Monitor unlimited number of servers
Filter log events
Create email and web-based reports

Direct access to Microsoft articles
Customized keywords for major search engines
Access to premium content

Comments for event ID 1219 currently in the processing queue.

Note: We have not reviewed this information yet so it is unfiltered, exactly how it was submitted by our contributors.

Event ID: 1219
Event Source: Winlogon
Event Type: -
Event Description: -
Comment: The solution is pretty had to find, so I reckon it is a good idea to share it:

    Oper the registry (Start/Run/Regedit)
    Navigate to HKLM\SYSTEM\CurrentControlSet\Control\Terminal Server
    Add a new DWORD Value named IgnoreRegUserConfigErrors
    Set its value to 1 decimal.
    Close the registry (no need to restart the server)

Try now to RDP into the server and everything should work perfectly. Index: 2848
Event ID: 1219
Event Source: Winlogon
Event Type: -
Event Description: -
Comment: found in an other board:

Oper the registry (Start/Run/Regedit)
Navigate to HKLM\SYSTEM\CurrentControlSet\Control\Terminal Server
Add a new DWORD Value named IgnoreRegUserConfigErrors
Set its value to 1 decimal.
Close the registry (no need to restart the server) Index: 2848

Windows Event Log Analysis Splunk App

Build a great reporting interface using Splunk, one of the leaders in the Security Information and Event Management (SIEM) field, linking the collected Windows events to www.eventid.net.

Read more...

 

Cisco ASA Log Analyzer Splunk App

Obtain enhanced visibility into Cisco ASA firewall logs using the free Firegen for Cisco ASA Splunk App. Take advantage of dashboards built to optimize the threat analysis process.

Read more...