Monitor unlimited number of servers
Filter log events
Create email and web-based reports

Direct access to Microsoft articles
Customized keywords for major search engines
Access to premium content

Comments for event ID 2501 currently in the processing queue.

Note: We have not reviewed this information yet so it is unfiltered, exactly how it was submitted by our contributors.

Event ID: 2501
Event Source: MSExchangeADAccess
Event Type: Error
Event Description: The description for Event ID ( 2501 ) in Source ( MSExchange ADAccess ) cannot be found. The local computer may not have the necessary registry information or message DLL files to display messages from a remote computer. You may be able to use the /AUXSOURCE= flag to retrieve this description see Help and Support for details. The following information is part of the event: MSEXCHANGEADTOPOLOGY 1996 HrSearch 80040a01.
Comment:
Event ID: 2501
Event Source: MSExchangeADAccess
Event Type: -
Event Description: -
Comment: For Exchange servers running Windows Server 2008 R2, these event IDs (2601, 2604, 2501) are caused by Exchange not re-trying AD query after initial failure. Per MS KB2025528:
"After the server has been up for a minute or two, run NLTest /DSGetSite to verify that that the proper Active Directory Site is being returned by Windows.  Once that has been verified, restart the MSExchange ADTopology Service." Index: 9243
Event ID: 2501
Event Source: MSExchange ADAccess
Event Type: Error
Event Description: Log Name:      Application
Source:        MSExchange ADAccess
Date:          11/12/2012 8:47:11 AM
Event ID:      2501
Task Category: General
Level:         Error
Keywords:      Classic
User:          N/A
Computer:      Exchange.server.name
Description:
Process MSEXCHANGEADTOPOLOGY (PID=1788). The site monitor API was unable to verify the site name for this Exchange computer - Call=DsctxGetContext Error code=8007077f. Make sure that Exchange server is correctly registered on the DNS server.
Event Xml:
<Event xmlns="http://schemas.microsoft.com/win/2004/08/events/event">
  <System>
    <Provider Name="MSExchange ADAccess" />
    <EventID Qualifiers="49156">2501</EventID>
    <Level>2</Level>
    <Task>1</Task>
    <Keywords>0x80000000000000</Keywords>
    <TimeCreated SystemTime="2012-12-11T16:47:11.000000000Z" />
    <EventRecordID>140014</EventRecordID>
    <Channel>Application</Channel>
    <Computer>Exchange.server.name</Computer>
    <Security />
  </System>
  <EventData>
    <Data>MSEXCHANGEADTOPOLOGY</Data>
    <Data>1788</Data>
    <Data>DsctxGetContext</Data>
    <Data>8007077f</Data>
  </EventData>
</Event>
Comment: Contractor installed BES Express prior.

Items also changed during the BES installation.
Enabled secure updates on DNS zones.
Relocated the server objects in the default computer container to the OU designated for servers.
Event ID: 2501
Event Source: DNS Event
Event Type: -
Event Description: -
Comment: Which log do i find this in? Index: 2965

Windows Event Log Analysis Splunk App

Build a great reporting interface using Splunk, one of the leaders in the Security Information and Event Management (SIEM) field, linking the collected Windows events to www.eventid.net.

Read more...

 

Cisco ASA Log Analyzer Splunk App

Obtain enhanced visibility into Cisco ASA firewall logs using the free Firegen for Cisco ASA Splunk App. Take advantage of dashboards built to optimize the threat analysis process.

Read more...