Monitor unlimited number of servers
Filter log events
Create email and web-based reports

Direct access to Microsoft articles
Customized keywords for major search engines
Access to premium content

Comments for event ID 53 currently in the processing queue.

Note: We have not reviewed this information yet so it is unfiltered, exactly how it was submitted by our contributors.

Event ID: 53
Event Source: Symantec Antivirus
Event Type: Information
Event Description: User 'admin' logged in to Server Group Symantec AntiVirus 1 from (IP)-192.168.10.11 port 1186.  Login session will expire 10/28/2005 - 10:33:21 AM (GMT).
Comment:
Event ID: 53
Event Source: RMS
Event Type: Error
Event Description: The topology for Active Directory queries cannot be initialized. Windows Rights Management Services cannot access Active Directory. Microsoft.DigitalRightsManagement.Utilities.ADEntrySearchFailedException: Failed to find an entry in the Active Directory: id=S-1-5-21-3542044960-272679561-1127247009-500. ---> Microsoft.DigitalRightsManagement.DirectoryServices.DirectoryServiceGetPrincipalIdentifierException: An Active Directory services component failed to find the principal. ---> Microsoft.DigitalRightsManagement.DirectoryServices.RemoteDirectoryServiceGetPrincipalIdentifierException: The remote Active Directory services component failed to find the principal. ---> Microsoft.DigitalRightsManagement.DirectoryServices.UnableToIncarnateException: LDAP pool failed to initialize. ---> Microsoft.DigitalRightsManagement.DirectoryServices.UnableToInitializeTopologyException: The topology could not be initialized. ---> Microsoft.DigitalRightsManagement.DirectoryServices.NoGcsfoundException: There are no Global Catalog servers available or there are fewer servers than are required. Verify that this computer is connected to the network and the Global Catalog servers are available.
   at Microsoft.DigitalRightsManagement.DirectoryServices.Topology.Initialize()
   --- Fin de la trace de la pile d'exception interne ---
   at Microsoft.DigitalRightsManagement.DirectoryServices.Topology.Initialize()
   at Microsoft.DigitalRightsManagement.DirectoryServices.Incarnation.Initialize()
   --- Fin de la trace de la pile d'exception interne ---
   at Microsoft.DigitalRightsManagement.DirectoryServices.Incarnation.Initialize()
   at Microsoft.DigitalRightsManagement.DirectoryServices.Incarnation._MapToDrmsAdirMethod(String[] strInputs METHOD_TYPE mt)
   at Microsoft.DigitalRightsManagement.DirectoryServices.RemoteActiveDirectoryServices.GetPrincipalIdentifier(String strPrincipal String desiredIdentifier)
   --- Fin de la trace de la pile d'exception interne ---
   at Microsoft.DigitalRightsManagement.DirectoryServices.RemoteActiveDirectoryServices.GetPrincipalIdentifier(String strPrincipal String desiredIdentifier)
   at Microsoft.DigitalRightsManagement.DirectoryServices.ActiveDirectoryServices.GetPrincipalIdentifier(String strPrincipal String desiredIdentifier)
   --- Fin de la trace de la pile d'exception interne ---
   at Microsoft.DigitalRightsManagement.DirectoryServices.ActiveDirectoryServices.GetPrincipalIdentifier(String strPrincipal String desiredIdentifier)
   at Microsoft.DigitalRightsManagement.Certification.Pipeline._GetPrincipalIdentifier(String principal String desiredIdentifier)
   --- Fin de la trace de la pile d'exception interne ---
   at Microsoft.DigitalRightsManagement.Certification.Pipeline._GetPrincipalIdentifier(String principal String desiredIdentifier)
   at Microsoft.DigitalRightsManagement.Certification.Pipeline._ProcessEmailAddress(IDrmsPropertyBag propertyBag CaType caType String& emailAddress Identification identification)
   at Microsoft.DigitalRightsManagement.Certification.Pipeline.Certify(CaType caType CertifyParams[] requestParams HttpRequest request IIdentity userIdentity)

