Monitor unlimited number of servers
Filter log events
Create email and web-based reports

Direct access to Microsoft articles
Customized keywords for major search engines
Access to premium content

Comments for event ID 2089 currently in the processing queue.

Note: We have not reviewed this information yet so it is unfiltered, exactly how it was submitted by our contributors.

Event ID: 2089
Event Source: ActiveDirectory_DomainService
Event Type: Error
Event Description: Log Name:      Directory Service
Source:        Microsoft-Windows-ActiveDirectory_DomainService
Date:          11/6/2011 9:16:05 PM
Event ID:      2089
Task Category: Backup
Level:         Warning
Keywords:      Classic
User:          ANONYMOUS LOGON
Computer:     DC.domain.com
Description:
This directory partition has not been backed up since at least the following number of days.

Directory partition:
CN=ConfigurationDC=domainDC=com

''Backup latency interval'' (days):
30

It is recommended that you take a backup as often as possible to recover from accidental loss of data. However if you haven''t taken a backup since at least the ''backup latency interval'' number of days this message will be logged every day until a backup is taken. You can take a backup of any replica that holds this partition.

By default the ''Backup latency interval'' is set to half the ''Tombstone Lifetime Interval''. If you want to change the default ''Backup latency interval'' you could do so by adding the following registry key.

''Backup latency interval'' (days) registry key:
System\CurrentControlSet\Services\NTDS\Parameters\Backup Latency Threshold (days)

Event Xml:
<Event xmlns="http://schemas.microsoft.com/win/2004/08/events/event">
  <System>
    <Provider Name="Microsoft-Windows-ActiveDirectory_DomainService" Guid="{0e8478c5-3605-4e8c-8497-1e730c959516}" EventSourceName="NTDS Replication" />
    <EventID Qualifiers="32768">2089</EventID>
    <Version>0</Version>
    <Level>3</Level>
    <Task>14</Task>
    <Opcode>0</Opcode>
    <Keywords>0x8080000000000000</Keywords>
    <TimeCreated SystemTime="2011-11-07T03:16:05.091092200Z" />
    <EventRecordID>4395</EventRecordID>
    <Correlation />
    <Execution ProcessID="472" ThreadID="592" />
    <Channel>Directory Service</Channel>
    <Computer>DC.domain.com</Computer>
    <Security UserID="S-1-5-7" />
  </System>
  <EventData>
    <Data>CN=ConfigurationDC=domainDC=com</Data>
    <Data>30</Data>
    <Data>System\CurrentControlSet\Services\NTDS\Parameters</Data>
    <Data>Backup Latency Threshold (days)</Data>
  </EventData>
</Event>
Comment:

Windows Event Log Analysis Splunk App

Build a great reporting interface using Splunk, one of the leaders in the Security Information and Event Management (SIEM) field, linking the collected Windows events to www.eventid.net.

Read more...

 

Cisco ASA Log Analyzer Splunk App

Obtain enhanced visibility into Cisco ASA firewall logs using the free Firegen for Cisco ASA Splunk App. Take advantage of dashboards built to optimize the threat analysis process.

Read more...