Build a great reporting interface using Splunk, one of the leaders in the Security Information and Event Management (SIEM) field, linking the collected Windows events to www.eventid.net. The EventId.Net for Splunk Add-on assumes that Splunk is collecting information from Windows servers and workstation via the Splunk Universal Forwarder.
wuauclt (4004) An attempt to move the file "C:\WINDOWS\SoftwareDistribution\DataStore\Logs\res1.log" to "C:\WINDOWS\SoftwareDistribution\DataStore\Logs\edbtmp.log" failed with system error 2 (0x00000002): "The system cannot find the file specified. ". The move file operation will fail with error -1811 (0xfffff8ed).
|English: Request a translation of the event description in plain English.|
|Concepts to understand:|
What is the role of ESENT?
Various error codes/descriptions can be recorded with this event. The troubleshooting should be based on those specific errors. Recorded error codes:
- 2 = The system cannot find the file specified.
- 183 = Cannot create a file when that file already exists.
Some support forums relate this event to failed installations of Windows updates, in many cases caused by a malware infection. The suggested remedy was to install an antivirus or otherwise remove the offending programs. After that the updates worked fine and the error dissapeared.
Can be related to event IDs 413, 428, 429 and 482 (related to low disk space or file corruption).
|Private comment: Subscribers only. See example of private comment|
|Links: Error code 2, Error code 183|
|Search: Google - Bing - Microsoft - Yahoo - EventID.Net Queue (1) - More links...|
|Custom search for *****: Google - Bing - Microsoft - Yahoo|
Send comments or solutions
- Notify me when updated