Event ID 62464 - Getting Thousands of Log Entries
Hello all,
If your event logs are getting overwhelmed by this informational, there is a way to suppress such loggings.
Look at the followup post for the solution.
Solved!
Go to Solution.
Here's the solution:
CAUTION: The solution requires a registry edit so proceed with caution!
This solution is courtesy of "Your Fairy Godmother" (that is her real forum name)!
This is a way to suppress those useless informational logs:
Edit the registry value:
HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\services\Atierecord\eRecordEnable and set it to 0.
Then reboot.
Note: You will have to do the above every time you install a new driver (which should not be often).
This solution was extracted directly from the thread below. All praise for this solution goes to "Your Fairy Godmother."
http://forums.amd.com/game/messageview.cfm?catid=260&threadid=138421
Similar Messages
-
Thousands of log entries for systemd-tmpfiles-clean.timer on boot
I'm running a 32 bit Arch install as a VMware ESXi 5.1 guest. Whenever the guest boots up, I get several thousand of the following entries in the system log:
Feb 18 12:49:01 squid systemd[1]: systemd-tmpfiles-clean.timer: time change, recalculating next elapse.
The most recent boot had almost 20,000 entries within 5 seconds:
$ sudo journalctl -b | grep systemd-tmpfiles-clean.timer | wc -l
19693
$ sudo journalctl -b | grep systemd-tmpfiles-clean.timer | sed -n '1p;$p'
Feb 18 12:49:01 squid systemd[1]: systemd-tmpfiles-clean.timer: time change, recalculating next elapse.
Feb 18 12:49:06 squid systemd[1]: systemd-tmpfiles-clean.timer: time change, recalculating next elapse.
I've pasted the entry into Google but have not come up with anything helpful.
I have disabled host-guest time sync:
$ vmware-toolbox-cmd timesync status
Disabled
There is a NTP daemon running that syncs time with a single windows server (which is also a guest on the same ESXi host).
As far as I'm aware there shouldn't be anything else playing with the time, but theres obviously something going on.
Can anyone please help me troubleshoot?I've had the same problem and I don't know what's going wrong. But I have a workaround:
If you're booting into a graphical environment you can disable the vmtoolsd service
# systemctl disable vmtoolsd
and add the following line to your ~/.xinitrc:
vmware-user-suid-wrapper
The ~/.xinitrc will start the vmtoolsd service then.
This solved two problems for me:
1. No more messages like you posted in my log file.
2. The virtual machine shuts down promptly (see vmtoolsd not stopping)
Last edited by BertiBoeller (2013-03-14 13:40:21) -
Removed standby but getting interesting alert log entry
So, we had multiple set ups of primary database in our local data center, standby in remote location.
We're in the process of shutting down our remote location and have shut down our standbys gracefully, i.e., shutdown managed standby mode, removed archive_log_dest, changed archive_log_dest_state, etc. However, in some primary databases, I'm seeing a weird entry in the alert log:
Changing destination 2 from remote to local during archival of log#: 2 sequence#: 48708 thread#: 1
If I check my local destination, the archive log is created fine. In the remote location, no archives are being created.
I've not found anything on Google, Metalink, anywhere! Has anyone else seen this before, and if so, do I need to worry about it?
Oracle version is 11.1.0.7Hello;
Its just information. You can ignore it.
Went back to some 2010 alert logs and found :
network reconnect abandoned
Attempting destination LOG_ARCHIVE_DEST_2 network reconnect
Setting 'active' archival for destination LOG_ARCHIVE_DEST_2Not much chance of finding here as all old version of Oracle are gone and a SAN move makes old alert logs rare. Still it just information or Oracle would throw an error.
Best Regards
mseberg
Edited by: mseberg on Jul 31, 2012 11:32 AM
Later
Tried to recreate message using several combinations of the parameters you listed. Unable to recreate, but only have 11.2.0.3.0 to test on.
Edited by: mseberg on Jul 31, 2012 12:44 PM -
No Log entry while executing web service
Hi,
I have a web service which is deployed successfully to a server in the Weblogic
Workshop domain.
When I try to test the methods of the web service using the Test form, sometimes,
I get a message 'No Log Entry'. When I reploy the application, it starts working
properly.
There is no problem with the code. Could someone please tell me as to why I might
be getting the 'No Log Entry' message randomly.
Thanks,
AparnaMy guess is that you are using the tutorial "Creating a SOAP Web Service". This one has a couple of errors in it:
1. The directory it tells you to deploy the class to the following location:
<JDeveloper_home>\soap\webapps\soap\soap\WEB-INF\lib
when in fact it should be:
<JDeveloper_home>\soap\lib\soap\soap\WEB-INF\lib
2. This tutorial also says you do not have to re-start OC4J; in this case you do.
If you are doing the J2EE Web service tutorial a re-start should not be required. One other potential cause of this kind of error can be because your proxy server is set on in Tools->Preferences->Proxy Server. Turn it off and this might fix the problem - my guess, however, is that your problem is either with step 1 or step 2 above.
