Monitor unlimited number of servers
Filter log events
Create email and web-based reports

Direct access to Microsoft articles
Customized keywords for major search engines
Access to premium content

Event ID: 13516 Source: NtFrs

The File Replication Service is no longer preventing the computer DESCARTES from becoming a domain controller. The system volume has been successfully initialized and the Netlogon service has been notified that the system volume is now ready to be shared as SYSVOL.

Type "net share" to check for the SYSVOL share.
This event ID is directly related to Missing FRS objects and FRS attributes in AD. Steps to diagnose and rectify the issue:

1. Go to Microsoft download page and download the FRS Diagnostics Tool (see the link below). Note this tool can be run remotely from an XP station or on the server.

2. Select all the servers you want to run this diagnostics on (typically all DCs) and click GO (on the FRSDiag Tools GUI)

3. Parse through the report and locate missing Computre Ref for the Server "server name". This will refer to  article KB312862. Go to MS site and locate this artcile. Now you will need to use ADSIedit to rectify the missing/deleted server reference.

4. Download ADSIedit utility (see ADSI Edit link). You can also run ADSIedit remotely on an XP.

5. Run ADSIedit and follow through the steps in the article ME312862. Different error messages will need you to follow different resolution detailed in the article. Wait for the replication to happen next time or force a replication to see the results.

You can repeat the FRSDiag to look for any other potential problem.
See ME283133 for a situation in which this event occurs.
ME315457 gives information on how to rebuild SYSVOL and its content in a Domain. This event also appears in the contents of this article.

See ME555381 for information on how to configure the Windows 2003 SP1 firewall on a Domain Controller. A wrongly configured firewall might be the cause of this event.

See MSW2KDB for additional information on this event.
This event is generated when a Windows 2000 domain controller boots or the FRS (File Replication Service) is restarted. This behavior is by design - the event is just informational. The events 13502, 13503, and 13501 are usually generated  before 13516.

Windows Event Log Analysis Splunk App

Build a great reporting interface using Splunk, one of the leaders in the Security Information and Event Management (SIEM) field, linking the collected Windows events to



Cisco ASA Log Analyzer Splunk App

Obtain enhanced visibility into Cisco ASA firewall logs using the free Firegen for Cisco ASA Splunk App. Take advantage of dashboards built to optimize the threat analysis process.