Monitor unlimited number of servers
Filter log events
Create email and web-based reports

Direct access to Microsoft articles
Customized keywords for major search engines
Access to premium content

Event ID: 9022 Source: MSExchangeSA

Microsoft Exchange System Attendant encountered an error while processing the security data for Exchange server '<server name>'.
As per Microsoft: "This event indicates that the Microsoft Exchange System Attendant Service was unable to access the password management keys for the server specified in the Description section of the Event". See MSEX2K3DB for the most common causes known and for possible resolutions for this problem.
This could be because permissions on one of these key containers are corrupted. See per ME325964 and ME325964 for more details.
This event ID can be accompanied by event IDs 9149, 1005. Essentially there are corrupted keys within the server's key container. See ME280432.
Also together with 9149 and 1005, as per ME325674, "This issue may occur if the server account does not have the correct permissions on both the Exchange Organization container and the server container in Active Directory".

Windows Event Log Analysis Splunk App

Build a great reporting interface using Splunk, one of the leaders in the Security Information and Event Management (SIEM) field, linking the collected Windows events to



Cisco ASA Log Analyzer Splunk App

Obtain enhanced visibility into Cisco ASA firewall logs using the free Firegen for Cisco ASA Splunk App. Take advantage of dashboards built to optimize the threat analysis process.