Mike. -
Mysterious repeat log entries in System events log
I tried unsuccessfully to share internet connection with 2 iMacs without router(That doesn't matter). But after this, my iMac (24" 2.8 GHz) not networked or on internet now shows this repeated log entries every minute:
com.apple.launchd[1] (com.apple.InternetSharing): Throttling respawn: Will start in 10 seconds
This message gets repeated every minute on System events log. Daily, Monthly maintenance was not done automatically earlier today on this iMac (usually it did without any problem) which was on all-night.
I checked with Disk Utility, repaired permissions. Although no problems in working, this continuous log writings disturbs me.
Thanks for any help & Happy New Year!
Best.Thanks, V.K. Did that (was asked password). System log showed after restart:
com.apple.launchd[1] (com.apple.InternetSharing[152]): Exited with exit code: 1
com.apple.launchd[1] (com.apple.InternetSharing): Throttling respawn: Will start in 10 seconds
com.apple.launchd[1] (com.apple.InternetSharing153): Exited with exit code: 1
com.apple.launchd[1] (com.apple.InternetSharing): Throttling respawn: Will start in 10 seconds
Then it started again the same way as above - with each aditional line each time as shown above. Thanks for sticking with me on this. Hope you will offer other suggestions.
Best. -
Hi, I am trying to create an Event log entry in Event viewer in Windows 7 when the processor exceeds a set percentage of usage. I have unsuccessfully tried doing this through a Data Collection Set in the User Defined folder to monitor CPU usage
and to trigger an Alert and log an entry when the CPU exceeds a set percentage of usage. Any suggestions, and please if possible keep them simple and easy to follow, I am not to familar with Windows 7.Hi, I am trying to create an Event log entry in Event viewer in Windows 7 when the processor exceeds a set percentage of usage. I have unsuccessfully tried doing this through a Data Collection Set in the User Defined folder to monitor CPU usage
and to trigger an Alert and log an entry when the CPU exceeds a set percentage of usage. Any suggestions, and please if possible keep them simple and easy to follow, I am not to familar with Windows 7. -
Account locked out events are not getting in active directory security event logs
Account locked out events are not getting in active directory security event logs for some users. I can see that the user is locked and when i tried to find out the event in sec log at DC but couldnt able to find. It is only happening for some users.
not for the all users.In addition.
Check the ADDS Audit.
Active Directory Services Audit - Document references
Regards~Biswajit
Disclaimer: This posting is provided & with no warranties or guarantees and confers no rights.
MCP 2003,MCSA 2003, MCSA:M 2003, CCNA, MCTS, Enterprise Admin
MY BLOG
Domain Controllers inventory-Quest Powershell
Generate Report for Bulk Servers-LastBootUpTime,SerialNumber,InstallDate
Generate a Report for installed Hotfix for Bulk Servers -
Can someone explain how log entries work in FMS 3? If I play
one FLV file, there are 5 entries. I am starting with a clean
logfile to see how things are logged and I see:
Connect
Play
Stop
Play
Stop
A total of these 5 entries has a throughput of 36MB for this
one play. Is that correct? Is there an expert who knows how logging
works in FMS3?
TIA.shamus1 wrote:
for a long time i had been getting this in my logs
(765310.500000) CWMP: Set Parameter by TR069 failure 9005: Invalid parameter name
but since the log entries
21:48:56, 13 Sep.
(864052.520000) CWMP: Session start now. Event code(s): '7 TRANSFER COMPLETE,M Download,4 VALUE CHANGE'
21:48:55, 13 Sep.
(864051.130000) CWMP: Initializing transaction for event code M Download
21:48:55, 13 Sep.
(864051.130000) transfer completed successfully
21:48:52, 13 Sep.
(864048.200000) CWMP: session completed successfully
21:48:52, 13 Sep.
(864047.980000) CWMP: Download file, FileType=4, FileName=4a-5app-bundle-v3-package.tar.gz.aes.rsa.signed, Username=, CommandKey=1736293426
i am now getting
21:48:58, 14 Sep.
(950453.180000) CWMP: Set Parameter by TR069 Success
21:48:56, 14 Sep.
(950450.560000) CWMP: Set Parameter by TR069 Success
This may not be significant as I have had both the success and failure messages after the download of the file. -
Add log entries to an emailed alerts
Is there any way to add the logs entries that is included in a report/incident in an emailed alert. In other words, instead of just having the link to the mars emailed in the alert, have the actual data that the user will see once they enter the mars.
