Build a great reporting interface using Splunk, one of the leaders in the Security Information and Event Management (SIEM) field, linking the collected Windows events to www.eventid.net. The EventId.Net for Splunk Add-on assumes that Splunk is collecting information from Windows servers and workstation via the Splunk Universal Forwarder.
|Source: Remote Assistance|
RA: A XML parsing error for (local user) <user name> occurred when attempting to process a remote assistance ticket.
|English: Request a translation of the event description in plain English.|
This event is logged when you end a Remote Assistance session from a Systems Management Server 2003 Administrator console on a computer that has Internet Explorer 7 installed. See ME940181 for additional information about this event.
When using Remote Assistance, a local user called HelpAssistant is needed on the novice machine. If this user has been removed, start Windows in safe mode and enter sessmgr.exe -service in the run command. This will recreate the HelpAssistant user and allow you to offer remote assistance.
This event is informaional, however, it contains an error description. In my case, this event was generated on an "Expert" computer and event 5252 on a "Novice" computer. See the comments for Event ID 5252.
|Private comment: Subscribers only. See example of private comment|
|Links: ME940181, Event ID 5252 from source Remote Assistance|
|Search: Google - Bing - Microsoft - Yahoo - EventID.Net Queue (0) - More links...|
Send comments or solutions
- Notify me when updated