Needle in Haystack Report

Reportname: Needle in Haystack Report
Input Parameter 1 SystemEvents.DeviceReportedTime > 'Jul 14,2003 12:50:08 PM'
From Host Event Source Event Id Message Count
TESTPROD TermServLicensing 5 Policy Module %SystemRoot%\system32\tls236.dll for company Microsoft Corporation has been loaded. 1
TESTPROD RemoteAccess 20192 A certificate could not be found. Connections that use the L2TP protocol over IPSec require the installation of a machine certificate, also known as a computer certificate. No L2TP calls will be accepted. 1
TESTPROD TermServLicensing 0 Terminal Services Licensing was started. 1
TESTPROD DNS 3000 The DNS server is logging numerous run-time events. For information about these events, see previous DNS Server event log entries. To prevent the DNS Server from clogging server logs, further logging of this event and other events with higher Event IDs will now be suppressed. 1
TESTPROD NTDS General 1394 Updates to the Directory Service database are succeeding again, so the NetLogon service has been restarted. 1
TESTPROD MSExchangeMTA 9298 Microsoft Exchange Server MTA Service startup complete, version 5.5 (build 2653.23). [BASE IL MAIN BASE 20 490] (14) 1
TESTPROD NTDS ISAM 202 NTDS (264) The database engine has completed the backup procedure successfully. 1
TESTPROD MSExchangeIS Public 1000 Attempting to start the Microsoft Exchange Information Store service. 1
TESTWS03 w32time 54 EvntSLog:81356: [WRN] Tue Jul 15 09:45:31 2003: N\A/TESTWS03/w32time (54) - "The Windows Time Service was not able to find a Domain Controller. A time and date update was not possible. 1
TESTPROD NTDS KCC 1404 The local Directory Service has assumed the responsibility of generating and maintaining inter-site replication topologies for its site. 1
TESTPROD Microsoft ISA Firewall H.323 Filter 20065 Registration with H323 Gatekeeper at address 192.168.123.1:1719 succeeded. 1
TESTPROD MSExchange Pop3 Interface 11502 Initializing the POP3 external interface. 1
TESTPROD Application Popup 26 Application popup: Service Control Manager : At least one service or driver failed during system startup. Use Event Viewer to examine the event log for details. 1
TESTPROD MSExchange Pop3 Interface 11507 Ready to accept clients on the POP3 interface. 1
TESTPROD EventLog 6009 Microsoft (R) Windows 2000 (R) 5.0 2195 Service Pack 3 Uniprocessor Free. 1
TESTPROD MSExchangeIS Public 3000 The replication agent has started. 1
TESTPROD MSExchangeIS Private 1000 Attempting to start the Microsoft Exchange Information Store service. 1
TESTPROD Microsoft Firewall 14003 Firewall service started. 1
TESTPROD SpntLog 10 Real-time scan start success 1
TESTPROD MSExchangeIS Public 1001 The Microsoft Exchange Information Store has started. Service startup complete, version 5.5 (build 2653.23). 1
TESTWS03 MSSQL$VSDOTNET 19011 EvntSLog:82277: [WRN] Tue Jul 15 09:45:25 2003: N\A/TESTWS03/MSSQL$VSDOTNET (19011) - "The description for Event ID ( 19011 ) in Source ( MSSQL$VSDOTNET ) could not be found. It contains the following insertion string(s): (SpnRegister) : Error 1355 1
TESTPROD MSExchangeES 8192 No registered folders were found to monitor. 1
TESTWS03 EventLog 6005 EvntSLog:82576: [INF] Tue Jul 15 11:17:52 2003: N\A/TESTWS03/EventLog (6005) - "The Event log service was started. 1
TESTPROD TermServLicensing 18 Terminal Services Licensing on server TESTPROD has not been activated. Terminal Services Licensing will only issue temporary licenses until the server is activated. See Terminal Services Licensing help topic for more information. 1
TESTPROD RemoteAccess 20088 The Remote Access Server acquired IP Address 169.254.38.112 to be used on the Server Adapter. 1
TESTPROD MSExchange IMAP4 Interface 11505 Ready to accept clients on the IMAP4 interface. 1
