Monitor unlimited number of servers
Filter log events
Create email and web-based reports

Direct access to Microsoft articles
Customized keywords for major search engines
Access to premium content

Comments for event ID 1001 currently in the processing queue.

Note: We have not reviewed this information yet so it is unfiltered, exactly how it was submitted by our contributors.

Event ID: 1001
Event Source: Health Service Script
Event Type: Warning
Event Description: AD Client Connectivity : The bind to ''LDAP://dc.domain.com/RootDSE'' took 3406 milliseconds which is longer than the allowed 1000 milliseconds.

For more information see Help and Support Center at http://go.microsoft.com/fwlink/events.asp.
Comment: SCOM 2007
Event ID: 1001
Event Source: Dhcp
Event Type: -
Event Description: -
Comment: I get this message after installation of a patch. It occours when trying to connect to live audio streaming from opera browser with wmp 12. Running sfc/scannow eliminates the problem by repairing the dll previously changed.After restart, the reason the patch installed in the first place comes back. Remove watermark from windows 7 build 7000 64bit desktop.

                                       Constantine N. Laitsas Index: 1627
Event ID: 1001
Event Source: HP System
Event Type: Error
Event Description: Log: System
Type: Error
Event: 1001
Agent Time: 17:12:34  7-May-09
Event Time: 16:12:34  7-May-09 UTC
Source: HP System
Category: System Hardware
Username: N/A
Computer: IGCT03UK
Description: Power-On-Self-Test (POST) errors occurred during the last system startup.



User Action

Check the Power-On-Self-Test (POST) errors and take corrective action as needed.



WBEM Indication Properties

AlertingElementFormat: 0 0 (Unknown)
AlertType: 5 0x5 (Device Alert)
Description: "Power-On-Self-Test (POST) errors occurred during the last system startup."
EventCategory: 4 0x4 (System Hardware)
EventID: "1"
ImpactedDomain: 4 0x4 (System)
IndicationIdentifier: "{C9F997C0-AFB1-4886-9533-CA31D556A805}"
IndicationTime: "20090507171229.012000+060"
NetworkAddresses[0]: "192.168.5.38"
OSType: 69 0x45 (Microsoft Windows Server 2003)
OSVersion: "5.2.3790"
PerceivedSeverity: 5 0x5 (Major)
ProbableCause: 8 0x8 (Configuration/Customization Error)
ProbableCauseDescription: "POST Errors Occurred"
ProviderName: "HP POST"
ProviderVersion: "2.2.1.0"
RecommendedActions[0]: "Check the Power-On-Self-Test (POST) errors and take corrective action as needed."
Summary: "POST errors occurred"
SystemCreationClassName: "HP_WinComputerSystem"
SystemFirmwareVersion[0]: "2008.11.02"
SystemFirmwareVersion[1]: "2007.06.28"
SystemGUID: "39353334-3434-5A43-4A37-333830305A32"
SystemModel: "ProLiant DL360 G5"
SystemName: "igct03uk.interglobal.uk"
SystemProductID: "435944-421"
SystemSerialNumber: "CZJ73800Z2"
TIME_CREATED: 128861863543579425 0x1c9cf2ea19c2321
VariableNames[0]: "POST Error Code"
VariableNames[1]: "POST Error String"
VariableTypes[0]: 3 0x3 (uint8)
VariableTypes[1]: 1 0x1 (string)
VariableValues[0]: "210"
VariableValues[1]: "Could not translate POST error"



Comment:
Event ID: 1001
Event Source: NfsServer
Event Type: Error
Event Description: "The Network File System (NFS) driver has suspended operations.

If this is not a result of administrative action check the status of the Server for NFS service. If this service process is missing try to restart the service using ""nfsadmin server start""."

