Monitor unlimited number of servers
Filter log events
Create email and web-based reports

Direct access to Microsoft articles
Customized keywords for major search engines
Access to premium content

Event ID: 100

Source
AASecurityMonitor
Level
Error
Description
Object: <object>
Number: <number>
Message: <message>.
Source
ab
Level
Error
Description
The service failed to shutdown correctly due to subprocess being unable to be killed. Error code: <error code>.
Source
ACCPAC
Level
Error
Description
DBSCONN.C 143 log buffer overflow.
Source
Adiscon EvntSLog
Level
Information
Description
The Adiscon EvntSLog service was installed.
Source
AdisconMoniLog
Level
Information
Description
The AdisconMoniLog service was installed.
Source
AVG7
Level
Error
Description
<date> <time> <computer> [001456:001620] FATAL 000 AVG7.AM.WSC.CServiceModule unhandled exception caught (299 Wed Sep 22 00:51:41 2004).
Source
Backup Exec System Recovery
Level
Error
Description
Error <error code>: <error message>.
Source
Bonjour Service
Level
Error
Description
576: ERROR: read_msg errno 10054 (An existing connection was forcibly closed by the remote host.)
Source
CertSvc
Level
Error
Description
Certificate Services did not start: Could not load or verify the current CA certificate. Enterprise-Sub The revocation function was unable to check revocation because the revocation server was offline.
Source
ConnectPro
Level
Warning
Description
JVM did not exit on request terminated
Source
CVHSVC
Level
Warning
Description
Information only. The action cannot be completed. Try the action again. If the problem continues contact Microsoft Product Support.
Source
DAVEX
Level
Success Audit
Description
DAVEX has successfully started. Version: <version>.
Source
DeploymentAgent
Level
Warning
Description
The description for Event ID ( 100 ) in Source ( DeploymentAgent ) cannot be found. The local computer may not have the necessary registry information or message DLL files to display messages from a remote computer. You may be able to use the /AUXSOURCE= flag to retrieve this description; see Help and Support for details. The following information is part of the event: Thu May 08 12:01:44 2008 WARN Error performing antigen dataset query; (14DC) Error 0x80080005 creating Statistics Service instance..
Source
drvmanager
Level
Error
Description
The service failed to shutdown correctly due to subprocess being unable to be killed. Error code: <error code>.
Source
emcmpio
Level
Error
Description
Path Bus 4 Tgt 1 Lun 4 to APM00053901234 is dead.
Source
EmcpBase
Level
Error
Description
Path Bus 4 Tgt 3 Lun 0 to APM00035002116 is dead.
Source
EmcpMpx
Level
Error
Description
Path Bus 3 Tgt 0 Lun 257 to 000190102478 is dead.
Source
ESE
Level
Information
Description
<process name> (<process id>) The database engine <version> started.
Source
ESE97
Level
Information
Description
MSExchangeIS <process id> The database engine <version> started.
Source
ESE98
Level
Information
Description
<process name> (<process id>) The database engine <version> started.
Source
ESENT
Level
Information
Description
<service> (892) The database engine 6.00.3940.0004 started.
Source
Exchange availability
Level
Error
Description
Store <mailbox store name> is not available.
Source
Exchsync
Level
Information
Description
The Exchange Replication Service has started.
Source
File System Auditor
Level
Error
Description
The description for Event ID ( 100 ) in Source ( File System Auditor ) cannot be found. The local computer may not have the necessary registry information or message DLL files to display messages from a remote computer. You may be able to use the /AUXSOURCE= flag to retrieve this description see Help and Support for details. The following information is part of the event: Unable to open the database.
[DBNETLIB][ConnectionOpen (Connect()).]SQL Server does not exist or access denied.
Error = -2147467259.
Source
FileSize
Level
Warning
Description
Generate Alert if tmp*.log size is more than 100 MB.
Source
FSCStatsServ
Level
Error
Description
The description for Event ID ( 100 ) in Source ( FSCStatsServ ) cannot be found. The local computer may not have the necessary registry information or message DLL files to display messages from a remote computer. You may be able to use the /AUXSOURCE= flag to retrieve this description; see Help and Support for details. The following information is part of the event: Thu May 08 12:01:44 2008 ERROR StatisticsInitializeEx returns: -1.
Source
HP Command View EVA
Level
Information
Description
INFO: User administrator successfully logged on.
Source
InterScan MSS Monitor
Level
Error
Description
InterScan MSS Monitor is sending out a notification. Reason: InterScan MSS scheduled update status.

