Monitor unlimited number of servers
Filter log events
Create email and web-based reports

Direct access to Microsoft articles
Customized keywords for major search engines
Access to premium content

Event ID: 52 Source: WinMgmt

Source
Level
Description
WMI ADAP was unable to create the object Win32_PerfRawData_McShield_NetShield for Performance Library McShield because of an invalid property type at index 2291
Comments
 
Here is the solution that worked for us. Clear the Application Event log in Windows 2000. Open Windows Explorer, Open up a directory, containing files, on each hard drive letter. This will allow Netshield to attempt to scan each file access on the various drives. Open the Application Event log and match up the files and directories that have the event id 52 to the drive that contains them.  Once you have determined on which drives this is occuring then go to the Windows 2000 disk management console. Within the disk management console look to see if those drives are marked as dynamic under the disk number (i.e. Disk 0, Disk 1). If the disk is marked as dynamic and the partitions within it are marked as simple then right click on the disk number and click on revert to basic. If this option is greyed out try rebooting and if this option is still greyed out you will have to delete your partitions on that disk. Once your disk number is converted to basic this error goes away. Clear the Application event log and reboot.

Windows Event Log Analysis Splunk App

Build a great reporting interface using Splunk, one of the leaders in the Security Information and Event Management (SIEM) field, linking the collected Windows events to www.eventid.net.

Read more...

 

Cisco ASA Log Analyzer Splunk App

Obtain enhanced visibility into Cisco ASA firewall logs using the free Firegen for Cisco ASA Splunk App. Take advantage of dashboards built to optimize the threat analysis process.

Read more...