I have been working on this one for a few months now. Out of the box, no, there is not. There was a feature request added into 6.0.3 that was supposed to add this functionality but it got left out because it was going to be a lot of work. I have opened a new case with TAC (611170537) and the guy confirmed that the engineers added some data to the email alerts that was already being processed and wouldnt need much additional coding.
I have filed a new feature request with my local Cisco team but I do not know the bug id yet. Basically what i want is the ability to create an email template which will have the ability to include variables in the email, so the raw message or matched event ID can be included. I was told by the guy at TAC that when he brought up this idea to the developers, they werent too excited because it seemed like a lot of work and there didnt seem to be a business case for it. So if anyone wants to see this feature added, please contact your local account team and include my latest case #. I will include the bug id once I get one. The only way to get this feature added is to request it. -
Power supply related log entries?
(This question was posted all day yesterday, with no replies, in the iMac G5 forum. Perhaps someone here will have some idea what these logs mean in this situation.)
I recently had the PSU and the Logic Board replaced (two tries to get it right) for the sudden shutdown/ defective capacitor issue. Everything, fingers crossed, seems to be functioning properly, at least, so far. But, now that I'm completely paranoid about this issue, I've noticed log entries "AppleSMU -- shutdown cause = 1" or "AppleSMU -- shutdown cause = 2" (at least, not the dreaded = -110) in the log just after bootup. I know these are often related to the PSU issue and, since my shutdowns have been normal, I don't understand why they are appearing or what they mean.Here's the latest log from after an SMU reset. (Rebooted after that and only got the usual "shutdown cause =1.") The message in question is in bold. Should I be thinking of a corrupted cache, or is this a possible indication that the latest PSU is also on the way out? My shutdowns (as well as everything else, +so far+) appear to be normal, but this entry "localhost kernel[0]: AppleSMU -- shutdown cause = -110," is the log I was getting from when the computer was shutting down all the time, which is very strange. Thanks for any help.
Nov 19 23:23:14 Macintosh-3 shutdown[644]: SHUTDOWN_TIME: 1258690994 83525
Nov 19 23:23:14 Macintosh-3 com.apple.loginwindow[27]: Shutdown NOW!
Nov 19 23:23:14 Macintosh-3 com.apple.loginwindow[27]: System shutdown time has arrived^G^G
Nov 19 23:23:14 Macintosh-3 mDNSResponder mDNSResponder-176.3 (Jan 27 2009 14:51:59)[26]: stopping
Nov 19 23:23:14 Macintosh-3 com.apple.SystemStarter[20]: Stopping HP Trap Monitor
Nov 19 23:23:14 Macintosh-3 com.apple.SystemStarter[20]: Stopping HP IO Monitor
Nov 19 23:23:14 Macintosh-3 com.apple.usbmuxd[18]: stopping.
Nov 20 06:56:40 localhost kernel[0]: Darwin Kernel Version 9.8.0: Wed Jul 15 16:57:01 PDT 2009; root:xnu-1228.15.4~1/RELEASE_PPC
Nov 20 06:56:34 localhost com.apple.launchctl.System[2]: /dev/disk0s3 on / (hfs, local, journaled)
Nov 20 06:56:37 localhost com.apple.launchctl.System[2]: launchctl: Please convert the following to launchd: /etc/mach_init.d/dashboardadvisoryd.plist
Nov 20 06:56:37 localhost com.apple.launchd[1] (com.apple.usbmuxd): Unknown key for boolean: EnableTransactions
Nov 20 06:56:37 localhost com.apple.launchd[1] (org.cups.cupsd): Unknown key: SHAuthorizationRight
Nov 20 06:56:37 localhost com.apple.launchd[1] (org.ntp.ntpd): Unknown key: SHAuthorizationRight
Nov 20 06:56:37 localhost com.apple.launchd[1] (org.x.privileged_startx): Unknown key for boolean: EnableTransactions
Nov 20 06:56:39 localhost kextd[12]: 428 cached, 0 uncached personalities to catalog
Nov 20 06:56:40 localhost kernel[0]: standard timeslicing quantum is 10000 us
Nov 20 06:56:40 localhost kernel[0]: vmpagebootstrap: 313347 free pages and 14333 wired pages
Nov 20 06:56:40 localhost kernel[0]: migtable_maxdispl = 79
Nov 20 06:56:40 localhost kernel[0]: 103 prelinked modules
Nov 20 06:56:40 localhost kernel[0]: Loading security extension com.apple.security.TMSafetyNet
Nov 20 06:56:40 localhost kernel[0]: calling mpopolicyinit for TMSafetyNet
Nov 20 06:56:40 localhost kernel[0]: Security policy loaded: Safety net for Time Machine (TMSafetyNet)
Nov 20 06:56:40 localhost kernel[0]: Loading security extension com.apple.nke.applicationfirewall
Nov 20 06:56:40 localhost kernel[0]: Loading security extension com.apple.security.seatbelt
Nov 20 06:56:40 localhost kernel[0]: calling mpopolicyinit for mb
Nov 20 06:56:40 localhost kernel[0]: Seatbelt MACF policy initialized
Nov 20 06:56:40 localhost kernel[0]: Security policy loaded: Seatbelt Policy (mb)
Nov 20 06:56:40 localhost kernel[0]: Copyright (c) 1982, 1986, 1989, 1991, 1993
Nov 20 06:56:40 localhost kernel[0]: The Regents of the University of California. All rights reserved.
