Fix the Event Log service error ‘Access Denied’ after a restore of a Windows Server 2008 server

After preforming a disaster recovery of a Windows Server 2008 server, the Event Log service wouldn’t start. Manually trying to start it resulted in an Access Denied error.

A very helpful post in the Technet Forums, pointed me in the right direction: The correct permission on the event logs folder was missing.

Executing the following command fixed my problem:

ICACLS C:\Windows\System32\winevt\logs /grant *S-1-5-80-880578595-1860270145-482643319-2788375705-1540778122:(F)

This gives the EventLog group full permission on the folder C:\Windows\System32\winevt\logs.


About Yuri de Jager
Technology Addict

Leave a Reply

Fill in your details below or click an icon to log in: Logo

You are commenting using your account. Log Out /  Change )

Google photo

You are commenting using your Google account. Log Out /  Change )

Twitter picture

You are commenting using your Twitter account. Log Out /  Change )

Facebook photo

You are commenting using your Facebook account. Log Out /  Change )

Connecting to %s

%d bloggers like this: