Monitor unlimited number of servers
Filter log events
Create email and web-based reports

Direct access to Microsoft articles
Customized keywords for major search engines
Access to premium content

Event ID: 1000 Source: Userenv

Failed to access the registry information at \\\SysVol\\Policies\(Guid Number for Policy)\Machine\registry.pol with 53.
See also the information for Error code 53.
I have resolved this problem, deleting the user profile manually in C:\Documents and Settings, and re-booting the account. The only problem was (of course!) the I have lost all my links, and bookmarks of the account that I have deleted, so before to do it back up the profile!
We had this error occur on a server where the user account had expired and the account was logged into a box and the box was locked with this user account. Once we logged the user off the box, reset the account, and logged back into the box, the message disappeared.
As per Microsoft: "A startup script that you created with group policy to be run on a domain controller may not be run when you restart the domain controller. This behavior can occur if there is only one domain controller in the domain. Because scripts are run from the Sysvol share, the Sysvol share must be available. Startup scripts are run very early in the startup process, and if there is only one domain controller, the Sysvol share is not available until the startup process is finished". See ME232300 for more details and a fix for this problem.

Windows Event Log Analysis Splunk App

Build a great reporting interface using Splunk, one of the leaders in the Security Information and Event Management (SIEM) field, linking the collected Windows events to



Cisco ASA Log Analyzer Splunk App

Obtain enhanced visibility into Cisco ASA firewall logs using the free Firegen for Cisco ASA Splunk App. Take advantage of dashboards built to optimize the threat analysis process.