Nov 20 06:56:40 localhost kernel[0]: MAC Framework successfully initialized
Nov 20 06:56:40 localhost kernel[0]: using 6553 buffer headers and 4096 cluster IO buffer headers
Nov 20 06:56:40 localhost kernel[0]: AirPort_Brcm43xx::probe: 02956680, 0
Nov 20 06:56:40 localhost kernel[0]: AppleKauaiATA shasta-ata features enabled
Nov 20 06:56:40 localhost kernel[0]: DART enabled
Nov 20 06:56:40 localhost kernel[0]: FireWire (OHCI) Apple ID 52 PCI now active, GUID 001124fffe343a86; max speed s400.
Nov 20 06:56:40 localhost kernel[0]: mbinit: done
Nov 20 06:56:40 localhost kernel[0]: Security auditing service present
Nov 20 06:56:40 localhost kernel[0]: BSM auditing present
Nov 20 06:56:40 localhost kernel[0]: rooting via boot-uuid from /chosen: 06DF991F-E8CC-32A4-B78C-1791214651DE
Nov 20 06:56:40 localhost kernel[0]: Waiting on <dict ID="0"><key>IOProviderClass</key><string ID="1">IOResources</string><key>IOResourceMatch</key><string ID="2">boot-uuid-media</string></dict>
*Nov 20 06:56:40 localhost kernel[0]: AppleSMU -- shutdown cause = -110*
Nov 20 06:56:40 localhost kernel[0]: wl0: Broadcom BCM4320 802.11 Wireless Controller
Nov 20 06:56:40 localhost kernel[0]: 4.170.25.8.2Got boot device = IOService:/MacRISC4PE/ht@0,f2000000/AppleMacRiscHT/pci@3/IOPCI2PCIBridge/k2-sat a-root@C/AppleK2SATARoot/k2-sata@0/AppleK2SATA/ATADeviceNub@0/AppleATADiskDriver /IOATABlockStorageDevice/IOBlockStorageDriver/WDC WD800JD-40GBB2 WDC WD800JD-40GBB2/IOApplePartitionScheme/Untitled@3
Nov 20 06:56:40 localhost kernel[0]: BSD root: disk0s3, major 14, minor 2
Nov 20 06:56:40 localhost kernel[0]: AppleSMU::PMU vers = 0x000d004c, SPU vers = 0x15, SDB vers = 0x01,
Nov 20 06:56:40 localhost kernel[0]: Jettisoning kernel linker.
Nov 20 06:56:40 localhost kernel[0]: Resetting IOCatalogue.
Nov 20 06:56:40 localhost kernel[0]: Matching service count = 1
Nov 20 06:56:40 localhost kernel[0]: Matching service count = 3
Nov 20 06:56:40: --- last message repeated 4 times ---
Nov 20 06:56:40 localhost kernel[0]: Matching service count = 4
Nov 20 06:56:40 localhost kernel[0]: NVDANV30HAL loaded and registered.
Nov 20 06:56:40 localhost kernel[0]: PowerMac8,1: stalling for module
Nov 20 06:56:42 localhost bootlog[40]: BOOT_TIME: 1258718192 0
Nov 20 06:56:42 localhost fseventsd[31]: bumping event counter to: 0x1d08d5e (current 0x0) from log file '0000000001d0337a'
Nov 20 06:56:43 localhost kernel[0]: IPv6 packet filtering initialized, default to accept, logging disabled
Nov 20 06:56:46 localhost kernel[0]: Matching service count = 1
Nov 20 06:56:46 localhost DirectoryService[36]: Launched version 5.7 (v514.25)
Nov 20 06:56:47 localhost kernel[0]: PowerMac81SystemFansCtrlLoop::calculateNewTarget() linkedControl not ready
Nov 20 06:56:47 localhost /System/Library/CoreServices/loginwindow.app/Contents/MacOS/loginwindow[27]: Login Window Application Started -- Threaded auth
Nov 20 06:56:47 localhost rpc.statd[22]: statd.notify - no notifications needed
Nov 20 06:56:47 localhost kernel[0]: UniNEnet: Ethernet address 00:11:24:34:3a:86
Nov 20 06:56:48 localhost kernel[0]: AirPort_Brcm43xx: Ethernet address 00:0a:95:f4:79:08
Nov 20 06:56:49 localhost iStatLocalDaemon[45]: Waiting for connections on port 5204.