TESTPROD NtFrs 13516 The File Replication Service is no longer preventing the computer TESTPROD from becoming a domain controller. The system volume has been successfully initialized and the Netlogon service has been notified that the system volume is now ready to be shared as SYSVOL. Type "net share" to check for the SYSVOL share. 1
TESTWS03 EventLog 6006 EvntSLog:82574: [INF] Tue Jul 15 11:15:51 2003: N\A/TESTWS03/EventLog (6006) - "The Event log service was stopped. 1
TESTPROD Microsoft Web Proxy 14142 The dial-up network connection Dialup Cyber.Net failed. The error description is: The connection was closed by the remote computer.. The error code shown in the Data area of the event properties is specific to the Routing and Remote Access service (RRAS). For more information about this event, see ISA Server Help. 1
TESTWS03 EventLog 6009 EvntSLog:82575: [INF] Tue Jul 15 11:17:52 2003: N\A/TESTWS03/EventLog (6009) - "Microsoft (R) Windows 2000 (R) 5.0 2195 Service Pack 3 Uniprocessor Free. 1
TESTPROD MSExchange NNTP Interface 11505 Accept clients on the NNTP interface. 1
TESTPROD DNS 2 The DNS server has started. 1
TESTWS03 Security 612 EvntSLog:82435: [AUS] Tue Jul 15 11:17:52 2003: NT AUTHORITY\SYSTEM/TESTWS03/Security (612) - "Audit Policy Change: New Policy: Success Failure + + Logon/Logoff + + Object Access + + Privilege Use + + Account Management + + Policy Change + + System + + Detailed Tracking + + Directory Service Access + + Account Logon Changed By: User Name: TESTWS03$ Domain Name: TEST Logon ID: (0x0,0x3E7) 1
TESTPROD NTDS ISAM 200 NTDS (264) The database engine is starting a full backup. 1
TESTWS02 Service Control Manager 7031 The AdisconMoniLog service terminated unexpectedly. It has done this 1 time(s). The following corrective action will be taken in 0 milliseconds: No action. 1
TESTWS02 SceCli 1704 Security policy in the Group policy objects are applied successfully. 1
TESTPROD MSExchangeIMC 1000 The Microsoft Exchange Internet Mail Service, version 5.5.2653.19, started successfully. 1
TESTPROD LicenseService 202 The product Microsoft Exchange Server 5.5 is out of licenses. Use License Manager from the Administrative Tools folder for more information on which users are out of compliance and how many licenses should be purchased. 1
TESTPROD Microsoft Scheduled Cache Content Download 14185 The Scheduled Cache Content Download Service was started successfully. 1
TESTPROD NETLOGON 5781 Dynamic registration or deregistration of one or more DNS records failed because no DNS servers are available. 1
TESTPROD MSExchange IMAP4 Interface 11500 Initializing the IMAP4 external interface. 1
TESTWS02 AdisconMoniLog 150 Unknown error occured. See the details below: An interface has too many methods to fire events from 1
TESTWS02 w32time 54 The Windows Time Service was not able to find a Domain Controller. A time and date update was not possible. 1
TESTPROD MSExchangeSA 1000 Microsoft Exchange System Attendant is starting. Microsoft Exchange Server System Attendant, service startup complete, version 5.5 (build 2653.23). 1
TESTPROD MSExchangeIS Private 1217 Information store with unlimited storage capacity enabled. 1
TESTPROD MSExchangeIS Private 1001 The Microsoft Exchange Information Store has started. Service startup complete, version 5.5 (build 2653.23). 1
TESTPROD SceCli 1704 Security policy in the Group policy objects are applied successfully. 1
TESTWS02 Security 564 Object Deleted: Object Server: Security Handle ID: 596 Process ID: 2292 1
TESTPROD MSExchangeDS 1000 Started the Directory service. Microsoft Exchange Server Directory service startup is complete. Version 5.5 (build 2653.17). 1
TESTPROD Microsoft Web Proxy 14186 The Web Proxy Service was started successfully. 1
TESTPROD MSExchange NNTP Interface 11500 Initializing the NNTP external interface. 1
TESTPROD MSExchangeDS 1306 Register LDAP protocol failed with error 10048. If port number 389 is used by another application, change to an unused port, then shut down and restart Microsoft Exchange Directory Services. Contact Microsoft Support Service if condition persists. 1
