Build a great reporting interface using Splunk, one of the leaders in the Security Information and Event Management (SIEM) field, linking the collected Windows events to www.eventid.net. The EventId.Net for Splunk Add-on assumes that Splunk is collecting information from Windows servers and workstation via the Splunk Universal Forwarder.
The Remote Console Server could not grant access to user RConsole Users (1332).
|English: Request a translation of the event description in plain English.|
As a workaround, create a user called "Rconsole Users" (no quotes of course). When the rconsole service is restarted, a system event indicating that the service was started successfully will be logged. For security minded Administrators, you can take the further steps of removing the account from all groups and disabling it. The account just needs to exist for the service to be started; it does not need to be enabled or to belong to any groups. This problem is also referred in Microsoft’s article ME272710.
A user has attempted to use the Rconsole service client to connect to the computer reporting the error but it did not provide the required credentials.
|Private comment: Subscribers only. See example of private comment|
|Search: Google - Bing - Microsoft - Yahoo - EventID.Net Queue (0) - More links...|
Send comments or solutions
- Notify me when updated