Nov 20 06:56:50 localhost mDNSResponder mDNSResponder-176.3 (Jan 27 2009 14:51:59)[26]: starting
Nov 20 06:56:50 localhost com.apple.usbmuxd[18]: usbmuxd-176 built for iTunesNine on Jul 20 2009 at 13:06:53, running 32 bit
Nov 20 06:56:51 localhost com.paceap.pacesupport[44]: kextload: extension /System/Library/Extensions/PACESupportFamily.kext/Contents/PlugIns/PACESupportL eopard.kext is already loaded
Nov 20 06:56:52 localhost /usr/sbin/ocspd[67]: starting
Nov 20 06:56:55 localhost loginwindow[27]: Login Window Started Security Agent
Nov 20 06:56:57 localhost kernel[0]: AirPort: Link Down on en1
Nov 20 06:56:57 localhost kextd[12]: writing kernel link data to /var/run/mach.sym
Nov 20 06:56:58 Macintosh-3 configd[38]: setting hostname to "Macintosh-3.local"
Nov 20 06:56:59 Macintosh-3 kernel[0]: AirPort: Link Up on en1
Nov 20 06:56:59 Macintosh-3 kernel[0]: SetCryptoKey T: len 16, idx 0
Nov 20 06:56:59 Macintosh-3 kernel[0]: SetCryptoKey R: len 32, idx 2
Nov 20 06:57:02 Macintosh-3 com.apple.SystemStarter[20]: PACESupport - launchd already started us
Nov 20 06:57:02 Macintosh-3 com.apple.SystemStarter[20]: Starting HP IO Monitor
Nov 20 06:57:02 Macintosh-3 com.apple.SystemStarter[20]: Starting HP Trap Monitor
Nov 20 06:57:26 Macintosh-3 SecurityAgent[82]: NSExceptionHandler has recorded the following exception:\nNSRangeException -- * -[NSCFArray objectAtIndex:]: index (0) beyond bounds (0)\nStack trace: 0x39dbc 0x9329a4ec 0x92303c00 0x92303c38 0x90448180 0x709c8 0x5bee4 0x6edd8 0x637b4 0x649c4 0x6c678 0x9140c358 0x9140c28c 0x9144dc94 0x9144c0f4 0x914092dc 0x74764 0x913dc680 0x913498d8 0x11e14 0x2db0
Nov 20 06:57:33 Macintosh-3 authorizationhost[81]: MechanismInvoke 0x12d5f0 retainCount 2
Nov 20 06:57:34 Macintosh-3 SecurityAgent[82]: MechanismInvoke 0x101660 retainCount 1
Nov 20 06:57:34 Macintosh-3 SecurityAgent[82]: NSSecureTextFieldCell detected a field editor ((null)) that is not a NSTextView subclass designed to work with the cell. Ignoring...
Nov 20 06:57:34 Macintosh-3 SecurityAgent[82]: NSExceptionHandler has recorded the following exception:\nNSRangeException -- * -[NSCFArray objectAtIndex:]: index (0) beyond bounds (0)\nStack trace: 0x39dbc 0x9329a4ec 0x92303c00 0x92303c38 0x90448180 0x709c8 0x5bee4 0x6edd8 0x637b4 0x68368 0x774a4 0xe068 0x14200 0x13f64 0xdb58 0x9047f8f0 0x9227426c 0x92296634 0x900bbb18 0x900bb93c 0x900bb77c 0x91350248 0x9134fc00 0x913498a0 0x11e14 0x2db0
Nov 20 06:57:34 Macintosh-3 loginwindow[27]: Login Window - Returned from Security Agent
Nov 20 06:57:34 Macintosh-3 SecurityAgent[82]: MechanismDestroy 0x101660 retainCount 1
Nov 20 06:57:34 Macintosh-3 authorizationhost[81]: MechanismDestroy 0x12d5f0 retainCount 2
Nov 20 06:57:34 Macintosh-3 loginwindow[27]: USER_PROCESS: 27 console
Nov 20 06:57:34 Macintosh-3 com.apple.launchd[1] (com.apple.UserEventAgent-LoginWindow[80]): Exited: Terminated
Nov 20 06:57:34 Macintosh-3 com.apple.launchctl.Aqua[110]: launchctl: Couldn't stat("/etc/machinit_peruser.d"): No such file or directory
Nov 20 06:57:34 Macintosh-3 com.apple.launchd[107] (com.apple.AirPortBaseStationAgent): Unknown key for boolean: EnableTransactions
Nov 20 06:57:34 Macintosh-3 com.apple.launchd[107] (org.x.startx): Unknown key for boolean: EnableTransactions
Nov 20 06:57:35 Macintosh-3 com.apple.launchd[1] (com.apple.aslmanager): Throttling respawn: Will start in 2 seconds
Nov 20 06:57:42 Macintosh-3 /System/Library/CoreServices/coreservicesd[51]: SFLSharePointsEntry::CreateDSRecord: dsCreateRecordAndOpen(.... Public Folder) returned -14135
Nov 20 06:57:49 Macintosh-3 SystemUIServer[125]: MenuCracker 2.0 (/Library/Application Support/iStat local/extras/MenuCracker.menu)\n See http://sourceforge.net/projects/menucracker\n MenuCracker is now loaded. Ready to accept new menu extras. Ignore the failure message that follows.