TESTWS02 BROWSER 8032 The browser service has failed to retrieve the backup list too many times on transport \Device\NetBT_Tcpip_{B4BBB1FB-C6BB-4306-B0EC-4F19254127B6}. The backup browser is stopping. 1
TESTPROD NTDS ISAM 101 NTDS (264) The database engine stopped. 1
TESTPROD MSExchangeIMC 1004 The Microsoft Exchange Internet Mail Service, version 5.5.2653.19, is starting. 1
TESTPROD Schannel 36872 No suitable default server credential exists on this system. This will prevent server applications that expect to make use of the system default credentials from accepting SSL connections. An example of such an application is the directory server. Applications that manage their own credentials, such as the internet information server, are not affected by this. 1
TESTPROD NtFrs 13501 The File Replication Service is starting. 1
TESTPROD MSFTPSVC 101 The server was unable to add the virtual root '/downloads' for the directory 'C:\Downloads' due to the following error: The system cannot find the file specified. The data is the error code. For additional information specific to this message please visit the Microsoft Online Support site located at: http://www.microsoft.com/contentredirect.asp. 1
TESTPROD NTDS ISAM 100 NTDS (264) The database engine 6.00.3940.0025 started. 1
TESTWS03 SceCli 1704 EvntSLog:82319: [INF] Tue Jul 15 11:18:12 2003: N\A/TESTWS03/SceCli (1704) - "Security policy in the Group policy objects are applied successfully. 1
TESTWS03 Security 512 EvntSLog:82424: [AUS] Tue Jul 15 11:17:52 2003: NT AUTHORITY\SYSTEM/TESTWS03/Security (512) - "Windows NT is starting up. 1
TESTPROD Microsoft H.323 Gatekeeper 21033 The H.323 Gatekeeper service has started. 1
TESTPROD MSExchangeES 0 The Microsoft Exchange Event Service (5.5.2653.11) started successfully. 1
TESTPROD Disk 34 The driver disabled the write cache on device \Device\Harddisk0\DR0. 1
TESTPROD MSExchangeIS Public 1217 Information store with unlimited storage capacity enabled. 1
TESTPROD NTBackup 8008 Begin Verify to 'C:' 1
TESTPROD NTBackup 8009 End Verify to 'C:' 1
TESTPROD EventLog 6005 The Event log service was started. 1
TESTPROD EventLog 6006 The Event log service was stopped. 1
TESTWS03 Userenv 1000 EvntSLog:82276: [ERR] Tue Jul 15 09:45:25 2003: NT AUTHORITY\SYSTEM/TESTWS03/Userenv (1000) - "Windows cannot determine the user or computer name. Return value (1722). 1
TESTPROD AdisconMonitoreWareAgent 118 MonitorWare Agent is running in registered mode. 1
TESTPROD NTDS ISAM 701 NTDS (264) Online defragmentation has completed a full pass on database 'C:\WINNT\NTDS\ntds.dit'. 1
TESTPROD NTDS General 1000 Microsoft Directory startup complete, version 5.00.2195.5979 1
TESTPROD NTDS General 1004 The directory was shut down successfully. 1
TESTPROD MSDTC 4097 MS DTC has started 1
TESTWS02 AdisconMoniLog 113 Successfully called MoniLog CTRL 1
TESTPROD NTDS ISAM 700 NTDS (264) Online defragmentation is beginning a full pass on database 'C:\WINNT\NTDS\ntds.dit'. 1
TESTPROD Microsoft ISA Server Control 14027 The Microsoft ISA Server Control Service started. 1
TESTPROD MSExchangeSA 2042 Unable to get the AppleTalk network address of the Microsoft Exchange Server computer. 1
TESTWS03 Security 518 EvntSLog:82438: [AUS] Tue Jul 15 11:17:52 2003: NT AUTHORITY\SYSTEM/TESTWS03/Security (518) - "An notification package has been loaded by the Security Account Manager. This package will be notified of any account or password changes. Notification Package Name: scecli 1
TESTWS02 FTPCtrs 1000 Unable to collect the FTP performance statistics. The error code returned by the service is data DWORD 0. For additional information specific to this message please visit the Microsoft Online Support site located at: http://www.microsoft.com/contentredirect.asp. 1
