machine account passwords of a Windows Server domain controller helped me fix this problem.
The Security Accounts Manager (SAM) database on the Kerberos client (the local list of users) is used to authenticate requests from the Kerberos Key Distribution Center (KDC). The SAM database must be available for the Kerberos client authentication request to succeed.

Reported lookup types:
- 0x0
- 0x8
- 0x20
- 0x28
- 0x108
- 0x100

Reported error codes in the Data portion of the event:
0xc00000e5 = INTERNAL_ERROR
Low disk space is another cause of these errors. A customer complained about not being able to log on to the server. When checking the event logs, I found that it was filled with these errors. On further examination, I found that the C: drive had only 60MB free.
You may receive this event on the domain controllers where you install the hotfix provided in ME812499.

Windows Event Log Analysis Splunk App

Build a great reporting interface using Splunk, one of the leaders in the Security Information and Event Management (SIEM) field, linking the collected Windows events to



Cisco ASA Log Analyzer Splunk App

Obtain enhanced visibility into Cisco ASA firewall logs using the free Firegen for Cisco ASA Splunk App. Take advantage of dashboards built to optimize the threat analysis process.