Build a great reporting interface using Splunk, one of the leaders in the Security Information and Event Management (SIEM) field, linking the collected Windows events to www.eventid.net. The EventId.Net for Splunk Add-on assumes that Splunk is collecting information from Windows servers and workstation via the Splunk Universal Forwarder.
|Source: Application Popup|
lsass.exe - System Error : Security Accounts Manager initialization failed because of the following error: Directory Service cannot start. Error Status: 0xc00002e1. Please click OK to shutdown this system and reboot into Directory Services Restore Mode, check the event log for more detailed information.
|English: Request a translation of the event description in plain English.|
|Concepts to understand:|
What is the LSA?
What is a directory service?
This behavior can occur because the computer name of Internet is a restricted Windows 2000 computer name and cannot be used by a domain controller, a member server, or a Microsoft Windows 2000 Professional-based client that is a member of a Windows 2000 domain. See ME273875 for details.
This issue can occur if the path to the NTDS folder that holds the Active Directory database files and log files does not exist or the NTFS permissions on this folder and database files are too restrictive, and Active Directory cannot start. See ME258007 and ME295932 for more details. Also check Event id 26 from source Program Popup.
|Private comment: Subscribers only. See example of private comment|
|Links: ME258007, ME273875, ME295932, Event id 26 from source Program Popup|
|Search: Google - Bing - Microsoft - Yahoo - EventID.Net Queue (0) - More links...|
Send comments or solutions
- Notify me when updated