TESTPROD AdisconMonitoreWareAgent 105 The service was started. 1
TESTWS02 RSVP 10047 QoS RSVP has failed to find any interfaces with traffic control enabled. Install QoS traffic control services via network and dial-up connections. 1
TESTWS02 AdisconMonitoreWareAgent 1005 Can't initiate the SETP session. Most probably the SETP server could not be reached or does not answer. Please check the the configuration holds the correct server name or IP address as well as the correct port. If you use an server name, you might want to check the dns settings to make sure the name can be resolved. Please also check if the SETP server process is operational. Additional help might be available at http://www.adiscon.com/EventHelp.asp 2
TESTWS02 AdisconWinSyslog 114 ERROR, your trial period is over. expired... 2
TESTPROD ESE97 104 MSExchangeDS (2076) The database engine has stopped the backup procedure. 2
TESTPROD ESENT 100 lserver (1756) The database engine 6.00.3940.0025 started. 2
TESTPROD LoadPerf 1001 Performance counters for the FileReplicaSet service were removed successfully. The Record Data contains the new values of the system Last Counter and Last Help registry entries. 2
TESTPROD ESE97 100 MSExchangeDS (2068) The database engine 05.2653.0011 started. 2
TESTWS02 MSDTC 4097 MS DTC has started 2
TESTWS02 NwlnkIpx 9502 A SAP announcement was sent over \Device\NwlnkIpx which is configured for multiple networks, but no internal network is configured. This may prevent machines on some networks from locating the advertised service. 2
TESTWS02 AdisconMoniLog 105 The service was started. 2
TESTPROD LoadPerf 1000 Performance counters for the FileReplicaSet service were loaded successfully. The Record Data contains the new index values assigned to this service. 2
TESTWS03 MSSQLServer 19011 EvntSLog:81295: [WRN] Tue Jul 15 09:45:32 2003: N\A/TESTWS03/MSSQLServer (19011) - "SuperSocket info: (SpnRegister) : Error 1355. 2
TESTWS02 AdisconMoniLog 109 The MoniLog deamon background thread was successfully started. 2
TESTWS02 Security 680 Account Used for Logon by: MICROSOFT_AUTHENTICATION_PACKAGE_V1_0 Account Name: __vmware_user__ Workstation: TESTWS02 2
TESTWS02 AdisconWINSyslog 118 WinSyslog Service is running in registered mode. 2
TESTWS03 RemoteAccess 20192 EvntSLog:81360: [WRN] Tue Jul 15 09:45:47 2003: N\A/TESTWS03/RemoteAccess (20192) - "A certificate could not be found. Connections that use the L2TP protocol over IPSec require the installation of a machine certificate, also known as a computer certificate. No L2TP calls will be accepted. 2
TESTWS03 EventSystem 4100 EvntSLog:81218: [WRN] Mon Jul 14 18:35:33 2003: N\A/TESTWS03/EventSystem (4100) - "The COM+ Event System failed to create an instance of the subscriber {6295DF2D-35EE-11D1-8707-00C04FD93327}. CoCreateInstanceEx returned HRESULT 8000401A 2
TESTWS02 Userenv 1000 Windows cannot determine the user or computer name. Return value (1722). 2
TESTWS02 AdisconMonitoreWareAgent 108 The service was stopped. 2
TESTWS03 AdisconMonitoreWareAgent 108 EvntSLog:82313: [INF] Tue Jul 15 10:37:23 2003: N\A/TESTWS03/AdisconMonitoreWareAgent (108) - "The service was stopped. 2
TESTPROD Service Control Manager 7009 Timeout (30000 milliseconds) waiting for the InterScan eManager Content Management service to connect. 2
TESTWS02 Adiscon EvntSLog 107 The logger background thread started successfully - licensed to 'Adiscon - Wajih'. 2
TESTWS02 Adiscon EvntSLog 105 The service was started. 2
TESTPROD BROWSER 8015 The browser has forced an election on network \Device\NetBT_Tcpip_{962E1A96-C050-4719-8BBB-0DC60501743F} because a Windows 2000 Server (or domain master) browser is started. 2
TESTWS02 Security 681 The logon to account: by: MICROSOFT_AUTHENTICATION_PACKAGE_V1_0 from workstation: TESTWS02 failed. The error code was: 3221225572 2
TESTWS02 mnmsrvc 16 NetMeeting RDS Service Start 2
