Event ID:
Source:
Service Control Manager
Message:
The Microsoft Exchange Routing Engine service failed to start due to the following error:
The executable program that this service is configured to run in does not implement the service.


Event ID:
Source:
Service Control Manager
Message:
The Microsoft Exchange Information Store service terminated with service-specific error 0 (0x0).


Event ID:
Source:
Service Control Manager
Message:
The PfModNT service failed to start due to the following error:
The system cannot find the file specified.



Event ID:
Source:
Service Control Manager
Message:
The ServiceABC service terminated unexpectedly. It has done this 3 time(s). The following corrective action will be taken in 0 milliseconds: No action.


Event ID:
Source:
LicenseService
Message:
Replication of license information failed because the License Logging Service on server <Server> could not be contacted.



Event ID:
Source:
LicenseService
Message:
Replication of license information failed because the License Logging Service on server <PDC servername> could not be contacted.


Event ID:
Source:
Removable Storage Service
Message:
RSM could not load media in drive Drive 0 of library Iomega RRD2.


Event ID:
Source:
Service Control Manager
Message:
The ABC service was unable to log on as DOMAIN\service.account with the currently configured password due to the following error:
Logon failure: unknown user name or bad password.

To ensure that the service is configured properly, use the Services snap-in in Microsoft Management Console (MMC).


Event ID:
Source:
.NET Runtime Optimization Service
Message:
.NET Runtime Optimization Service (clr_optimization_v2.0.50727_32) - Failed to compile: Microsoft.ReportingServices.QueryDesigners, Version=9.0.242.0, Culture=neutral, PublicKeyToken=89845dcd8080cc91 . Error code = 0x80070002


Event ID:
Source:
Service Control Manager
Message:
The APC UPS Service service is marked as an interactive service. However, the system is configured to not allow interactive services. This service may not function properly.


Event ID:
Source:
Windows SharePoint Services 3
Category:
Timer
Message:
The Execute method of job definition Microsoft.Office.Server.Administration.ApplicationServerAdministrationServiceJob (ID 693fe0b2-6c9f-47bf-9d1a-c6a2aa7cd3c3) threw an exception. More information is included below.

Attempted to read or write protected memory. This is often an indication that other memory is corrupt.



Event ID:
Source:
NtServicePack
Message:
Windows XP Service Pack 3 installation failed.
Access is denied.


Event ID:
Source:
VWServicesPA
Message:
Source: Process AnalyzerCube Processing Status: DTSRun: Loading...DTSRun: Executing...DTSRun OnStart: DTSStep_DTSOlapProcess.Task_1DTSRun OnError: DTSStep_DTSOlapProcess.Task_1, Error = -2147221384 (80040078) Error string: More than the maximum of 64,000 dimension member children for a single parent (dimension 'Zaaknummer', level 'Zaaknummer', member '141715'). Error source: Zaaknummer Help file: Help context: 1000440Error Detail Records:Error: 0 (0)


Event ID:
Source:
Windows SharePoint Services 3
Message:
The Execute method of job definition Microsoft.Office.Server.Administration.ApplicationServerAdministrationServiceJob (ID a778c03a-b4d5-47ad-b0d5-6130b9c8ba14) threw an exception. More information is included below.

Attempted to read or write protected memory. This is often an indication that other memory is corrupt.



Event ID:
Source:
Service Control Manager
Category:
None
Message:
Timeout (30000 milliseconds) waiting for the hpqwmiex service to connect.


Event ID:
Source:
Report Server Windows Service (EVENTSENTRY)
Category:
Startup/Shutdown
Message:
The report server database is an invalid version.


Event ID:
Source:
User Profile Service
Message:
Windows detected your registry file is still in use by other applications or services. The file will be unloaded now. The applications or services that hold your registry file may not function properly afterwards.

