A Security Information and Event Management (SIEM) solution designed to enhance the security of critical systems, ensure confident compliance and improve overall performance and availability.

 

ABOUT EVENTTRACKER KB

What is EventTracker KB?

A systematic, searchable collection of information relating to events generated from Windows, syslog and SNMP sources. Since 2002, Prism Microsystems has been engaged in a serious, committed long term effort to collate and catalog information from disparate sources in a searchable database. At present, EventTracker KB represents the largest and most comprehensive collection of information of this kind anywhere on the Internet.

Why is this useful?

A common first step in diagnosing system problems in the modern backoffice, is to identify events emitted by the system(s) in question and examining them for clues to resolution. However, event descriptions are often cryptic and provide little help to the System Administrator. EventTracker KB has been designed to help by gathering all available information on events including a verbose description, resolution information and links to helpful articles and other knowledgebases from vendors.

How can one search the database?

You have to know something, anything about the event. A portion of the description, the event id or the event source.

Who is responsible for this database?

Prism Microsystems, the vendor of EventTracker has been engaged in the compilation and propagation of this site and underlying database. Access to the EventTracker KB database is tightly integrated into EventTracker as an important element of the products promise of "Complete Event Management".

Is there a fee for this service?

At the present time, access to the site requires a free registration.

I don't see info about <event>. Can you help me?

Sure - just ask. Want our experts to research a particular event? Drop us a line at eventtracker-kb@prismmicrosys.com.

How can I contribute to this database?

Know more about a certain event? Want to share your experience with it? Tell us - click on the Share Your Knowledge link. All contributions are reviewed by our staff and used with attribution.

I like/hate it - who do I tell?

Tell us, we welcome your comments.
Bouqets to eventtracker-kb@prismmicrosys.com
Brickbats to /dev/null.
Tell a friend, spread the word.
Bookmark us.

Event Source

KDC

Event ID

11

Category ID

Description

There are multiple accounts with name host/SERVERNAME.microsoft.com of type10

Event Information

CAUSE: This behavior can be caused by a duplicate SPN (ServicePrincipalName) value in the Active Directory tree.
RESOLUTION: NOTE: Only experienced administrators should consider using the Ldp.exe and Adsiedit.msc tools that are called for in the following procedure.
To resolve this behavior, use the Ldp.exe tool to determine the location of the duplicate SPN value, and then use the Adsiedit.msc tool to remove the duplicate SPN value. Follow these steps on a Windows 2000-based domain controller:
Click Start, and then click Run.
Type ldp, and then click OK.
Click Connection, click Connect, and then click OK. Leave the Server box blank.
Click Connection, click Bind, and then click OK. Leave all fields blank.
Click View, click Tree, and then click OK. Leave the BaseDN window blank.
Click Browse, and then click Search.
Set the BaseDN as DC=Home and DC=com, separated by a comma. For example, if the FQDN name of the domain is Mydomain.com, type DC=Mydomain,DC=com.
Set the filter to the following:
serviceprincipalname=Host/computername.home.com
For example, if the relevant computer is named Computer1 and the domain name is Mydomain.com, type the following:
serviceprincipalname=Host/Computer1.Mydomain.com
Set Scope to Subtree, and then click Run.
After you locate the duplicate SPN, you can use the Adsiedit.msc tool to go to the object, view the duplicate SPN value, and remove the duplicate SPN value.
Move the server from the domain to a workgroup, delete the servers computer account from the domain, and then join the server to the domain again, using the same computer account.

Reference Links

Windows 2000 Server Prompts Domain User for Credentials  

EventTracker: Centralized Event Log Analysis, Archiving, Reporting and Alerting for NT, XP, 2000, Unix, SNMP