AD Failed Logon Critical Notification for Data Insertion

Overview

The customer reported receiving critical notifications related to data insertion failures in the Active Directory (AD) module.

Environment Details

  • Lepide version installed: 24.4

Observations

  • AD auditing logs indicated “Data insertion failed” errors.

  • Error details pointed to the Failed Logon folder (AD_GP_TYPE5_2).

  • The AD_GP_TYPE5_2 folder contained a large volume of unprocessed logs.

  • These logs were outdated, indicating a backlog issue.

Troubleshooting Steps Performed

  • Stopped all Lepide services.

  • Moved the Failed Logon (AD_GP_TYPE5_2) folder to a different location to clear backlog.

  • Reinstalled agents on all Domain Controllers.

  • Performed a test change in Active Directory (updated description of a test user).

Results

  • Data insertion started working successfully.

  • Reports began generating without any issues.

  • No further critical notifications were received by the customer.

Recommendations Provided to Customer

  • Investigate the root cause of excessive failed logon events in the environment.

  • Temporarily disabled the “Audit Failed Logon” option under Object Classes and other AD settings to prevent log overflow.

  • Once the failed logon issue is resolved:

    • Re-enable Audit Failed Logon.

    • Monitor the solution behavior to ensure stability.

Conclusion

The issue was caused by a backlog of unprocessed failed logon logs, which disrupted data insertion. Clearing the backlog and reinstalling agents resolved the issue. Preventive steps were recommended to avoid recurrence.