Build a great reporting interface using Splunk, one of the leaders in the Security Information and Event Management (SIEM) field, linking the collected Windows events to www.eventid.net. The EventId.Net for Splunk Add-on assumes that Splunk is collecting information from Windows servers and workstation via the Splunk Universal Forwarder.
A Kerberos Error Message was received:
on logon session InitializeSecurityContext
Server Time: 17:15:47.0000 11/18/2003 Z
Error Code: <error code> <error symbolic name>
Extended Error: 0xc00000bb KLIN(0)
Server Realm: <domain>
Server Name: host/<domain>
Target Name: host/<name>@<domain>
Error Data is in record data.
|English: Request a translation of the event description in plain English.|
See the link for event id 3 from Kerberos, the events are identical.
|Private comment: Subscribers only. See example of private comment|
|Links: Event id 3 from Kerberos|
|Search: Google - Bing - Microsoft - Yahoo - EventID.Net Queue (0) - More links...|
|Custom search for *****: Google - Bing - Microsoft - Yahoo|
Send comments or solutions
- Notify me when updated