Monitor unlimited number of servers
Filter log events
Create email and web-based reports

Direct access to Microsoft articles
Customized keywords for major search engines
Access to premium content

Event ID: 1008 Source: winlogon

Source
Level
Description
The Enterprise Root Certificate store could not be updated. (<error code>)
Comments
 
This event, along with EventID 1009 from the same source, is also generated in W2K servers that are not domain members but are in a workgroup with the same name as the domain. Changing the workgroup name solves the problem.
After solving an issue with LicenseService (EventID 213), I was getting this event and EventID 1009 (same source). I re-applied the GPO manually which seemed to resolve the above errors.

On Windows 2000:
SECEDIT /REFRESHPOLICY MACHINE_POLICY /ENFORCE
SECEDIT /REFRESHPOLICY USER_POLICY /ENFORCE

On Windows 2003:
gpupdate /force.

After this, reboot the machine and the problem should be solved.
From a newsgroup post: "The 1008 errors are not the problem, they are the messenger. However, these errors are indicative that there are clock cycles being stolen by these items. There is a specific Perflib error that follows on the installation of SBS 2000. You resolve it quite simply with a command explained in the SBS readme doc which from the top of my head is:

c:\winnt.sbs\system32>lodctr c:\exchsrvr\bin\eseperf.ini

That means you must execute that command from that directory in order for this to solve the problem regarding this specific issue on this counter, assuming the other paths are correct.  BTW, this comes from the SBS readme doc."

Error code 0x80070051 = - no additional info
Error code 0x80070057 = E_INVALIDARG = "One or more arguments are not valid error." - no additional info

Windows Event Log Analysis Splunk App

Build a great reporting interface using Splunk, one of the leaders in the Security Information and Event Management (SIEM) field, linking the collected Windows events to www.eventid.net.

Read more...

 

Cisco ASA Log Analyzer Splunk App

Obtain enhanced visibility into Cisco ASA firewall logs using the free Firegen for Cisco ASA Splunk App. Take advantage of dashboards built to optimize the threat analysis process.

Read more...