Build a great reporting interface using Splunk, one of the leaders in the Security Information and Event Management (SIEM) field, linking the collected Windows events to www.eventid.net. The EventId.Net for Splunk Add-on assumes that Splunk is collecting information from Windows servers and workstation via the Splunk Universal Forwarder.
|Source: NTDS General|
System Monitor was unable to open Active Directory performance counters. An attempt to query the following performance counter registry key failed.
2 The system cannot find the file specified.
|English: Request a translation of the event description in plain English.|
From a newsgroup post: "To reload the NTDS extensible counter (one that is not installed by default on a Windows 2000 installation, since NTDS is installed during promotion to a DC) perform the following steps:
1. Open a command prompt window.
2. At the command prompt, enter "cd %Systemroot%\System32"
3. Enter the following line: "lodctr ntdsctrs.ini"
Refer to KB article ME300956 for this and more info on rebuilding performance counters".
Verify that the registry key exists.
|Private comment: Subscribers only. See example of private comment|
|Search: Google - Bing - Microsoft - Yahoo - EventID.Net Queue (0) - More links...|
Send comments or solutions
- Notify me when updated