<?xml version="1.0" encoding="UTF-8" ?>
<?xml-stylesheet type="text/xsl" href="http://blogs.technet.com/utility/FeedStylesheets/rss.xsl" media="screen"?><rss version="2.0" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:slash="http://purl.org/rss/1.0/modules/slash/" xmlns:wfw="http://wellformedweb.org/CommentAPI/"><channel><title>Troubleshooting Group Policy Using Event Logs </title><link>http://blogs.technet.com/gpguru/pages/troubleshooting-group-policy-using-event-logs.aspx</link><description>Group Policy Event Log Improvements Windows Vista provides a new centralized event logging system and Event Viewer. Features such as cross-log querying, scheduled task integration, and page support in filtered views make the Event Viewer the ideal tool</description><dc:language>en-US</dc:language><generator>CommunityServer 2.1 SP1 (Build: 61025.2)</generator><item><title>re: Troubleshooting Group Policy Using Event Logs </title><link>http://blogs.technet.com/gpguru/pages/troubleshooting-group-policy-using-event-logs.aspx#3224597</link><pubDate>Thu, 09 Apr 2009 20:24:11 GMT</pubDate><guid isPermaLink="false">d5e57398-b9ef-4490-9955-07cbb4e4a80d:3224597</guid><dc:creator>JoeC</dc:creator><description>&lt;p&gt;The computer name on this notice is unknown to me. &amp;nbsp;How can I find out how to block this other computer from my computer....Thanks &amp;nbsp;JoeC&lt;/p&gt;
&lt;p&gt;Log Name: &amp;nbsp; &amp;nbsp; &amp;nbsp;Microsoft-Windows-GroupPolicy/Operational&lt;/p&gt;
&lt;p&gt;Source: &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp;Microsoft-Windows-GroupPolicy&lt;/p&gt;
&lt;p&gt;Date: &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp;2/22/2008 7:11:01 AM&lt;/p&gt;
&lt;p&gt;Event ID: &amp;nbsp; &amp;nbsp; &amp;nbsp;8001&lt;/p&gt;
&lt;p&gt;Task Category: None&lt;/p&gt;
&lt;p&gt;Level: &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; Information&lt;/p&gt;
&lt;p&gt;Keywords: &amp;nbsp; &amp;nbsp; &amp;nbsp;&lt;/p&gt;
&lt;p&gt;User: &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp;SYSTEM&lt;/p&gt;
&lt;p&gt;Computer: &amp;nbsp; &amp;nbsp; &amp;nbsp;WIN-RI6Z3BLOBTK&lt;/p&gt;
&lt;p&gt;Description:&lt;/p&gt;
&lt;p&gt;Completed user logon policy processing for WIN-RI6Z3BLOBTK\Administrator in 0 seconds.&lt;/p&gt;
&lt;p&gt;Event Xml:&lt;/p&gt;
&lt;p&gt;&amp;lt;Event xmlns=&amp;quot;&lt;a rel="nofollow" target="_new" href="http://schemas.microsoft.com/win/2004/08/events/event&amp;quot;&amp;gt;"&gt;http://schemas.microsoft.com/win/2004/08/events/event&amp;quot;&amp;gt;&lt;/a&gt;&lt;/p&gt;
