Build a great reporting interface using Splunk, one of the leaders in the Security Information and Event Management (SIEM) field, linking the collected Windows events to www.eventid.net. The EventId.Net for Splunk Add-on assumes that Splunk is collecting information from Windows servers and workstation via the Splunk Universal Forwarder.
The file C:\Program Files\Citrix\HealthMon\Tests\Citrix\RequestTicket.exe does not have the correct permissions. In SDDL the expected ACL was O:BAD:AI(AID0x1200a9LS)(AIDFABA). The actual ACL was O:BAD:AI(AFABA)(AIDFABA)(AIDFASY)(AID0x1200a9BU)(AID0x1200a9LS)(AIDFRNS). For reference the files placed in the test folder should have inheritable permissions turned on which will result in the file have full control access for the Administrators group Read and Execute access for the Local Service user account and the owner will be the Administrators group.
|1 Comment for event id 4004 from source CitrixHealthMon|
The DFS Replication service stopped replication on the replicated folder at local path E:\Files\Information Technology.
Error: 9098 (A tombstoned content set deletion has been scheduled)
Additional context of the error:
Replicated Folder Name: Information Technology
Replicated Folder ID: 3E205C8A-60E4-436A-8B6A-9DDBEE2F6B54
Replication Group Name: <domain name>\data\information technology
Replication Group ID: BD7D0BDA-22D9-4294-93EC-CF715A4EA5A5
Member ID: 2A896016-35CC-4F7A-8C83-256E744D1540
|4 Comments for event id 4004 from source DFSR|
The DNS server was unable to complete directory service enumeration of zone .. This DNS server is configured to use information obtained from Active Directory for this zone and is unable to load the zone without it. Check that the Active Directory is functioning properly and repeat enumeration of the zone. The event data contains the error.
|9 Comments for event id 4004 from source DNS|
The following error occurred while trying to retrieve TCP/IP service information ((11004)).
|1 Comment for event id 4004 from source MSExchangeIMC|
Categorization failed. The error message is "<error message>".
|2 Comments for event id 4004 from source MSExchangeTransport|
Telnet Service failed to initialize.
|1 Comment for event id 4004 from source TlntSvr|