Build a great reporting interface using Splunk, one of the leaders in the Security Information and Event Management (SIEM) field, linking the collected Windows events to www.eventid.net. The EventId.Net for Splunk Add-on assumes that Splunk is collecting information from Windows servers and workstation via the Splunk Universal Forwarder.
Failed to create/open file \system32\config\netlogon.ftl with the following error: Access is denied. Data: 0000: 05 00 00 00
|English: Request a translation of the event description in plain English.|
|Concepts to understand:|
What is the role of the Netlogon share?
B.J.A.G. van Bokhoven
This error occurs when the hidden attribute is set on %SYSTEMROOT%\SYSTEM32\CONFIG\netlogon.ftl. So the resolution is removing this hidden attribute by typing the following command at the command prompt:
attrib -h %SYSTEMROOT%\SYSTEM32\CONFIG\netlogon.ftl
There is another reference which deals with security issues which are causing a Citrix XPa server to not list our security domain so we can add entries to published applications. Error is "... can not open Netlogon.ftl. Access denied." See ME310611.
|Private comment: Subscribers only. See example of private comment|
|Search: Google - Bing - Microsoft - Yahoo - EventID.Net Queue (0) - More links...|
Send comments or solutions
- Notify me when updated