Article ID: 166902
Article Last Modified on 11/21/2006
HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\EventLog
Typically an application source is listed under the application subkey.
HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\
Services\EventLog\Application\sourcename
verify that the path to the .dll or .exe file is correct and the name of
the .dll or .exe file is correct. In this case the Event Viewer
application fails to load the source of the message resources. Also, if
you use %SystemRoot% or some other macro, you must use the REG_EXPAND_SZ
registry value type. Otherwise, the macro does not get expanded.
HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\
Services\EventLog\Application\sourcename
verify that the path to the .dll or .exe file is the one which contains
the expected message resources. Be careful of listing an
EventMessageFile without a path and having multiple files with the same
name. Event Viewer follows the rules to find the message source by using
the search algorithm documented in the comments for the LoadLibrary API.
Additional query words: logging evtlog
Keywords: kbapi kbeventlog kbhowto kbkernbase KB166902