TESTWS03 Security 578 EvntSLog:82357: [AUS] Tue Jul 15 11:13:09 2003: TEST\Administrator/TESTWS03/Security (578) - "Privileged object operation: Object Server: EventLog Object Handle: 0 Process ID: 212 Primary User Name: TESTWS03$ Primary Domain: TEST Primary Logon ID: (0x0,0x3E7) Client User Name: administrator Client Domain: TEST Client Logon ID: (0x0,0x3412C) Privileges: SeSecurityPrivilege 2
TESTWS02 MSMQ 2124 Message Queuing was unable to join the local Windows 2000 domain. Hresult- c00e0075h 2
TESTWS02 EventLog 6009 Microsoft (R) Windows 2000 (R) 5.0 2195 Service Pack 3 Uniprocessor Free. 2
TESTWS02 Service Control Manager 7000 The Microsoft Legacy Modem Driver service failed to start due to the following error: The service cannot be started, either because it is disabled or because it has no enabled devices associated with it. 2
TESTWS02 EventLog 6005 The Event log service was started. 2
TESTWS02 EventLog 6006 The Event log service was stopped. 2
TESTWS02 PGPservice 105 The service was started. 2
TESTWS02 Application Popup 26 Application popup: winsyslg.exe - Application Error : The instruction at "0x0043078c" referenced memory at "0x00000000". The memory could not be "read". Click on OK to terminate the program Click on CANCEL to debug the program 2
TESTWS02 AdisconWINSyslog 104 The initialization process failed. 2
TESTPROD ESE97 102 MSExchangeDS (2076) The database engine is starting a full backup. 2
TESTWS03 Service Control Manager 7024 EvntSLog:81357: [ERR] Tue Jul 15 09:45:40 2003: N\A/TESTWS03/Service Control Manager (7024) - "The Computer Browser service terminated with service-specific error 2250. 2
TESTWS02 VMnetuserif 1 () Starting up the User Interface Driver for VMware Virtual Networks 2
TESTWS02 PGPsdkServ 0 The description for Event ID ( 0 ) in Source ( PGPsdkServ ) could not be found. It contains the following insertion string(s): Started Successfully 2
TESTWS02 VMnetuserif 4 (\Device\VMnetUserif) Driver entry exiting with status 0 2
TESTWS03 AdisconMonitoreWareAgent 151 EvntSLog:82290: [ERR] Tue Jul 15 09:45:27 2003: N\A/TESTWS03/AdisconMonitoreWareAgent (151) - "Numerous runtime events were encountered . This is usually caused by configuration or network problems. From now, there will no more events logged for this hour. 2
TESTWS02 MSMQ 2121 Unable to complete Message Queuing Setup. Hresult- c00e0075h 2
TESTPROD Userenv 1000 Windows cannot unload your registry file. If you have a roaming profile, your settings are not replicated. Contact your administrator. DETAIL - Access is denied. , Build number ((2195)). 2
TESTWS03 PGPsdkServ 0 EvntSLog:82275: [INF] Tue Jul 15 09:45:24 2003: N\A/TESTWS03/PGPsdkServ (0) - "The description for Event ID ( 0 ) in Source ( PGPsdkServ ) could not be found. It contains the following insertion string(s): Started Successfully 2
TESTWS02 MSMQ 2028 Initialization has successfully completed. 2
TESTWS03 W3Ctrs 1003 EvntSLog:81304: [ERR] Tue Jul 15 09:45:55 2003: N\A/TESTWS03/W3Ctrs (1003) - "Unable to query the W3SVC (HTTP) service performance data. The error code returned by the service is data DWORD 0. For additional information specific to this message please visit the Microsoft Online Support site located at: http://www.microsoft.com/contentredirect.asp. 3
TESTPROD NTBackup 8000 Begin Backup of 'KLV NetS GmbH\TEST\TESTPROD\Directory' Verify: On Mode: Append Type: Normal 3
TESTWS02 Security 529 Logon Failure: Reason: Unknown user name or bad password User Name: Domain: TEST Logon Type: 2 Logon Process: User32 Authentication Package: Negotiate Workstation Name: TESTWS02 3
TESTWS03 Ci 4130 EvntSLog:81368: [INF] Tue Jul 15 09:52:25 2003: N\A/TESTWS03/Ci (4130) - "Recovery was performed successfully on PropertyStore in catalog c:\system volume information\catalog.wci. 3
TESTWS02 AdisconMonitoreWareAgent 118 MonitorWare Agent is running in registered mode. 3
