Build a great reporting interface using Splunk, one of the leaders in the Security Information and Event Management (SIEM) field, linking the collected Windows events to www.eventid.net. The EventId.Net for Splunk Add-on assumes that Splunk is collecting information from Windows servers and workstation via the Splunk Universal Forwarder.
|Source: Microsoft-Windows-User Profiles Service|
Windows was unable to load the registry. This problem is often caused by insufficient memory or insufficient security rights. DETAIL - Access denied for C:\Users\TEMP\ntuser.dat
|English: Request a translation of the event description in plain English.|
According to ME960464, this problem occurs because of a race condition in which the Ntuser.dat file of the user cannot be mounted correctly. A hotfix is available to Windows Vista and 2008 however there is a workaround:
To log on to the system by using the user account again, you have to delete the following registry key:
To work around this problem, you have to disable roaming user profiles on the client computer.
|Private comment: Subscribers only. See example of private comment|
|Search: Google - Bing - Microsoft - Yahoo - EventID.Net Queue (0) - More links...|
|Custom search for *****: Google - Bing - Microsoft - Yahoo|
Send comments or solutions
- Notify me when updated