DETAIL -
2 user registry handles leaked from \Registry\User\S-1-5-21-3955188477-656860062-1151124159-1021:
Process 6540 (\Device\HarddiskVolume3\Windows\System32\winlogon.exe) has opened key \REGISTRY\USER\S-1-5-21-3955188477-656860062-1151124159-1021
Process 1356 (\Device\HarddiskVolume3\Windows\System32\svchost.exe) has opened key \REGISTRY\USER\S-1-5-21-3955188477-656860062-1151124159-1021\Printers\DevModePerUser



Event ID:
Source:
Windows Search Service
Category:
Gatherer
Message:
A document ID cannot be allocated.
Context: Windows Application, SystemIndex Catalog
Details:
The content index server cannot update or access information because of a database error. Stop and restart the search service. If the problem persists, reset and recrawl the content index. In some cases it may be necessary to delete and recreate the content index. (0x8004117f)



Event ID:
Source:
Apache Service
Message:
The Apache service named reported the following error:
>>> httpd.exe: Syntax error on line 116 of C:/Program Files (x86)/CollabNet Subversion Server/httpd/conf/httpd.conf: Cannot load C:/Program Files (x86)/CollabNet Subversion Server/httpd/modules/mod_dav_svn.so into server: The specified module could not be found.


Event ID:
Source:
Service Control Manager
Message:
The following boot-start or system-start driver(s) failed to load: storflt


Event ID:
Source:
Service Control Manager
Category:
Error
Message:
EVENT # 9697313
EVENT LOG System
EVENT TYPE Error
SOURCE Service Control Manager
EVENT ID 7011
COMPUTERNAME SERVER
DATE / TIME 7/28/2009 8:11:23 PM
MESSAGE Timeout (30000 milliseconds) waiting for a transaction response from the SharedAccess service.


Event ID:
Source:
Windows Server Update Services
Category:
Clients
Message:
Some client computers have not reported back to the server in the last 30 days. 4 have been detected so far.


Event ID:
Source:
service control manager
Message:
The Debug Diagnostic service entered the running state


Event ID:
Source:
service control manager
Category:
none
Message:
The Distributed Transaction Coordinator service terminated with service-specific error 3221229584 (0xC0001010).


Event ID:
Source:
NVRAIDSERVICE
Message:
Access failure: Critical error on disk XXXXXXX (Port: SATA 2.0).


Event ID:
Source:
NVRAIDSERVICE
Message:
Error message from one of the disks failing on an onboard nVidia nForce4 RAID controller.


Event ID:
Source:
Service Control Manager
Message:
________________________________________
EVENT # 170686
EVENT LOG System
EVENT TYPE Error
SOURCE Service Control Manager
EVENT ID 7034
COMPUTERNAME HDQ121
DATE / TIME 3/8/2011 3:29:02 PM
MESSAGE The McAfee Engine Service service terminated unexpectedly. It has done this 2 time(s).
________________________________________

Find out more about the event at http://www.myeventlog.com.




Event ID:
Source:
Service Control Manager
Message:
The start type of the Windows Modules Installer service was changed from auto start to demand start.


Event ID:
Source:
EventSentry Network Services
Category:
Snmp Trap
Message:
A SNMP trap was received:

Version: 1
Community: public
Trap Sender: vmware1.domain.local (192.168.12.55)
Trap ID: vmware.vmwProductSpecific.vmwESX.vmkLoaded (1.3.6.1.4.1.6876.4.1.6.1)

Trap Bindings:
1: vmware.vmwTraps.vmwVmID (1.3.6.1.4.1.6876.50.101) = 1
2: vmware.vmwTraps.vmwVmConfigFilePath (1.3.6.1.4.1.6876.50.102) = /vmfs/volumes/474c55f6-89ccc558-5555-001143ebb975/TestServerF/TestServerF.vmx
3: vmware.vmwVirtMachines.vmwVmTable.vmwVmEntry.vmwVmDisplayName.1 (1.3.6.1.4.1.6876.2.1.1.2.1) = TEST07-W2K3-DE


Event ID:
Source:
EventSentry Network Services
Category:
Snmp Trap
Message:
A SNMP trap was received:

Version: 3
Username: public
Trap Sender: ups41.domain.local (192.168.16.117)
Trap ID: apc (1.3.6.1.4.1.318.0.10)
Engine ID: 0x800000000300C0B74DD7A6
Security Level: Authentication and Privacy

Trap Bindings:
1: apc.apcmgmt.mtrapargs.mtrapargsString (1.3.6.1.4.1.318.2.3.3.0) = UPS: Passed a self-test.