Nov 20 06:57:49 Macintosh-3 SystemUIServer[125]: failed to instantiate and get the principal class of bundle: NSBundle </Library/Application Support/iStat local/extras/MenuCracker.menu> (loaded)
Nov 20 06:57:49 Macintosh-3 SystemUIServer[125]: MenuCracker: Allowing "iStatMenusCPU".
Nov 20 06:57:49 Macintosh-3 SystemUIServer[125]: MenuCracker: Allowing "iStatMenusDisks".
Nov 20 06:57:50 Macintosh-3 SystemUIServer[125]: MenuCracker: Allowing "iStatMenusMemory".
Nov 20 06:57:50 Macintosh-3 SystemUIServer[125]: MenuCracker: Allowing "iStatMenusNetwork".
Nov 20 06:57:50 Macintosh-3 SystemUIServer[125]: MenuCracker: Allowing "iStatMenusTemps".
Message was edited by: WZZZ -
Hello,
I have a RV325 Router. Entries in the System Log are mysterious to me and all my search results and reading are not relevant.
The Event-Type is - "Kernel", and the Message is "kernel: wrong ip[0],not_list[0]"
The Log entries occur every few minutes.
Does anyone know what this log entry signifies?
Also, does anyone know how to get an answer to any question from Cisco?
Thanks,
Michael DownsHello
yes, there are several existing discussions about same syslog message, like here, here or here, but neither of discussions points to solution.
If you device is still under warranty I would suggest you to open service request to Cisco Small Business Support Center to make this issue fixed permanently. -
Incorrect log entries from iPhone and iPad
Hello iPhone/iPad users and admins
For some time now, I have the problem, that I find the following entries in my log files of a business firewall.
Here are the log entries
# Time Message Source Destination Notes Category Priority Rule
1 03/19/2011 23:43:53.640 IP spoof dropped Alert Intrusion Prevention 10,157,205,175, 62 348, X3 192.168.210.1, 8080, X8 MAC address: 40: a6: d9: 9a: f1: 2e
# Time Message Source Destination Notes Category Priority Rule
1 03/29/2011 09:38:00.352 IP spoof dropped Alert Intrusion Prevention 10.153.53.141, 51 561, X3 192.168.210.1, 8080, X8 MAC address: 40: a6: d9: 9a: f1: 2e
# Time Message Source Destination Notes Category Priority Rule
1 04/18/2011 18:23:03.560 IP spoof dropped Alert Intrusion Prevention 10,150,154,123, 49 515, X3 192.168.210.1, 8080, X8 MAC address: 40: a6: d9: 9a: f1: 2e
# Time Message Source Destination Notes Category Priority Rule
1 04/26/2011 08:20:49.544 IP spoof dropped Alert Intrusion Prevention 10.120.159.79, 56 770, X3 17,250,248,212, 443, X8, switchboard.me.com MAC address: d8: 30:62:81: f6: 7a
# Time Message Source Destination Notes Category Priority Rule
1 27/04/2011 02:40:35.496 IP spoof dropped Alert Intrusion Prevention 10.120.159.79, 56 860, X3 17,250,248,212, 443, X8 MAC address: d8: 30:62:81: f6: 7a
# Time Message Source Destination Notes Category Priority Rule
1 06/05/2011 21:57:47.928 IP spoof dropped Alert Intrusion Prevention 10.166.15.122, 61 764, X3 17,250,248,212, 443, X8 MAC address: d8: 30:62:81: f6: 7a
and so on .....
After a long search, I found out that it is my iPhone and my iPad.
How do I find out which app is behaving wrongly , because along side with the wrong IP the equipment does get a correct IP and can be used quite normal on the Internet.
Do I have to use the developer environment to test out each APP or can I find it out with a packet capture?
Is there some other way or do I have to denistall all apps and activate one by one an test the logfiles?
This would be a dayswork and I hope I can go around this.
Thanky you for any relevant information.
Kind regards
ThomasHi A. Hinsen!
It's the same with me. I sync a lot of pictures to the iPad setting "Selected albums, events ..." and using iPhoto on my Mac. But when I added some pictures to an iPhoto-event and try to sync them again, iTunes automatic set "All pictures ..." and the iPad do not contain any picture. Allthough I just looked at them before I started the synchronisation.
