Build a great reporting interface using Splunk, one of the leaders in the Security Information and Event Management (SIEM) field, linking the collected Windows events to www.eventid.net. The EventId.Net for Splunk Add-on assumes that Splunk is collecting information from Windows servers and workstation via the Splunk Universal Forwarder.
The Workstation service has not been started.
|English: Request a translation of the event description in plain English.|
|Concepts to understand:|
What is the role of Workstation Service?
What is the role of the Netlogon share?
See the link to "EventID 2138 from source System" for information about this event.
This event take place if the dependencies of Netlogon service are not set correctly, i.e. Netlogon doesn’t depend on Workstation service. To correct it, I have followed the next steps:
1. Start Registry Editor (Regedt32.exe).
2. Locate and then click the "DependOnService" value under the following key in the registry: "HKEY_LOCAL_MACHINE\System\CurrentControlSet\Services\Netlogon"
3. On the Edit menu, click Multi String, add line "LanmanWorkstation", and then click OK.
4. Quit Registry Editor.
|Private comment: Subscribers only. See example of private comment|
|Links: EventID 2138 from source System|
|Search: Google - Bing - Microsoft - Yahoo - EventID.Net Queue (0) - More links...|
Send comments or solutions
- Notify me when updated