Event ID:
Source:
EventSentry Network Services
Category:
Syslog
Message:
syslog@vmserver5.domain.local[daemon.warning]: Server Administrator: Storage Service EventID: 2264 A device is missing.: Battery 0 Controller 0


Event ID:
Source:
Microsoft-Windows-Service Pack Installer
Message:
There is not enough free disk space to install the Service Pack. Required=4834 MB.


Event ID:
Source:
User profile service
Message:
Log Name: Application
Source: Microsoft-Windows-User Profiles Service
Date: 5/12/2012 4:13:40 PM
Event ID: 1530
Task Category: None
Level: Warning
Keywords:
User: SYSTEM
Computer: NONEOFYOURBIZ2
Description:
Windows detected your registry file is still in use by other applications or services. The file will be unloaded now. The applications or services that hold your registry file may not function properly afterwards.

DETAIL -
9 user registry handles leaked from \Registry\User\S-1-5-21-664570727-300873648-2978798648-1000:
Process 664 (\Device\HarddiskVolume2\Windows\System32\lsass.exe) has opened key \REGISTRY\USER\S-1-5-21-664570727-300873648-2978798648-1000
Process 664 (\Device\HarddiskVolume2\Windows\System32\lsass.exe) has opened key \REGISTRY\USER\S-1-5-21-664570727-300873648-2978798648-1000
Process 1324 (\Device\HarddiskVolume2\Windows\System32\FBAgent.exe) has opened key \REGISTRY\USER\S-1-5-21-664570727-300873648-2978798648-1000
Process 1324 (\Device\HarddiskVolume2\Windows\System32\FBAgent.exe) has opened key \REGISTRY\USER\S-1-5-21-664570727-300873648-2978798648-1000
Process 1324 (\Device\HarddiskVolume2\Windows\System32\FBAgent.exe) has opened key \REGISTRY\USER\S-1-5-21-664570727-300873648-2978798648-1000
Process 664 (\Device\HarddiskVolume2\Windows\System32\lsass.exe) has opened key \REGISTRY\USER\S-1-5-21-664570727-300873648-2978798648-1000\Software\Microsoft\SystemCertificates\My
Process 664 (\Device\HarddiskVolume2\Windows\System32\lsass.exe) has opened key \REGISTRY\USER\S-1-5-21-664570727-300873648-2978798648-1000\Software\Microsoft\SystemCertificates\CA
Process 664 (\Device\HarddiskVolume2\Windows\System32\lsass.exe) has opened key \REGISTRY\USER\S-1-5-21-664570727-300873648-2978798648-1000\Software\Microsoft\SystemCertificates\Disallowed
Process 1324 (\Device\HarddiskVolume2\Windows\System32\FBAgent.exe) has opened key \REGISTRY\USER\S-1-5-21-664570727-300873648-2978798648-1000\Software\Microsoft\Windows\CurrentVersion\Explorer