I hate it because the synchronisation need about an hour. And I am in a hurry.
Reinhold -
Strange HH5 TR069 Log entries.
01:12:15, 07 Feb.
(133394.140000) CWMP: Set Parameter by TR069 Success
01:11:54, 07 Feb.
(133372.840000) CWMP: Set Parameter by TR069 Success
01:11:53, 07 Feb.
(133371.310000) CWMP: Set Parameter by TR069 Success
01:11:27, 07 Feb.
(133345.840000) CWMP: Set Parameter by TR069 Success
00:42:13, 07 Feb.
(131592.070000) CWMP: Set Parameter by TR069 Success
00:41:52, 07 Feb.
(131570.770000) CWMP: Set Parameter by TR069 Success
00:41:51, 07 Feb.
(131569.250000) CWMP: Set Parameter by TR069 Success
00:41:25, 07 Feb.
(131543.720000) CWMP: Set Parameter by TR069 Success
00:21:19, 07 Feb.
(130338.140000) CWMP: session closed due to error: HTTP authentication error
00:21:19, 07 Feb.
(130338.140000) CWMP: HTTP authentication fail from https://pbthdm.bt.mo
00:21:17, 07 Feb.
(130335.730000) CWMP: Server URL: https://pbthdm.bt.mo; Connecting as user: ACS username
00:21:17, 07 Feb.
(130335.720000) CWMP: Session start now. Event code(s): '1 BOOT,4 VALUE CHANGE,2 PERIODIC'
00:12:12, 07 Feb.
(129790.850000) CWMP: Set Parameter by TR069 Success
00:11:51, 07 Feb.
(129769.550000) CWMP: Set Parameter by TR069 Success
00:11:49, 07 Feb.
(129768.040000) CWMP: Set Parameter by TR069 Success
00:11:23, 07 Feb.
(129741.830000) CWMP: Set Parameter by TR069 Success
Iv'e previously posted on another thread regarding .203 HH5 firmware update, but this is a new problem, which is strange.
Hence a new topic.
Two or three times per day there's a log entry suggesting an imminent reboot and parameter change. The authentication always fails so the boot is not implemented. This has been going on for 2 days following some sort of wifi checking software imposed on the hub - another TR069 event.
Also I get the Set Parameter by TR069 Success every 30 mins - only when the laptop and every other device is off or not connected to wifi - e.g. overnight.
At this rate there will be a stack overflow in the logs, which could overwrite everything else. Hope that part the firmware can handle this situation!!
Any ideas - I performed a factory reset of the Hub on 05-02-2015.Further progress.
Performed factory reset at 8-00am today.
This time the reset was done with a wooden cocktail stick pushed into the recess at the rear of the hub.
There was no backup or restore of settings, as this in done quickly here, just disable 5GHz sync, separate SSids, disable smat setup , disable smart wireless, change admin password.
A factory reset should in principle, just be changing the logic input into the hub CPU reset pin.
That's how it was always done in the past, from my own experience in industry with industrial CPUs.
Perhaps the HH series has its' own rules, as it does with remote management - keep the customer in the dark, etc, as you would with mushrooms.
Results after being out for 2 hours:-
09:12:46, 09 Feb.
( 3794.970000) CWMP: Set Parameter by TR069 Success
09:12:22, 09 Feb.
( 3770.890000) CWMP: Set Parameter by TR069 Success
08:43:08, 09 Feb.
( 2016.490000) CWMP: Set Parameter by TR069 Success
08:42:46, 09 Feb.
( 1995.190000) CWMP: Set Parameter by TR069 Success
08:42:45, 09 Feb.
( 1994.150000) CWMP: Set Parameter by TR069 Success
08:42:22, 09 Feb.
( 1970.530000) CWMP: Set Parameter by TR069 Success
08:13:36, 09 Feb.
( 245.150000) CWMP: session completed successfully
08:13:33, 09 Feb.
( 242.460000) CWMP: HTTP authentication success from https://pbthdm.bt.mo
08:13:32, 09 Feb.
( 240.940000) CWMP: Server URL: https://pbthdm.bt.mo; Connecting as user: ACS username
08:13:32, 09 Feb.
( 240.930000) CWMP: Session start now. Event code(s): '6 CONNECTION REQUEST'
08:13:32, 09 Feb.
( 240.660000) CWMP: Initializing transaction for event code 6 CONNECTION REQUEST
08:13:31, 09 Feb.
( 240.130000) CWMP: session completed successfully
08:13:31, 09 Feb.
( 239.940000) CWMP: HTTP authentication success from https://pbthdm.bt.mo
08:13:29, 09 Feb.
( 238.260000) CWMP: Server URL: https://pbthdm.bt.mo; Connecting as user: ACS username
08:13:29, 09 Feb.
