Build a great reporting interface using Splunk, one of the leaders in the Security Information and Event Management (SIEM) field, linking the collected Windows events to www.eventid.net. The EventId.Net for Splunk Add-on assumes that Splunk is collecting information from Windows servers and workstation via the Splunk Universal Forwarder.
The Event log service was stopped.
|English: Request a translation of the event description in plain English.|
This event can occur when the Windows logon (Winlogon.exe) process does not ignore the Windows logon screen saver time-out. See ME916719 for a hotfix applicable to Microsoft Windows Server 2003.
As per Microsoft: "This event is written during an expected restart or shutdown after the user initiates the restart or shutdown by clicking Start and then clicking Shut Down, or by pressing CTRL+ALT+DELETE and then clicking Shut Down". See MSW2KDB for additional information about this event.
Check ME196452 to see why WinNT Reports 6005, 6006, 6008, and 6009 event log entries.
Self-explanatory. It occurs during a shutdown.
|Private comment: Subscribers only. See example of private comment|
|Links: ME196452, ME916719, MSW2KDB|
|Search: Google - Bing - Microsoft - Yahoo - EventID.Net Queue (0) - More links...|
Send comments or solutions
- Notify me when updated