Monitor unlimited number of servers
Filter log events
Create email and web-based reports

Direct access to Microsoft articles
Customized keywords for major search engines
Access to premium content

Event ID: 54 Source: WMI

Source
Level
Description
The description for Event ID (54) in Source ( WMI ) cannot be found.  The local computer may not have the necessary registry information or message DLL files to display messages from a remote computer.  The folloing information is part of the event: \Device\WMIService Device
Comments
 
The event description should read:
"An Io Request to the device \Device\WMIService Device did not complete or canceled within the specific timeout. This can occur if the device driver does not set a cancel routine for a given IO request packet."

Look for various comments for other similar events. See the comments for event id 54 from AMBRIMCL.
Symptom - Windows 2000 takes a long time to load after logging in. Seem to hang at the Loading your setting screen. Disabling the WMI driver service seems to fix the problem, not sure if this may cause another problem.

Windows Event Log Analysis Splunk App

Build a great reporting interface using Splunk, one of the leaders in the Security Information and Event Management (SIEM) field, linking the collected Windows events to www.eventid.net.

Read more...

 

Cisco ASA Log Analyzer Splunk App

Obtain enhanced visibility into Cisco ASA firewall logs using the free Firegen for Cisco ASA Splunk App. Take advantage of dashboards built to optimize the threat analysis process.

Read more...