Monitor unlimited number of servers
Filter log events
Create email and web-based reports

Direct access to Microsoft articles
Customized keywords for major search engines
Access to premium content

Event ID: 1000 Source: Userenv

The logged on user's forest is different from the machine's forest. Cross Forest Group Policy processing is disabled and loopback processing has been enforced in this forest for this user account.
I have W2K clients that log on locally, and then connect via ADSL to Citrix on W2K SP4. This entry appears in the Citrix server event log. Apparently, Win2k SP4 and 2003 Server include a new GPO setting: “Computer Configuration\Administrative Templates\System\Group Policy\Allow Cross-Forest User Policy and Roaming Profiles”. This is disabled by default, and should be enabled if you have cross-forest trusts for policies and login scripts. See ME823862 for more details. Similar entries can be caused by "disjointed namespace" following server promotion to a domain controller. See ME257623 for more details.

Windows Event Log Analysis Splunk App

Build a great reporting interface using Splunk, one of the leaders in the Security Information and Event Management (SIEM) field, linking the collected Windows events to



Cisco ASA Log Analyzer Splunk App

Obtain enhanced visibility into Cisco ASA firewall logs using the free Firegen for Cisco ASA Splunk App. Take advantage of dashboards built to optimize the threat analysis process.