Monitor unlimited number of servers
Filter log events
Create email and web-based reports

Direct access to Microsoft articles
Customized keywords for major search engines
Access to premium content

Event ID: 9095 Source: MSExchangeSA

The MAD Monitoring thread is initializing.
This event also occurs when a server is restarted.

From a newsgroup post: "Verify if you are able to ping your GCs (Global Catalog servers) from your FE (Front End) server. I resolved an issue with a customer who had similar symptoms. We ultimately resolved the issue when we disabled the RRAS service on the GC."

From a newsgroup post: "If this event along with event id 9096 is recorded with event id 9098 (Access denied) chances are that the IBM Tivoli Endpoint agent is installed. Obtaining a patch from IBM or disabling it resolved the issue.
See ME305030 and ME837285 for details on this event.
This event is followed by event id: 9096. MAD refers to Exchange System Attendant initializing with Windows Management Instrumentation (WMI), the Microsoft implementation for Web Based Enterprise Management (WBEM). This was introduced with W2K SP2. Fore more information about WMI see link below.

Windows Event Log Analysis Splunk App

Build a great reporting interface using Splunk, one of the leaders in the Security Information and Event Management (SIEM) field, linking the collected Windows events to



Cisco ASA Log Analyzer Splunk App

Obtain enhanced visibility into Cisco ASA firewall logs using the free Firegen for Cisco ASA Splunk App. Take advantage of dashboards built to optimize the threat analysis process.