Monitor unlimited number of servers
Filter log events
Create email and web-based reports

Direct access to Microsoft articles
Customized keywords for major search engines
Access to premium content

Event ID: 1001 Source: SBCore

The server was shut down because it did not comply with the EULA.
We experienced this event while migrating from SBS2003 to full server setup (seperate DC and Exchange) Once the FSMO roles have been transferred away from the SBS to a dedicated DC, the event will trigger and the server will shut down after a couple of hours. You can restart the server and work for another couple of hours.
From ME555087: "This issue can occur if the Windows 2003 Small Business Server integrated setup was not completed.  Windows 2003 Small Business Server must be a domain controller and hold all FSMO roles for the domain.  In order to facilitate migration from an existing domain, the Small Business Server can function for 7 days after installing without being promoted to a domain controller.  After that time, the Small Business Server must be promoted to a domain controller using the integrated setup.  If the integrated setup is not completed, the SBCore service will initiate a shut down of the server".

See "EventID 1012 from source SBCore" and MSW2KDB for additional information.
See ME925652 for information about this event.
On my system the integrated SBS setup has not yet been completed. After 1 week in which you will find event 1013 every 4 hours in the system log, you'll first get event 1014 with the message that the server will be shut down in 60 minutes, half hour another one, that the server will shut down in 30 minutes, finally the 1001 event telling you that the server will shut down because it did not comply to the EULA. This happens when only the first part of the setup has been completed in which the Windows 2003 server is installed. It has not yet been made a Domain Controller, which will happen automatically when the integrated setup is completely finished.

Windows Event Log Analysis Splunk App

Build a great reporting interface using Splunk, one of the leaders in the Security Information and Event Management (SIEM) field, linking the collected Windows events to



Cisco ASA Log Analyzer Splunk App

Obtain enhanced visibility into Cisco ASA firewall logs using the free Firegen for Cisco ASA Splunk App. Take advantage of dashboards built to optimize the threat analysis process.