Monitor unlimited number of servers
Filter log events
Create email and web-based reports

Direct access to Microsoft articles
Customized keywords for major search engines
Access to premium content

Event ID: 4 Source: Microsoft-Windows-SpoolerWin32SPL

Level
Description
The print spooler failed to reopen an existing printer connection because it could not read the configuration information from the registry key S-1-5-18\Printers\Connections. The print spooler could not open the registry key. This can occur if the registry key is corrupt or missing, or if the registry recently became unavailable.
Comments
 
I had this problem on my notebook running Vista. Two warnings were logged in the system event log every 5 seconds. I ran "regedit" and added the missing key (an empty "(default)" variable type REG_SZ). Other HKEY_USERS\S-1-5-??\Printers directories had such keys. This stopped the logging of these warnings and I have not seen any side effects.

Windows Event Log Analysis Splunk App

Build a great reporting interface using Splunk, one of the leaders in the Security Information and Event Management (SIEM) field, linking the collected Windows events to www.eventid.net.

Read more...

 

Cisco ASA Log Analyzer Splunk App

Obtain enhanced visibility into Cisco ASA firewall logs using the free Firegen for Cisco ASA Splunk App. Take advantage of dashboards built to optimize the threat analysis process.

Read more...