or

Errors occurred when InterScan MSS Monitor was trying to send mail notification. Error code = -14.
Source
ISServ
Level
Error
Description
The description for Event ID ( 100 ) in Source ( ISServ ) cannot be found. The local computer may not have the necessary registry information or message DLL files to display messages from a remote computer. The following information is part of the event: subprocess being unable to be killed 5.
Source
LiveState Recovery
Level
Warning
Description
Cannot register GH78G0J with service principal name of LiveState Recovery Agent 3.0. Details: The specified domain either does not exist or could not be contacted.
Source
lsass
Level
Error
Description
The description for Event ID ( 100 ) in Source ( lsass ) cannot be found. The local computer may not have the necessary registry information or message DLL files to display messages from a remote computer. The following information is part of the event: subprocess being unable to be killed 5.
Source
Microsoft-Windows-CertificationAuthority
Level
Error
Description
Active Directory Certificate Services did not start: Could not load or verify the current CA certificate. Object was not found. 0x80090011 (-2146893807).
Source
Microsoft-Windows-Diagnostics-Performance
Level
Critical
Description
Windows has started up:
Boot Duration : 130912ms
IsDegradation : false
Incident Time (UTC) : 2/6/2010 3:14:41 AM.
Source
MSExchangeMTA
Level
Error
Description
A fatal MTA database server error was encountered. The MTA work queue could not be created. Internal database error: 2109. [MTA DISP:ROUTER 10 118] (16).
Source
MSFTPSVC
Level
Warning
Description
The server was unable to logon the Windows NT account 'anonymous@ftp.microsoft.com' due to the following error: <error description> The data is the error code.
Source
MSSQLServerADHelper
Level
Error
Description
"0" is an invalid number of start up parameters. This service takes two start up parameters.
Source
MySQL
Level
Warning
Description
Changed limits: max_open_files: <value>  max_connections: <value>  table_cache: <value>.
Source
MySQL
Level
Error
Description
Aborting

For more information, see Help and Support Center at http://www.mysql.com.
Source
MySQL
Level
Error
Description
Do you already have another mysqld server running on port: 3306 ?

For more information, see Help and Support Center at http://www.mysql.com.
Source
MySQL
Level
Warning
Description
MySQL: Forcing close of thread 28 user: 'root'

For more information, see Help and Support Center at http://www.mysql.com.
Source
NetBackup GDM VISD
Level
Error
Description
The description for Event ID ( 100 ) in Source ( NetBackup GDM VISD ) cannot be found. The local computer may not have the necessary registry information or message DLL files to display messages from a remote computer. The following information is part of the event: 0630:180051 ERROR: Unable to Create PID File: C:\Program Files\VERITAS\NetBackup\\Temp\visd_pid.
Source
NNTPSVC
Level
Error
Description
The server was unable to logon the Windows NT account "IUSR_EXCHANGE01" due to the following error: Logon faulure: unknown user name or bad password. The data is the error code.
Source
Norton Ghost
Level
Error
Description
Error EC8F1780: Cannot successfully reconcile changes since last session.
Error EC8F1772: The following component is not installed correctly: Symantec.Imaging.Imager.
Error EBAB03F1: Class not registered. (UMI:V-281-3215-6016)

Details:
Source: Norton Ghost
Source
Norton Ghost 9.0
Level
Error
Description
Cannot complete copying of Dell 8200 (C:\) drive. Details: The volume contains system or paging files.
Source
NTDS ISAM
Level
Information
Description
NTDS (328) The database engine 6.00.3940.0025 started.
Source
PortReporter
Level
Information
Description
The Port Reporter service was started.
Source
PortReporter
Level
Information
Description
The Port Reporter service successfully created log files in the following directory: <path of log files>.
Source
PowerQuest V2i Protector 2.0 Server Edition
Level
Error
Description
An error occurred during a scheduled backup of drive C:\. Error EA390719: Target disk full.
Details: 0xEA390719

or

An error occurred creating a backup of drive D:\. Error EBAB001A: An unknown exception has occurred.
Details: 0xEBAB001A

or

Unable to successfully reconcile changes since last session. Unable to enumerate the current drives on this system.
Cannot initialize the Storage Management Engine.
Error E0020002: Device \\.\PhysicalDrive0 cannot be opened. Error 00000020: The process cannot access the file because it is being used by another process. Error E0020002: Device \\.\PhysicalDrive1 cannot be opened. Error 00000020: The process cannot access the file because it is being used by another process.
Details: 0xEBAB0005
Source
PPPOE
Level
Error
Description
Warning: on_message_event; control session map host unique handle mismatch.
or
Warning:Control Dispatcher failed to dispath the handle_close_call_event() call; no matching Session Control found
or
Info: sending Discovery terminate packet, session id: 4.
Source
Reliability Server
Level
Error
Description
An internal server error occurred.
Source
RIM MDNS
Level
Error
Description
708: ERROR: read_msg errno 0 (The operation completed successfully.)
Source
RPC9
Level
Error
Description
The service failed to shutdown correctly due to subprocess being unable to be killed. Error code: <error code>.
Source
Rundll
Level
Error
Description
The service failed to shutdown correctly due to subprocess being unable to be killed. Error code: <error code>.
Source
SchedulerService
Level
Warning
Description
The description for Event ID ( 100 ) in Source ( SchedulerService ) cannot be found. The local computer may not have the necessary registry information or message DLL files to display messages from a remote computer. You may be able to use the /AUXSOURCE= flag to retrieve this description see Help and Support for details. The following information is part of the event: Wed Feb 25 02:58:31 2009 WARN  Job  failed to create the Mcrosoft.SEM.Services.AlertDeployment COM object. The reported error was 0x8007000e "Not enough storage is available to complete this operation."
Source
setup32
Level
Error
Description
The service failed to shutdown correctly due to subprocess being unable to be killed. Error code: <error code>.
Source
SharePoint Products and Technologies
Level
Error
Description
Configuration of SharePoint Products and Technologies failed. Configuration must be performed in order for this product to operate properly. To diagnose the problem, review the extended error information located at <log file>, fix the problem, and run this configuration wizard again.
Source
SmartMenu
Level
Information
Description
Failed to load button7.xml

or

Invalid action path in button7.xml
Source
SMTPSVC
Level
Warning
Description
The server was unable to logon the Windows NT account <account> due to the following error: Logon failure: unknown user name or bad password. The data is the error code.
Source
SNL HiveManager
Level
Warning
Description
The description for Event ID ( 100 ) in Source ( SNL HiveManager ) cannot be found. The local computer may not have the necessary registry information or message DLL files to display messages from a remote computer. You may be able to use the /AUXSOURCE= flag to retrieve this description see Help and Support for details. The following information is part of the event: C:\Program Files\Spybot - Search & Destroy\SpybotSD.exe
Error user loading hive C:\Documents and Settings\Owner\ntuser.dat
The process cannot access the file because it is being used by another process.
Source
SrmAgent
Level
Error
Description
Resource=<-1> Message=<error executing command at server: Connect to "<IP address>" port <port> failed: Connection timed out (WSAETIMEDOUT)>.
Source
StatisticsManagerClient
Level
Error
Description
The description for Event ID ( 100 ) in Source ( StatisticsManagerClient ) cannot be found. The local computer may not have the necessary registry information or message DLL files to display messages from a remote computer. You may be able to use the /AUXSOURCE= flag to retrieve this description; see Help and Support for details. The following information is part of the event: <date> <time> 2620 ERROR ***Exception thrown for classes generated by #import 0x80028019.
Source
StatisticsManagerServer
Level
Error
Description
The description for Event ID ( 100 ) in Source ( StatisticsManagerServer ) cannot be found. The local computer may not have the necessary registry information or message DLL files to display messages from a remote computer. You may be able to use the /AUXSOURCE= flag to retrieve this description; see Help and Support for details. The following information is part of the event: .
Source
stopradmin2
Level
Error
Description
The description for Event ID ( 100 ) in Source ( stopradmin2 ) cannot be found. The local computer may not have the necessary registry information or message DLL files to display messages from a remote computer. The following information is part of the event: subprocess being unable to be killed 5.
Source
svchost
Level
Error
Description
The service failed to shutdown correctly due to subprocess being unable to be killed. Error code: <error code>.
Source
Symantec SymSnap
Level
Information
Description
Info 67B70192: Symantec SymSnap VSS Software Provider Stopped Successfully.
Details:
Source: Symantec SymSnap VSS Software Provider
Source
TWGServer
Level
Error
Description
Application: 'TWGServer (TWGVersion 5.10 2005-10-18 build id 1104)'
Thread Name: TWGServer
Thread Group: ServiceThreadGroup
Exception Type: java.lang.NullPointerException
Stack Trace: java.lang.NullPointerException
at com.ibm.sysmgt.app.mpa.server.MPAExtension.TermBegin(MPAExtension.java:235)
at com.tivoli.twg.engine.TWGExtension.TermBegin(TWGExtension.java:901)
at com.tivoli.twg.engine.TWGExtension.DoTermBegin(TWGExtension.java:717)
at com.tivoli.twg.engine.TWGServer.run(TWGServer.java:885).
Source
vmauthd
Level
Error
Description
HLM took longer than expected. (time:51)
Source
VMware NAT Service
Level
Error
Description
Using configuration file: C:\WINNT\system32\vmnetnat.conf.
IP address: 192.168.192.2
Subnet: 255.255.255.0
External IP address: 0.0.0.0
Device: VMnet8.
MAC address: 00:50:56:C0:59:C4.
Ignoring host MAC address: 00:50:56:C0:00:08.
Source
W3SVC
Level
Warning
Description
The server was unable to logon the Windows NT account '<user name>' due to the following error: <error description>. The data is the error code.
Source
Winlog
Level
Error
Description
The service failed to shutdown correctly due to subprocess being unable to be killed. Error code: <error code>.
Source
WmdmPmSN
Level
Information
Description
The WmdmPmSN service was installed.

Windows Event Log Analysis Splunk App

Build a great reporting interface using Splunk, one of the leaders in the Security Information and Event Management (SIEM) field, linking the collected Windows events to www.eventid.net.

Read more...

 

Cisco ASA Log Analyzer Splunk App

Obtain enhanced visibility into Cisco ASA firewall logs using the free Firegen for Cisco ASA Splunk App. Take advantage of dashboards built to optimize the threat analysis process.

Read more...