So there is a lot of overlap and you can't just search for "Event ID 122" because you'll get a lot of nonsense. RCBNSA's error codes are probably not going to be in any regular list. Wednesday, April 18, 2012 11:24 AM Reply | Quote Answers 0 Sign in to vote Hello, this list doesn't exist that way.

I am the only admin in the company and I'm expected to know everything ther is about these servers. We have 450 users and 106 servers.

Windows 4799 A security-enabled local group membership was enumerated Windows 4800 The workstation was locked Windows 4801 The workstation was unlocked Windows 4802 The screen saver was invoked Windows 4803 The

Understanding the Interface When you first open Event Viewer, you'll notice it uses the three-pane configuration like many of the other administrative tools in Windows, although in this case, there are

It gets the work done but it still leaves the puzzler out there – why did the system crash in the first place? Windows 6403 BranchCache: The hosted cache sent an incorrectly formatted response to the client's message to offer it data.

Windows 6406 %1 registered to Windows Firewall to control filtering for the following: Windows 6407 %1 Windows 6408 Registered product %1 failed and Windows Firewall is now controlling the filtering for

Each Windows component will most likely have its own log.

An event, as described by Microsoft, is any significant happening in a system or in a program that should be brought to a user's attention.

This log is disabled by default and only a user with administer privileges can view this log. To perform a search you will need details like Event ID, Event Source, Message Text, File Name. Most of the solutions are contributed by users from their experience.

The notification is duly logged by the system in a log (the event logs) which we can see using the Event Viewer. Using Filters and Custom Views Rather than going through the zillion folders of custom event logs and trying to find everything that you're looking for, you can create a custom view You have to look on TechNet for specific ones. It is impossible to list all of them.

How do synchronization and federation play in?

Windows 4618 A monitored security event pattern has occurred Windows 4621 Administrator recovered system from CrashOnAuditFail Windows 4622 A security package has been loaded by the Local Security Authority.

All event log messages have a unique event ID. Windows 538 User Logoff Windows 539 Logon Failure - Account locked out Windows 540 Successful Network Logon Windows 551 User initiated logoff Windows 552 Logon attempt using explicit credentials Windows 560 Once you've selected what you want in the view, you'll be asked to give the custom view a name, and then you can use it to see just the events that

Level – This tells you how severe the event is – Information just tells you that something has changed or a component has started, or something has completed.