Somehow i can't see the event descriptions on Splunk from Windows 2008 servers:
10/14/09 03:56:06 PM
LogName=Security
SourceName=Microsoft-Windows-Security-Auditing
EventCode=5156
EventType=0
ComputerName=NT150.my.domain
TaskCategory=None
OpCode=None
RecordNumber=6989
Keywords=None
Message=The description for Event ID 5156 from source Microsoft-Windows-Security-Auditing cannot be found.
Either the component that raises this event is not installed on your local computer or the installation is corrupted.
You can install or repair the component on the local computer.
If the event originated on another computer, the display information had to be saved with the event.
The following information was included with the event:
The specified resource language ID cannot be found in the image file.
System %%14593 172.31.6.150 8 172.31.4.16 0 %%14611
Anyone an idea?