Build a great reporting interface using Splunk, one of the leaders in the Security Information and Event Management (SIEM) field, linking the collected Windows events to www.eventid.net. The EventId.Net for Splunk Add-on assumes that Splunk is collecting information from Windows servers and workstation via the Splunk Universal Forwarder.
The performance counter name string value in the registry is incorrectly formatted. The last valid index value is DWORD 0 in the Record
|English: Request a translation of the event description in plain English.|
|Concepts to understand:|
What is a DWORD?
As per Microsoft: "All performance counter names and explain text are maintained in string tables managed by the performance counter subsystem (Perflib). The current contents of the performance counter string tables are corrupted and cannot be displayed. To correct the problem, rebuild the string tables". See MSW2KDB for additional information about this event.
I received this error along with event id: 2000 and 3009 (source: LoadPerf) and event id: 1476 (source: NTDS General). The source of the problem ended up being with NTDS Performance Counters. Once the procedure in ME300956 was followed and the counters rebuilt, all 4 errors disappeared.
|Private comment: Subscribers only. See example of private comment|
|Links: ME300956, MSW2KDB|
|Search: Google - Bing - Microsoft - Yahoo - EventID.Net Queue (0) - More links...|
Send comments or solutions
- Notify me when updated