Build a great reporting interface using Splunk, one of the leaders in the Security Information and Event Management (SIEM) field, linking the collected Windows events to www.eventid.net. The EventId.Net for Splunk Add-on assumes that Splunk is collecting information from Windows servers and workstation via the Splunk Universal Forwarder.
Invalid user name or password for the <logname> log session. This session will not be started.
|English: Request a translation of the event description in plain English.|
I encountered this event when attempting SQL logging for the performance monitor counters. I was not using the proper Run As user, I had left the default. Microsoft article ME323354 refers to the proper setup of an SQL logging database for performance monitor.
This is a warning generated by the Performance logs and Alerts when the Run As user in counter properties is invalid or does not have the correct rights. However, in my case, this is happening for a user that has local admin and domain admin permissions and is listed in the Performance Log Users group. So the user has full rights to the system but the counter will not start. User name and password have been checked and recheked and this is not an operator error. The only possible solution I have found came from ME918953, but did not solve the problem in my case as the user does have the required permissions.
|Private comment: Subscribers only. See example of private comment|
|Links: ME323354, ME918953|
|Search: Google - Bing - Microsoft - Yahoo - EventID.Net Queue (0) - More links...|
Send comments or solutions
- Notify me when updated