TESTWS03 WMDM PMSP Service 105 EvntSLog:81299: [INF] Tue Jul 15 09:45:33 2003: N\A/TESTWS03/WMDM PMSP Service (105) - "The service was started. 3
TESTWS03 Security 528 EvntSLog:81375: [AUS] Tue Jul 15 10:35:50 2003: TEST\administrator/TESTWS03/Security (528) - "Successful Logon: User Name: administrator Domain: TEST Logon ID: (0x0,0x3412C) Logon Type: 2 Logon Process: User32 Authentication Package: Negotiate Workstation Name: TESTWS03 3
TESTWS03 FTPCtrs 1000 EvntSLog:81303: [ERR] Tue Jul 15 09:45:49 2003: N\A/TESTWS03/FTPCtrs (1000) - "Unable to collect the FTP performance statistics. The error code returned by the service is data DWORD 0. For additional information specific to this message please visit the Microsoft Online Support site located at: http://www.microsoft.com/contentredirect.asp. 3
TESTWS03 Ci 4129 EvntSLog:81367: [INF] Tue Jul 15 09:52:05 2003: N\A/TESTWS03/Ci (4129) - "Recovery is starting on PropertyStore in catalog c:\system volume information\catalog.wci. 3
TESTWS02 AdisconMonitoreWareAgent 105 The service was started. 3
TESTWS03 AdisconMonitoreWareAgent 105 EvntSLog:82274: [INF] Tue Jul 15 09:45:10 2003: N\A/TESTWS03/AdisconMonitoreWareAgent (105) - "The service was started. 3
TESTWS03 AdisconMonitoreWareAgent 118 EvntSLog:82273: [INF] Tue Jul 15 09:45:10 2003: N\A/TESTWS03/AdisconMonitoreWareAgent (118) - "MonitorWare Agent is running in registered mode. 3
TESTWS03 PGPservice 105 EvntSLog:81300: [INF] Tue Jul 15 09:45:36 2003: N\A/TESTWS03/PGPservice (105) - "The service was started. 3
TESTWS02 MSSQL$NETSDK 19011 The description for Event ID ( 19011 ) in Source ( MSSQL$NETSDK ) could not be found. It contains the following insertion string(s): Bind(MSAFD Tcpip [TCP/IP]) : Error 10048 3
TESTPROD Service Control Manager 7000 The InterScan eManager Content Management service failed to start due to the following error: The service did not respond to the start or control request in a timely fashion. 3
TESTWS03 IISInfoCtrs 1003 EvntSLog:81302: [ERR] Tue Jul 15 09:45:48 2003: N\A/TESTWS03/IISInfoCtrs (1003) - "Unable to query the IIS Info service performance data. The error code returned by the service is data DWORD 0. For additional information specific to this message please visit the Microsoft Online Support site located at: http://www.microsoft.com/contentredirect.asp. 3
TESTPROD w32time 11 The NTP server didn't respond 3
TESTWS02 VMnetAdapter 34 () Starting up: 0x81f808b0, \REGISTRY\MACHINE\SYSTEM\Contr 4
TESTWS02 VMware NAT Service 1000 Service started 4
TESTWS02 W3SVC 101 The server was unable to add the virtual root '/MWWebConfigService' for the directory 'D:\EnterpriseConfigService\MWConfigService\1.0\MWWebConfigService' due to the following error: The system cannot find the path specified. The data is the error code. For additional information specific to this message please visit the Microsoft Online Support site located at: http://www.microsoft.com/contentredirect.asp. 4
TESTWS03 Srv 2013 EvntSLog:81362: [WRN] Tue Jul 15 09:50:13 2003: N\A/TESTWS03/Srv (2013) - "The C: disk is at or near capacity. You may need to delete some files. 4
TESTPROD AdisconMonitoreWareAgent 1005 Can't initiate the SETP session. Most probably the SETP server could not be reached or does not answer. Please check the the configuration holds the correct server name or IP address as well as the correct port. If you use an server name, you might want to check the dns settings to make sure the name can be resolved. Please also check if the SETP server process is operational. Additional help might be available at http://www.adiscon.com/EventHelp.asp 4
TESTPROD NTBackup 8001 End Backup of 'F:' Verify: On Mode: Append Type: Normal 4
TESTWS03 RemoteAccess 20169 EvntSLog:81358: [WRN] Tue Jul 15 09:45:47 2003: N\A/TESTWS03/RemoteAccess (20169) - "Unable to contact a DHCP server. The Automatic Private IP Address 169.254.202.160 will be assigned to dial-in clients. Clients may be unable to access resources on the network. 4