Comment: windows server 2008  

Actually we have lost one of our drive in server
and we dont know the resoan
we are analysing logs for the cause
Event ID: 1001
Event Source: LanguagePackSetup
Event Type: Error
Event Description: Programinit. failed error:0x80070032
Microsoft-Windows-LanguagePackSetup
   [ Guid]  {7237fff9-a08a-4804-9c79-4a8704b70b87}

   EventID 1001

   Version 0

   Level 2

   Task 30

   Opcode 31

   Keywords 0x8000000000000000

  - TimeCreated

   [ SystemTime]  2010-06-15T07:56:10.468Z

   EventRecordID 157567

   Correlation

  - Execution

   [ ProcessID]  1608
   [ ThreadID]  1612

   Channel System

   Computer Birgit-dator

  - Security

   [ UserID]  S-1-5-18


- EventData

  Error 0x80070032

Comment:
Event ID: 1001
Event Source: Outlook
Event Type: Error
Event Description: Problem Event Name: APPCRASH
  Application Name: OUTLOOK.EXE
  Application Version: 12.0.6539.5000
  Application Timestamp: 4c12486d
  Fault Module Name: mspst32.dll
  Fault Module Version: 12.0.6539.5000
  Fault Module Timestamp: 4c12471a
  Exception Code: c0000005
  Exception Offset: 0001e1bb
  OS Version: 6.1.7600.2.0.0.768.3
  Locale ID: 2057

Additional information about the problem:
  LCID: 1033
  Brand: Office12Crash
  skulcid: 1033


Comment:
Event ID: 1001
Event Source: libcsd
Event Type: Warning
Event Description: The description for Event ID 1001 from source libcsd cannot be found. Either the component that raises this event is not installed on your local computer or the installation is corrupted. You can install or repair the component on the local computer.

If the event originated on another computer the display information had to be saved with the event.

The following information was included with the event:

[libcsd][warn][cert_init] failed to initialize mozilla certificates

Comment: Related to Cisco AnyConnect VPN client's Cisco Secure Desktop functionality but not sure why.  Occurs every minute while connected on this Windows 7 box.
Event ID: 1001
Event Source: dhcp client
Event Type: Error
Event Description: Your computer was not assigned an address from the network (by the DHCP Server) for the Network Card with network address 0x9-------5B.  The following error occurred: 0x79. Your computer will continue to try and obtain an address on its own from the network address (DHCP) server.
Comment:
Event ID: 1001
Event Source: MSExchangeTransport
Event Type: Error
Event Description: 987654321
Comment: Restart of the server fixed the problem (will see for how long).
Event ID: 1001
Event Source: Msinstaller
Event Type: Error
Event Description: Scandetails:
  Event Log Module Status: 0
  The Last Record Number of the eventlog type that current event entry belongs to: 0
  # of duplicate events: 1
  Source: MsiInstaller
  Category: (0)
  Event ID: 1001
  User (If Applicable): NT AUTHORITY\LOCAL SERVICE
  Computer: Guidance.baptisthomes.org
  
Event Description: Detection of product ''{9ACB414D-9347-40B6-A453-5EFB2DB59DFA}'' feature ''MainComponents'' failed during request for component ''{8704CBD6-DCC6-4BE1-90C4-6E4E802D30D0}''
  Event Log Name: Application
  Event Log Type: warning
  Event Log Date Time: 2012-12-05 15:08:54

Notification: 1
Notification Activated: 2012-12-05 15:13:14 Notification Sent: 2012-12-05 15:13:38


Comment:
Event ID: 1001
Event Source: Dhcp-Client
Event Type: Error
Event Description: Dem Computer wurde (vom DHCP-Server) keine Adresse aus dem Netzwerk für die Netzwerkkarte mit der Netzwerkadresse 0x84A6C89B3F08 zugewiesen. Fehler: 0x79. Der Computer versucht weiterhin selbständig eine Adresse vom Netzwerkadressserver (DHCP-Server) abzurufen.



