Monitor unlimited number of servers
Filter log events
Create email and web-based reports

Direct access to Microsoft articles
Customized keywords for major search engines
Access to premium content

Comments for event ID 1515 currently in the processing queue.

Note: We have not reviewed this information yet so it is unfiltered, exactly how it was submitted by our contributors.

Event ID: 1515
Event Source: Userenv
Event Type: -
Event Description: -
Comment: If you go into the following location in the registry on the workstation you are trying to log on to:

HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\ProfileList

You should see sub keys under there named with SIDs, one for each user that has ever logged on to this machine. Find the one that is named with the SID of the user you are having problems with and delete that subkey. Well you might want to look at the profile location in the ProfileImagePath value within before deleting it just to see if that gives you any clue why this is happening in the first place. Once you have deleted the key named with that user's SID, try logging back on as them and see what happens. Index: 2093
Event ID: 1515
Event Source: User Profile Service
Event Type: Error
Event Description: Windows has backed up this user profile. Windows will automatically try to use the backup profile the next time this user logs on.

Windows Event Log Analysis Splunk App

Build a great reporting interface using Splunk, one of the leaders in the Security Information and Event Management (SIEM) field, linking the collected Windows events to



Cisco ASA Log Analyzer Splunk App

Obtain enhanced visibility into Cisco ASA firewall logs using the free Firegen for Cisco ASA Splunk App. Take advantage of dashboards built to optimize the threat analysis process.