Monitor unlimited number of servers
Filter log events
Create email and web-based reports

Direct access to Microsoft articles
Customized keywords for major search engines
Access to premium content

Event ID: 1000 Source: Userenv

Windows cannot query DllName registry entry for {GUID}.
There should be few reasons for this event:
1. Wrong permissions on the SYSVOL folder/share. Check permissions according to ME290647.
2. Registry entry for GPO_GUID is missing in registry. In this case, verify in the registry editor if the registry entry is valid for this GPO. All entries are located in HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon\GPExtensions\{GPO_GUID}. Here there must be an entry DllName with a correct value. If it is not, create it.
Here you can find a list of few valid GPO registry names with valid DLLs:

Registry - Userenv.dll
Disk_Quota - Dskquota.dll
Folder_Redirection - Fdeploy.dll
Scripts - Gptext.dll
Software_Installation - Appmgmts.dll
Security - Scecli.dll
IP_Security - Gptext.dll
EFS_Recovery - Scecli.dll
Internet_Explorer_Maintenance - iedkcs32.dll.

Windows Event Log Analysis Splunk App

Build a great reporting interface using Splunk, one of the leaders in the Security Information and Event Management (SIEM) field, linking the collected Windows events to



Cisco ASA Log Analyzer Splunk App

Obtain enhanced visibility into Cisco ASA firewall logs using the free Firegen for Cisco ASA Splunk App. Take advantage of dashboards built to optimize the threat analysis process.