Monitor unlimited number of servers
Filter log events
Create email and web-based reports

Direct access to Microsoft articles
Customized keywords for major search engines
Access to premium content

Event ID: 3051 Source: NETLOGON

Source
Level
Description
The Registry or the information you just typed includes an illegal value for "SysVol".
Comments
 
From Microsoft:
SYMPTOMS
After you upgrade a domain controller to Windows 2000, run Dcpromo.exe, and then reboot the computer, the following events may be logged in the System log:
   Warning: Netlogon
   Event 3051: The registry or the information you just typed includes an illegal value for "DBFlag".
   Event 3051: The registry or the information you just typed includes an illegal value for "SysVol".
   Event 3051: The registry or the information you just typed includes an illegal value for "DynamicSiteName".
   Error: Netlogon Event 5706: Netlogon could not create share c:\winnt\system32\repl\import\scripts. The following error occurred: The System could not find the path specified.
  Error Netlogon Event 5706: The Netlogon service could not create server share. The following error occurred: The filename, directory name, or volume label syntax is incorrect.

CAUSE
These error messages can occur if entries under the following registry key on the domain controller are missing or incorrect:
   KEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\Netlogon\Parameters

RESOLUTION
To restore the Netlogon service to working order and prevent additional error messages:
1. Stop the Netlogon service by typing "net stop netlogon" (without the quotation marks) at a command prompt.
2. Start Registry Editor (Regedt32.exe).
3. Locate the following key in the registry:
   HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\Netlogon\Parameters
4. Adding registry values.
   NOTE: If you get the error message:
   Registry Editor could not create the value entry; the value entry already exists. Please enter a new name. This indicates that the entries may already exist but not be visible.
Open regedit.exe and view
   HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\Netlogon\Parameters
   If you see all of the entries, delete the SysVol entry and continue with step 4 and re-create only the SysVol entry in regedt32.exe.
   On the Edit menu, click Add Value, and then add the following registry values:
   Value Name: DBFlag
   Data Type: REG_SZ
   Value: 0
   Value Name: DynamicSiteName
   Data Type: REG_SZ
   Value: <YourSiteName>
   Value Name: SysVol
   Data Type: REG_SZ
   Value: <Path_to_sysvol> (By default, this value is set to C:\WINNT\SYSVOL\sysvol)
5. Quit Registry Editor.
6. Restart the Netlogon service by typing "net start netlogon" (without the quotation marks).
NOTE: If there is another domain controller in the domain, you can save the Parameters key from that domain controller and restore it to the problem domain controller, making corrections if necessary.

Windows Event Log Analysis Splunk App

Build a great reporting interface using Splunk, one of the leaders in the Security Information and Event Management (SIEM) field, linking the collected Windows events to www.eventid.net.

Read more...

 

Cisco ASA Log Analyzer Splunk App

Obtain enhanced visibility into Cisco ASA firewall logs using the free Firegen for Cisco ASA Splunk App. Take advantage of dashboards built to optimize the threat analysis process.

Read more...