TESTWS02 BROWSER 8021 The browser was unable to retrieve a list of servers from the browser master \\TESTPROD on the network \Device\NetBT_Tcpip_{B4BBB1FB-C6BB-4306-B0EC-4F19254127B6}. The data is the error code. 5
TESTWS03 Security 514 EvntSLog:82425: [AUS] Tue Jul 15 11:17:52 2003: NT AUTHORITY\SYSTEM/TESTWS03/Security (514) - "An authentication package has been loaded by the Local Security Authority. This authentication package will be used to authenticate logon attempts. Authentication Package Name: C:\WINNT\system32\LSASRV.dll : Negotiate 5
TESTWS02 Security 528 Successful Logon: User Name: user2 Domain: TEST Logon ID: (0x0,0x2C43A6) Logon Type: 7 Logon Process: User32 Authentication Package: Negotiate Workstation Name: TESTWS02 5
TESTWS02 Server 2511 The server service was unable to recreate the share Hellow$ because the directory C:\Hellow no longer exists. 6
TESTWS03 Security 540 EvntSLog:81205: [AUS] Mon Jul 14 13:14:01 2003: NT AUTHORITY\SYSTEM/TESTWS03/Security (540) - "Successful Network Logon: User Name: TESTWS03$ Domain: TEST Logon ID: (0x0,0x5A1C3) Logon Type: 3 Logon Process: Kerberos Authentication Package: Kerberos Workstation Name: 7
TESTWS02 Security 540 Successful Network Logon: User Name: TESTWS02$ Domain: TEST Logon ID: (0x0,0x2229EE) Logon Type: 3 Logon Process: Kerberos Authentication Package: Kerberos Workstation Name: 7
TESTWS03 Security 538 EvntSLog:81206: [AUS] Mon Jul 14 13:14:01 2003: NT AUTHORITY\SYSTEM/TESTWS03/Security (538) - "User Logoff: User Name: TESTWS03$ Domain: TEST Logon ID: (0x0,0x5A1C3) Logon Type: 3 7
TESTWS02 RemoteAccess 20158 The user AdisconVpn successfully established a connection to VPN For TeamSpeak using the device VPN2-0. 8
TESTWS02 RemoteAccess 20159 The connection to Virtual Private Connection made by user user2 using device VPN2-1 was disconnected. 8
TESTWS02 Security 538 User Logoff: User Name: TESTWS02$ Domain: TEST Logon ID: (0x0,0x2229EE) Logon Type: 3 8
TESTPROD Security 528 Successful Logon: User Name: Administrator Domain: TEST Logon ID: (0x0,0xC466) Logon Type: 5 Logon Process: SCMgr Authentication Package: MICROSOFT_AUTHENTICATION_PACKAGE_V1_0 Workstation Name: TESTPROD 9
TESTWS03 Ci 4137 EvntSLog:81365: [INF] Tue Jul 15 09:52:03 2003: N\A/TESTWS03/Ci (4137) - "CI has started for catalog c:\documents and settings\iullah\desktop\adiscon\catalog.wci. 9
TESTWS03 MSSQLServer 19010 EvntSLog:81292: [INF] Tue Jul 15 09:45:32 2003: N\A/TESTWS03/MSSQLServer (19010) - "RPC Net-Library listening on: ncalrpc:TESTWS03[LRPC000002cc.00000001]. 9
TESTPROD RemoteAccess 20169 Unable to contact a DHCP server. The Automatic Private IP Address 169.254.53.188 will be assigned to dial-in clients. Clients may be unable to access resources on the network. 10
TESTPROD MSSQLSERVER 17055 17052 : Microsoft SQL Server 2000 - 8.00.194 (Intel X86) Aug 6 2000 00:57:48 Copyright (c) 1988-2000 Microsoft Corporation Desktop Engine on Windows NT 5.0 (Build 2195: Service Pack 3) 10
TESTWS03 Security 576 EvntSLog:81204: [AUS] Mon Jul 14 13:14:01 2003: NT AUTHORITY\SYSTEM/TESTWS03/Security (576) - "Special privileges assigned to new logon: User Name: Domain: Logon ID: (0x0,0x5A1C3) Assigned: SeBackupPrivilege SeRestorePrivilege SeDebugPrivilege SeChangeNotifyPrivilege 11
TESTPROD Security 672 Authentication Ticket Granted: User Name: Administrator Supplied Realm Name: TEST User ID: %{S-1-5-21-4277340742-1997144596-2485913829-500} Service Name: krbtgt Service ID: %{S-1-5-21-4277340742-1997144596-2485913829-502} Ticket Options: 0x40810010 Ticket Encryption Type: 0x17 Pre-Authentication Type: 2 Client Address: 127.0.0.1 14
TESTPROD Security 680 Account Used for Logon by: MICROSOFT_AUTHENTICATION_PACKAGE_V1_0 Account Name: user2 Workstation: TESTPROD 16
