Admin Tip #123: Event ID descriptions truncated.

Hits: Failed to execute CGI : Win32 Error Code = 3


NT allows servers to be managed from NT workstations or Win9x workstations if the NT Server Tools are installed. I would not recommend using Win9x workstations for this purpose. If you must do so, be aware that viewing NT event logs using these tools will result in truncated event ID descriptions if the hidden administrative shares of the NT server with the event logs has been disabled. Event logs do not actually contain the description strings. What is actually stored in the event log is an event id and number. The corresponding description is pulled from the approproriate dlls. Disabling the hidden admin shares blocks access to the system executables with the embedded descriptions.

Event Log Tips:

Archiving Event Logs
Event Log explained
How to Delete Corrupt Event Viewer Log Files
Forensics: CrashOnAuditFail
Restrict access to Application and System event logs
Security Event Descriptions
Security Events Logon Type Definitions
Security Log Location
Suppress Browser Event Log Messages
Suppress Prevent logging of print jobs
System events in NT4 SP4
User Authentication with Windows NT
User Rights, Definition and List

Frank Heyne has made available a Windows NT Eventlog FAQ .

Book Recommendation:



A must have for NT administrators in corporate or governmental organizations or anyone being audited by a large outside audit firm.
It is not a secrets type guide but it has excellent sound advice and its used by PriceWaterhouse's auditors as a guide.