Build a great reporting interface using Splunk, one of the leaders in the Security Information and Event Management (SIEM) field, linking the collected Windows events to www.eventid.net. The EventId.Net for Splunk Add-on assumes that Splunk is collecting information from Windows servers and workstation via the Splunk Universal Forwarder.
Session from user "<user>" was timed out and disconnected by the server. The IP address of the Macintosh workstation is in the data.
|English: Request a translation of the event description in plain English.|
As per Microsoft: "A workstation was disconnected from the server. To locate the workstation, convert the specified binary data to a hexadecimal format to resolve the physical address of the workstation. Use the physical address with the ARP command from the command prompt to validate the connection between the client and the server". See MSW2KDB for more details.
|Private comment: Subscribers only. See example of private comment|
|Search: Google - Bing - Microsoft - Yahoo - EventID.Net Queue (0) - More links...|
Send comments or solutions
- Notify me when updated