Event Xml:
<Event xmlns="http://schemas.microsoft.com/win/2004/08/events/event">
<System>
<Provider Name="Microsoft-Windows-User Profiles Service" Guid="{89B1E9F0-5AFF-44A6-9B44-0A07A7CE5845}" />
<EventID>1530</EventID>
<Version>0</Version>
<Level>3</Level>
<Task>0</Task>
<Opcode>0</Opcode>
<Keywords>0x8000000000000000</Keywords>
<TimeCreated SystemTime="2012-05-12T20:13:40.907441900Z" />
<EventRecordID>30031</EventRecordID>
<Correlation />
<Execution ProcessID="416" ThreadID="4684" />
<Channel>Application</Channel>
<Computer>NONEOFYOURBIZ2</Computer>
<Security UserID="S-1-5-18" />
</System>
<EventData Name="EVENT_HIVE_LEAK">
<Data Name="Detail">9 user registry handles leaked from \Registry\User\S-1-5-21-664570727-300873648-2978798648-1000:
Process 664 (\Device\HarddiskVolume2\Windows\System32\lsass.exe) has opened key \REGISTRY\USER\S-1-5-21-664570727-300873648-2978798648-1000
Process 664 (\Device\HarddiskVolume2\Windows\System32\lsass.exe) has opened key \REGISTRY\USER\S-1-5-21-664570727-300873648-2978798648-1000
Process 1324 (\Device\HarddiskVolume2\Windows\System32\FBAgent.exe) has opened key \REGISTRY\USER\S-1-5-21-664570727-300873648-2978798648-1000
Process 1324 (\Device\HarddiskVolume2\Windows\System32\FBAgent.exe) has opened key \REGISTRY\USER\S-1-5-21-664570727-300873648-2978798648-1000
Process 1324 (\Device\HarddiskVolume2\Windows\System32\FBAgent.exe) has opened key \REGISTRY\USER\S-1-5-21-664570727-300873648-2978798648-1000
Process 664 (\Device\HarddiskVolume2\Windows\System32\lsass.exe) has opened key \REGISTRY\USER\S-1-5-21-664570727-300873648-2978798648-1000\Software\Microsoft\SystemCertificates\My
Process 664 (\Device\HarddiskVolume2\Windows\System32\lsass.exe) has opened key \REGISTRY\USER\S-1-5-21-664570727-300873648-2978798648-1000\Software\Microsoft\SystemCertificates\CA
Process 664 (\Device\HarddiskVolume2\Windows\System32\lsass.exe) has opened key \REGISTRY\USER\S-1-5-21-664570727-300873648-2978798648-1000\Software\Microsoft\SystemCertificates\Disallowed
Process 1324 (\Device\HarddiskVolume2\Windows\System32\FBAgent.exe) has opened key \REGISTRY\USER\S-1-5-21-664570727-300873648-2978798648-1000\Software\Microsoft\Windows\CurrentVersion\Explorer
</Data>
</EventData>
</Event>


Event ID:
Source:
Service Control Manager
Message:
The EventSentry service terminated unexpectedly. It has done this 1 time(s). The following corrective action will be taken in 60000 milliseconds: Restart the service.


Event ID:
Source:
Microsoft-Windows-CertificateServicesClient-AutoEnrollment
Message:
Certificate for %1 with Thumbprint %2 is about to expire or has already expired.


Event ID:
Source:
Service Control Manager
Message:
The VNC Server Version 4 service terminated unexpectedly. It has done this 1 time(s)


Event ID:
Source:
Service Control Manager
Message:
The Creative Audio Service service failed to start due to the following error:
The system cannot find the file specified.


Event ID:
Source:
Windows Media Player Network Sharing Service
Message:
Service 'WMPNetworkSvc' did not start correctly because CoCreateInstance(CLSID_UPnPDeviceFinder) encountered error '0x80004005'. Verify that the UPnPHost service is running and that the UPnPHost component of Windows is installed properly.


Event ID:
Source:
NtServicePack
Category:
None
Message:
Windows XP WIC installation failed.
Access is denied.


Event ID:
Source:
Microsoft-Windows-CertificateServicesClient-CertEnroll
Message:
Certificate enrollment for Local system failed to enroll for a DomainController certificate with request ID N/A from testsql.domain.local\TESTCA (The RPC server is unavailable. 0x800706ba (WIN32: 1722)).


