Build a great reporting interface using Splunk, one of the leaders in the Security Information and Event Management (SIEM) field, linking the collected Windows events to www.eventid.net. The EventId.Net for Splunk Add-on assumes that Splunk is collecting information from Windows servers and workstation via the Splunk Universal Forwarder.
The attempt to collect OS Performance data failed beause the DLL did not open successfully.
|English: Request a translation of the event description in plain English.|
|Concepts to understand:|
What is a DLL?
What are the performance counters?
1. Check that the dll %windir%\system32\perfnet.dll exists (in my case, the dll’s version was 5.0.2164.1). If it does not exist, try to copy it from a different system.
2. Check that SYSTEM has Full Access.
3. Check that the performance extension DLL is enabled. See ME248993 for details.
In my case, the error was “No Registry-Key HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\PerfNet\Performance\Open”. I created this entry as [REG_SZ] with the value “OpenNetSvcsObject” and the problem was solved.
From Exctrlst-Help: “Open Procedure - The name of the function that is found in the DLL file, which performs the initialization of the performance, functions for this service. This function must be exported by the DLL and return a successful status for the registry to collect performance data from this service. If this function is not found in the DLL or returns an error, the registry will log an error in the system’s Application Event Log”.
|Private comment: Subscribers only. See example of private comment|
|Search: Google - Bing - Microsoft - Yahoo - EventID.Net Queue (0) - More links...|
Send comments or solutions
- Notify me when updated