- System

  - Provider

   [ Name]  Microsoft-Windows-Dhcp-Client
   [ Guid]  {15A7A4F8-0072-4EAB-ABAD-F98A4D666AED}

   EventID 1001

   Version 0

   Level 2

   Task 3

   Opcode 75

   Keywords 0x4000000000000001

  - TimeCreated

   [ SystemTime]  2013-03-16T07:10:53.167586200Z

   EventRecordID 1864

   Correlation

  - Execution

   [ ProcessID]  1116
   [ ThreadID]  6000

   Channel Microsoft-Windows-Dhcp-Client/Admin

   Computer HPENVY

  - Security

   [ UserID]  S-1-5-19


- EventData

  HWLength 6
  HWAddress 84A6C89B3F08
  StatusCode 121




- <Event xmlns="http://schemas.microsoft.com/win/2004/08/events/event">
- <System>
  <Provider Name="Microsoft-Windows-Dhcp-Client" Guid="{15A7A4F8-0072-4EAB-ABAD-F98A4D666AED}" />
  <EventID>1001</EventID>
  <Version>0</Version>
  <Level>2</Level>
  <Task>3</Task>
  <Opcode>75</Opcode>
  <Keywords>0x4000000000000001</Keywords>
  <TimeCreated SystemTime="2013-03-16T07:10:53.167586200Z" />
  <EventRecordID>1864</EventRecordID>
  <Correlation />
  <Execution ProcessID="1116" ThreadID="6000" />
  <Channel>Microsoft-Windows-Dhcp-Client/Admin</Channel>
  <Computer>HPENVY</Computer>
  <Security UserID="S-1-5-19" />
  </System>
- <EventData>
  <Data Name="HWLength">6</Data>
  <Data Name="HWAddress">84A6C89B3F08</Data>
  <Data Name="StatusCode">121</Data>
  </EventData>
  </Event>


Comment:
Event ID: 1001
Event Source: Microsoft Antimalware
Event Type: Information
Event Description: Microsoft Antimalware scan has finished.
Scan ID: {C2C14CF4-F858-4700-8568-F70253321E6C}
Scan Type: Antimalware
Scan Parameters: Full Scan
User: LLBPCSAM310240\L&B Basic
Scan Time: 0:53:35
Comment:
Event ID: 1001
Event Source: Event reader 3.03
Event Type: Error
Event Description: 987654321
Comment: Windows Installer reconfigured the product. Product Name: EventReader 3. Product Version: 3.0.3.0. Product Language: 1033. Manufacturer: Altair Technologies Ltd.. Reconfiguration success or error status: 0.

There aren't any indications that the repair did not work.
Event ID: 1001
Event Source: bug check
Event Type: Error
Event Description: - System

  - Provider

   [ Name]  Microsoft-Windows-WER-SystemErrorReporting
   [ Guid]  {ABCE23E7-DE45-4366-8631-84FA6C525952}
   [ EventSourceName]  BugCheck

  - EventID 1001

   [ Qualifiers]  16384

   Version 0

   Level 2

   Task 0

   Opcode 0

   Keywords 0x80000000000000

  - TimeCreated

   [ SystemTime]  2016-03-08T04:19:21.000000000Z

   EventRecordID 221195

   Correlation

  - Execution

   [ ProcessID]  0
   [ ThreadID]  0

   Channel System

   Computer William-PC

   Security


- EventData

  param1 0x0000001e (0x0000000000000000 0x0000000000000000 0x0000000000000000 0x0000000000000000)
  param2 C:\Windows\Minidump\030716-20046-01.dmp
  param3 030716-20046-01

Comment:
Event ID: 1001
Event Source: Microsoft-Windows-WER-SystemErrorReporting
Event Type: -
Event Description: -
Comment: the reference page doesn't exist, are you guys updating this for windows 10? Otherwise it's getting limited mileage now. Index: 10481

Windows Event Log Analysis Splunk App

Build a great reporting interface using Splunk, one of the leaders in the Security Information and Event Management (SIEM) field, linking the collected Windows events to www.eventid.net.

Read more...

 

Cisco ASA Log Analyzer Splunk App

Obtain enhanced visibility into Cisco ASA firewall logs using the free Firegen for Cisco ASA Splunk App. Take advantage of dashboards built to optimize the threat analysis process.

Read more...