TESTWS03 AdisconMonitoreWareAgent 114 EvntSLog:82278: [ERR] Tue Jul 15 09:45:26 2003: N\A/TESTWS03/AdisconMonitoreWareAgent (114) - "Error while applying an action - skipping this action. Error is 'ODBC Error Code: '37000' ODBC Error Description: '[Microsoft][ODBC SQL Server Driver][SQL Server]Cannot open database requested in login 'mwdb'. Login fails.'.'. 20
TESTWS03 Security 515 EvntSLog:81318: [AUS] Tue Jul 15 09:45:42 2003: NT AUTHORITY\SYSTEM/TESTWS03/Security (515) - "A trusted logon process has registered with the Local Security Authority. This logon process will be trusted to submit logon requests. Logon Process Name: RASMAN 21
TESTWS03 MSSQLSERVER 17055 EvntSLog:82286: [INF] Tue Jul 15 09:45:27 2003: N\A/TESTWS03/MSSQLSERVER (17055) - "17052 : Microsoft SQL Server 2000 - 8.00.194 (Intel X86) Aug 6 2000 00:57:48 Copyright (c) 1988-2000 Microsoft Corporation Developer Edition on Windows NT 5.0 (Build 2195: Service Pack 3) 27
TESTPROD MSExchangeIMC 4106 The dial-up connection 'wol.net.pk' could not be made. The error reported was: [797] (797) 30
TESTWS03 Security 562 EvntSLog:81326: [AUS] Tue Jul 15 09:45:47 2003: NT AUTHORITY\SYSTEM/TESTWS03/Security (562) - "Handle Closed: Object Server: Security Account Manager Handle ID: 722736 Process ID: 224 30
TESTWS03 Security 560 EvntSLog:81323: [AUS] Tue Jul 15 09:45:47 2003: NT AUTHORITY\SYSTEM/TESTWS03/Security (560) - "Object Open: Object Server: Security Account Manager Object Type: SAM_SERVER Object Name: SAM New Handle ID: 722736 Operation ID: {0,98891} Process ID: 224 Primary User Name: TESTWS03$ Primary Domain: TEST Primary Logon ID: (0x0,0x3E7) Client User Name: TESTWS03$ Client Domain: TEST Client Logon ID: (0x0,0x3E7) Accesses LookupDomain Privileges - 34
TESTPROD DNS 6701 DNS Server has updated its own host (A) records. In order to insure that its DS-integrated peer DNS servers are able to replicate with it, they have been updated with the new records through dynamic update. 39
TESTWS03 Security 593 EvntSLog:81314: [AUS] Tue Jul 15 09:45:37 2003: NT AUTHORITY\SYSTEM/TESTWS03/Security (593) - "A process has exited: Process ID: 1216 User Name: TESTWS03$ Domain: TEST Logon ID: (0x0,0x3E7) 42
TESTWS03 Security 577 EvntSLog:81307: [AUS] Tue Jul 15 09:45:31 2003: NT AUTHORITY\SYSTEM/TESTWS03/Security (577) - "Privileged Service Called: Server: NT Local Security Authority / Authentication Service Service: LsaRegisterLogonProcess() Primary User Name: TESTWS03$ Primary Domain: TEST Primary Logon ID: (0x0,0x3E7) Client User Name: TESTWS03$ Client Domain: TEST Client Logon ID: (0x0,0x3E7) Privileges: SeTcbPrivilege 81
TESTWS03 Security 592 EvntSLog:81207: [AUS] Mon Jul 14 14:25:33 2003: NT AUTHORITY\SYSTEM/TESTWS03/Security (592) - "A new process has been created: New Process ID: 1432 Image File Name: \OfficeScan NT\AUBin\patch.exe Creator Process ID: 1060 User Name: TESTWS03$ Domain: TEST Logon ID: (0x0,0x3E7) 99
TESTPROD Security 673 Service Ticket Granted: User Name: TESTPROD$ User Domain: Testsoft.COM.PK Service Name: TESTPROD$ Service ID: %{S-1-5-21-4277340742-1997144596-2485913829-1002} Ticket Options: 0x40810010 Ticket Encryption Type: 0x17 Client Address: 127.0.0.1 300
TESTPROD Security 540 Successful Network Logon: User Name: TESTPROD$ Domain: TEST Logon ID: (0x0,0x1CEF9A) Logon Type: 3 Logon Process: Kerberos Authentication Package: Kerberos Workstation Name: 845
TESTPROD Security 538 User Logoff: User Name: TESTPROD$ Domain: TEST Logon ID: (0x0,0x1D50A3) Logon Type: 3 866
TESTWS02 Security 562 Handle Closed: Object Server: Security Handle ID: 1592 Process ID: 2504 1113
TESTWS02 Security 560 Object Open: Object Server: Security Object Type: File Object Name: D:\PROGRA~1\MICROS~1\Office10 New Handle ID: 1592 Operation ID: {0,2116665} Process ID: 2504 Primary User Name: user2 Primary Domain: TEST Primary Logon ID: (0x0,0x15929) Client User Name: - Client Domain: - Client Logon ID: - Accesses SYNCHRONIZE ReadData (or ListDirectory) Privileges - 1113