&lt;p&gt; &amp;nbsp;&amp;lt;System&amp;gt;&lt;/p&gt;
&lt;p&gt; &amp;nbsp; &amp;nbsp;&amp;lt;Provider Name=&amp;quot;Microsoft-Windows-GroupPolicy&amp;quot; Guid=&amp;quot;{aea1b4fa-97d1-45f2-a64c-4d69fffd92c9}&amp;quot; /&amp;gt;&lt;/p&gt;
&lt;p&gt; &amp;nbsp; &amp;nbsp;&amp;lt;EventID&amp;gt;8001&amp;lt;/EventID&amp;gt;&lt;/p&gt;
&lt;p&gt; &amp;nbsp; &amp;nbsp;&amp;lt;Version&amp;gt;0&amp;lt;/Version&amp;gt;&lt;/p&gt;
&lt;p&gt; &amp;nbsp; &amp;nbsp;&amp;lt;Level&amp;gt;4&amp;lt;/Level&amp;gt;&lt;/p&gt;
&lt;p&gt; &amp;nbsp; &amp;nbsp;&amp;lt;Task&amp;gt;0&amp;lt;/Task&amp;gt;&lt;/p&gt;
&lt;p&gt; &amp;nbsp; &amp;nbsp;&amp;lt;Opcode&amp;gt;2&amp;lt;/Opcode&amp;gt;&lt;/p&gt;
&lt;p&gt; &amp;nbsp; &amp;nbsp;&amp;lt;Keywords&amp;gt;0x4000000000000000&amp;lt;/Keywords&amp;gt;&lt;/p&gt;
&lt;p&gt; &amp;nbsp; &amp;nbsp;&amp;lt;TimeCreated SystemTime=&amp;quot;2008-02-22T13:11:01.154Z&amp;quot; /&amp;gt;&lt;/p&gt;
&lt;p&gt; &amp;nbsp; &amp;nbsp;&amp;lt;EventRecordID&amp;gt;22&amp;lt;/EventRecordID&amp;gt;&lt;/p&gt;
&lt;p&gt; &amp;nbsp; &amp;nbsp;&amp;lt;Correlation ActivityID=&amp;quot;{9B9B8490-C3A9-4708-A4AC-E5CA27C30D20}&amp;quot; /&amp;gt;&lt;/p&gt;
&lt;p&gt; &amp;nbsp; &amp;nbsp;&amp;lt;Execution ProcessID=&amp;quot;960&amp;quot; ThreadID=&amp;quot;2396&amp;quot; /&amp;gt;&lt;/p&gt;
&lt;p&gt; &amp;nbsp; &amp;nbsp;&amp;lt;Channel&amp;gt;Microsoft-Windows-GroupPolicy/Operational&amp;lt;/Channel&amp;gt;&lt;/p&gt;
&lt;p&gt; &amp;nbsp; &amp;nbsp;&amp;lt;Computer&amp;gt;WIN-RI6Z3BLOBTK&amp;lt;/Computer&amp;gt;&lt;/p&gt;
&lt;p&gt; &amp;nbsp; &amp;nbsp;&amp;lt;Security UserID=&amp;quot;S-1-5-18&amp;quot; /&amp;gt;&lt;/p&gt;
&lt;p&gt; &amp;nbsp;&amp;lt;/System&amp;gt;&lt;/p&gt;
&lt;p&gt; &amp;nbsp;&amp;lt;EventData&amp;gt;&lt;/p&gt;
&lt;p&gt; &amp;nbsp; &amp;nbsp;&amp;lt;Data Name=&amp;quot;PolicyElaspedTimeInSeconds&amp;quot;&amp;gt;0&amp;lt;/Data&amp;gt;&lt;/p&gt;
&lt;p&gt; &amp;nbsp; &amp;nbsp;&amp;lt;Data Name=&amp;quot;ErrorCode&amp;quot;&amp;gt;0&amp;lt;/Data&amp;gt;&lt;/p&gt;
&lt;p&gt; &amp;nbsp; &amp;nbsp;&amp;lt;Data Name=&amp;quot;PrincipalSamName&amp;quot;&amp;gt;WIN-RI6Z3BLOBTK\Administrator&amp;lt;/Data&amp;gt;&lt;/p&gt;
&lt;p&gt; &amp;nbsp; &amp;nbsp;&amp;lt;Data Name=&amp;quot;IsMachine&amp;quot;&amp;gt;false&amp;lt;/Data&amp;gt;&lt;/p&gt;
&lt;p&gt; &amp;nbsp; &amp;nbsp;&amp;lt;Data Name=&amp;quot;IsConnectivityFailure&amp;quot;&amp;gt;false&amp;lt;/Data&amp;gt;&lt;/p&gt;
&lt;p&gt; &amp;nbsp;&amp;lt;/EventData&amp;gt;&lt;/p&gt;
&lt;p&gt;&amp;lt;/Event&amp;gt;&lt;/p&gt;
</description></item></channel></rss>