Monitor unlimited number of servers
Filter log events
Create email and web-based reports

Direct access to Microsoft articles
Customized keywords for major search engines
Access to premium content

Event ID: 1511 Source: Userenv

Source
Level
Description
Windows cannot find the local profile and is logging you on with a temporary profile. Changes you make to this profile will be lost when you log off.
Comments
 
Before trying MS Fixes run a chkdsk /f against the machine. Most of times it solves the issue if the profile went bad due to a dirty shutdown.
Restore folder "Default" (c:\user\default) (in my case I copied the folder from another computer).
Ensure that the paths are correct in:

HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\ProfileList

or (if the problem is with an existing user account, not a new one)

HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\ProfileList\<SID>

For more information see ME947215.
This issue occurs because the NTUser.dat file is not released successfully after the file is loaded under the HKEY_USERS\<SID> registry key. See ME941339 for information on solving this problem.
If the user's profile has become corrupted then see ME318011 for details on fixing this problem.


Windows Event Log Analysis Splunk App

Build a great reporting interface using Splunk, one of the leaders in the Security Information and Event Management (SIEM) field, linking the collected Windows events to www.eventid.net.

Read more...

 

Cisco ASA Log Analyzer Splunk App

Obtain enhanced visibility into Cisco ASA firewall logs using the free Firegen for Cisco ASA Splunk App. Take advantage of dashboards built to optimize the threat analysis process.

Read more...