Event ID:
Source:
Microsoft-Windows-Time-Service
Message:
NtpClient was unable to set a domain peer to use as a time source because of discovery error. NtpClient will try again in 15 minutes and double the reattempt interval thereafter. The error was: The entry is not found. (0x800706E1)


Event ID:
Source:
Service Control Manager
Message:
De Windows Presentation Foundation Font Cache 3.0.0.0-service is bij het starten vastgelopen.


Event ID:
Source:
Windows Server Update Services
Category:
Clients
Message:
No client computers have ever contacted the server.


Event ID:
Source:
Windows Server Update Services
Category:
Core
Message:
The catalog was last synchronized successfully 1 or more days ago.


Event ID:
Source:
Microsoft-Windows-DNS-Server-Service
Message:
Zone somedomain.local expired before it could obtain a successful zone transfer or update from a master server acting as its source for the zone. The zone has been shut down.


Event ID:
Source:
Service Control Manager Eventlog Provider
Message:
The windows Modules Installer Service failed to start due to the following error:The Service did not start due to a logon failure


Event ID:
Source:
Service Control Manager
Category:
Error
Message:
The Routing and Remote Access service terminated with the following service-specific error: The callback function must be invoked inline.


Event ID:
Source:
Service Control Manager
Category:
None
Message:
The Remote Desktop Services service terminated due to an error The specified file cannot be found.


Event ID:
Source:
Microsoft-Windows-ActiveDirectory_DomainService
Category:
Security
Message:
The directory has been configured to not enforce per-attribute authorization during LDAP add operations. Warning events will be logged, but no requests will be blocked. This setting is not secure and should only be used as a temporary troubleshooting step. Please review the suggested mitigations in the link below.

https://go.microsoft.com/fwlink/?linkid=2174032


Event ID:
Source:
OneApp_IGCC_WinService
Category:
none
Message:
TLBs created - Done


Event ID:
Source:
Service Control Manager
Category:
None
Message:
A timeout (30000 milliseconds) was reached while waiting for a transaction response from the AudioEndpointBuilder service.


Event ID:
Source:
Python Service
Message:
The description for Event ID 255 from source Python Service cannot be found. Either the component that raises this event is not installed on your local computer or the installation is corrupted. You can install or repair the component on the local computer.

If the event originated on another computer, the display information had to be saved with the event.

The following information was included with the event:

Exception : (1058, 'StartService', 'The service cannot be started, either because it is disabled or because it has no enabled devices associated with it.')

The message resource is present but the message was not found in the message table


Event ID:
Source:
TerminalServices-RemoteConnectionManager
Category:
None
Message:
The RD Session Host server received large number of incomplete connections. The system may be under attack.


Event ID:
Source:
Service Control Manager
Message:
The EuGdiDrv Service was not started due to the following error:
The specified path cannot be found.


Event ID:
Source:
Service Control Manager
Message:
The EuGdiDrv Service was not started due to the following error:
The specified path cannot be found.


Event ID:
Source:
Service Control Manager
Category:
None
Message:
The following boot-start or system-start driver(s) did not load:
dam


Event ID:
Source:
CertificateServicesClient-CertEnroll
Message:
Certificate enrollment for Local system failed in authentication to policy servers with ID {########-####-####-####-72067EF2E6D9} (The user name or password is incorrect. 0x8007052e (WIN32: 1326 ERROR_LOGON_FAILURE))


Event ID:
Source:
Microsoft-Windows-Directory-Services-SAM
Message:
There is no message from the SIEM logs I'm seeing from. Fields unique to this Event ID (Kibana Discover):

winlog.event_data.AccountDN
winlog.event_data.AccountSID
winlog.event_data.KeyHash


Event ID:
Source:
Service Control Manager
Message:
The FirmwareSwitchService service terminated unexpectedly. It has done this 6 time(s). The following corrective action will be taken in 30000 milliseconds: Restart the service.


Found 59 records