Pour plus d'informations consultez le centre Aide et support à l'adresse http://go.microsoft.com/fwlink/events.asp.
Données :
0000: 7b 35 65 37 62 31 32 37   {5e7b127
0008: 63 2d 36 62 63 38 2d 34   c-6bc8-4
0010: 34 34 33 2d 39 62 37 65   443-9b7e
0018: 2d 64 39 33 33 35 63 39   -d9335c9
0020: 34 64 61 62 61 7d 2e 34   4daba}.4
Comment:
Event ID: 53
Event Source: RMS
Event Type: Error
Event Description: The topology for Active Directory queries cannot be initialized. Windows Rights Management Services cannot access Active Directory. Microsoft.DigitalRightsManagement.Utilities.ADEntrySearchFailedException: Failed to find an entry in the Active Directory: id=S-1-5-21-4107011738-1849158312-295014890-500. ---> Microsoft.DigitalRightsManagement.DirectoryServices.DirectoryServiceGetPrincipalIdentifierException: An Active Directory services component failed to find the principal. ---> Microsoft.DigitalRightsManagement.DirectoryServices.RemoteDirectoryServiceGetPrincipalIdentifierException: The remote Active Directory services component failed to find the principal. ---> Microsoft.DigitalRightsManagement.DirectoryServices.UnableToIncarnateException: LDAP pool failed to initialize. ---> Microsoft.DigitalRightsManagement.DirectoryServices.UnableToInitializeTopologyException: The topology could not be initialized. ---> Microsoft.DigitalRightsManagement.DirectoryServices.NoGcsfoundException: There are no Global Catalog servers available or there are fewer servers than are required. Verify that this computer is connected to the network and the Global Catalog servers are available.
   at Microsoft.DigitalRightsManagement.DirectoryServices.Topology.Initialize()
   --- End of inner exception stack trace ---
   at Microsoft.DigitalRightsManagement.DirectoryServices.Topology.Initialize()
   at Microsoft.DigitalRightsManagement.DirectoryServices.Incarnation.Initialize()
   --- End of inner exception stack trace ---
   at Microsoft.DigitalRightsManagement.DirectoryServices.Incarnation.Initialize()
   at Microsoft.DigitalRightsManagement.DirectoryServices.Incarnation._MapToDrmsAdirMethod(String[] strInputs METHOD_TYPE mt)
   at Microsoft.DigitalRightsManagement.DirectoryServices.RemoteActiveDirectoryServices.GetPrincipalIdentifier(String strPrincipal String desiredIdentifier)
   --- End of inner exception stack trace ---
   at Microsoft.DigitalRightsManagement.DirectoryServices.RemoteActiveDirectoryServices.GetPrincipalIdentifier(String strPrincipal String desiredIdentifier)
   at Microsoft.DigitalRightsManagement.DirectoryServices.ActiveDirectoryServices.GetPrincipalIdentifier(String strPrincipal String desiredIdentifier)
   --- End of inner exception stack trace ---
   at Microsoft.DigitalRightsManagement.DirectoryServices.ActiveDirectoryServices.GetPrincipalIdentifier(String strPrincipal String desiredIdentifier)
   at Microsoft.DigitalRightsManagement.Certification.Pipeline._GetPrincipalIdentifier(String principal String desiredIdentifier)
   --- End of inner exception stack trace ---
   at Microsoft.DigitalRightsManagement.Certification.Pipeline._GetPrincipalIdentifier(String principal String desiredIdentifier)
   at Microsoft.DigitalRightsManagement.Certification.Pipeline._ProcessEmailAddress(IDrmsPropertyBag propertyBag CaType caType String& emailAddress Identification identification)
   at Microsoft.DigitalRightsManagement.Certification.Pipeline.Certify(CaType caType CertifyParams[] requestParams HttpRequest request IIdentity userIdentity)

For more information see Help and Support Center at http://go.microsoft.com/fwlink/events.asp.
Data:
0000: 7b 30 35 33 31 39 66 35   {05319f5
0008: 62 2d 65 37 34 36 2d 34   b-e746-4
0010: 37 31 32 2d 38 38 37 64   712-887d
0018: 2d 65 36 33 32 37 66 62   -e6327fb
0020: 63 66 63 32 36 7d 2e 31   cfc26}.1
0028: 32                        2      

Comment:
Event ID: 53
Event Source: k-Store Exception
Event Type: Error
Event Description: ) Exception Information
*********************************************
Exception Type: System.NullReferenceException
Message: Object reference not set to an instance of an object.
TargetSite: Int32 GetFavouriteCount(System.String System.String System.String)
HelpLink: NULL
Source: KStore.Services

Comment:
Event ID: 53
Event Source: SAVOnAccessFilter
Event Type: Error
Event Description: The on-access driver failed to attach to \Device\ADVirtualDisk\Volume because the IO method is not supported.
Comment: Sophos antivirus generated error.

Windows Event Log Analysis Splunk App

Build a great reporting interface using Splunk, one of the leaders in the Security Information and Event Management (SIEM) field, linking the collected Windows events to www.eventid.net.

Read more...

 

Cisco ASA Log Analyzer Splunk App

Obtain enhanced visibility into Cisco ASA firewall logs using the free Firegen for Cisco ASA Splunk App. Take advantage of dashboards built to optimize the threat analysis process.

Read more...