Monitor unlimited number of servers
Filter log events
Create email and web-based reports

Direct access to Microsoft articles
Customized keywords for major search engines
Access to premium content

Event ID: 4006 Source: Winlogon

Source
Level
Description
The Windows logon process has failed to spawn a user application. Application name: . Command line parameters: c:\windows\system32\userinit.exe.
Comments
 
See the "Vista or Server2008 stuck at a black screen and the desktop never renders" blog entry for some details about this problem. You can solve this by adding the NT Authority\Interactive in the local users group on Windows 2008.
One newsgroup post claims that the cause appears to be related to User Account Control (UAC). The suggested workaround is to disable UAC. This solution did work for me but I prefer to use UAC.
This issue occurs if the Userinit key in the Windows registry has been modified. For example, this issue may occur if the Userinit key has a value but no binary data. See ME929825 to solve this problem.

Windows Event Log Analysis Splunk App

Build a great reporting interface using Splunk, one of the leaders in the Security Information and Event Management (SIEM) field, linking the collected Windows events to www.eventid.net.

Read more...

 

Cisco ASA Log Analyzer Splunk App

Obtain enhanced visibility into Cisco ASA firewall logs using the free Firegen for Cisco ASA Splunk App. Take advantage of dashboards built to optimize the threat analysis process.

Read more...