( 238.260000) CWMP: Session start now. Event code(s): '6 CONNECTION REQUEST'
08:13:29, 09 Feb.
( 237.990000) CWMP: session completed successfully
08:13:16, 09 Feb.
( 225.020000) CWMP: Set Parameter by TR069 Success
08:13:13, 09 Feb.
( 221.890000) CWMP: Set Parameter by TR069 Success
08:13:09, 09 Feb.
( 217.660000) CWMP: Initializing transaction for event code 6 CONNECTION REQUEST
08:13:07, 09 Feb.
( 215.470000) CWMP: Set Parameter by TR069 Success
08:13:06, 09 Feb.
( 215.290000) CWMP: HTTP authentication success from https://pbthdm.bt.mo
08:13:04, 09 Feb.
( 213.190000) CWMP: Initializing transaction for event code 6 CONNECTION REQUEST
08:13:04, 09 Feb.
( 213.170000) CWMP: Server URL: https://pbthdm.bt.mo; Connecting as user: ACS username
08:13:04, 09 Feb.
( 213.170000) CWMP: Session start now. Event code(s): '6 CONNECTION REQUEST'
08:13:04, 09 Feb.
( 212.900000) CWMP: Initializing transaction for event code 6 CONNECTION REQUEST
08:12:59, 09 Feb.
( 208.320000) CWMP: session completed successfully
08:12:59, 09 Feb.
( 208.140000) CWMP: HTTP authentication success from https://pbthdm.bt.mo
08:12:57, 09 Feb.
( 205.760000) CWMP: Server URL: https://pbthdm.bt.mo; Connecting as user: ACS username
08:12:57, 09 Feb.
( 205.760000) CWMP: Session start now. Event code(s): '6 CONNECTION REQUEST,4 VALUE CHANGE'
08:12:57, 09 Feb.
( 205.490000) CWMP: session completed successfully
08:12:46, 09 Feb.
( 194.650000) CWMP: Set Parameter by TR069 Success
08:12:45, 09 Feb.
( 194.150000) CWMP: Set Parameter by TR069 Success
08:12:44, 09 Feb.
( 193.200000) CWMP: Set Parameter by TR069 Success
08:12:43, 09 Feb.
( 192.020000) CWMP: Set Parameter by TR069 Success
08:12:42, 09 Feb.
( 191.390000) CWMP: HTTP authentication success from https://pbthdm.bt.mo
Hub is now authenticating with pbthdm.bt.mo. The Set Parameter entry repeats itself every 1/2 hour.
It's just a case of waiting. -
i was playing and online game earlier tonight and all of a sudden i got disconnected when i finally managed to get my pc to connect up to my router (i hade to remove the phone cable and perform a power cycle as simple restart button wasnt enough) i found the following log entries in the machine
23:19:52 22 Jul
IDS proto parser : tcp data on syn segment (1 of 1) : 173.201.146.1 217.42.75.241 0419 TCP 80->31594 [S.A...] seq 624090545 ack 102806882 win 16384
23:16:31 22 Jul
SNTP Synchronised again to server: 213.123.26.170
23:10:04 22 Jul
IDS proto parser : udp null port (1 of 1) : 82.33.120.197 217.42.75.241 0048 UDP 0->1948
at the same time sa the first entry was made my 2 wondows vista pc's we cut off from the router
and at the same time as the secodn entry my 2 win xp pc's were cut off as well
it took me a while to get everythign reconected to the internet but i cant seem to find any reason for what has happend
i realsie its an intrusion detection log entry but it means nothing to me and trying to google for it returned a lot of nonsence about p2p programs but nothing that matched the entries
should prolly mention i have a V2(A) home hub
Hub Firmware Information
Current firmware
Version 8.1.H.J (Type A)
Last updated
28/01/10
so am kinda hoping this is the lastest update
any ionfo on what just happend would be nice and also why the wireless keeps getting turned on when this stuff happens (i have it turned off since i dont have anythign i need connectiong wirelessly)There is an issue with some older versions of the home hub which causes loss of connection if the IDS events fill up the internal memory.
This causes loss of DNS, which can be fixed by clearing the IDS logs. I thought this problem had been fixed in later firmware releases.
On my old home hub I run a script to clear the IDS logs at regular intervals, which sorts the problem out.
The alternative is to reboot the hub.
There are some useful help pages here, for BT Broadband customers only, on my personal website.
BT Broadband customers - help with broadband, WiFi, networking, e-mail and phones. -
Excessive log entries with buffalo linkstation
Hi all,
I am getting excessive log entries on my MacBook Pro (OS 10.6.7) that appear to be related to my Buffalo LinkStation HD-CELU2 external drive. This drive is connected to my Airport Extreme (latest firmware) via USB and acts as my iTunes (10.2.2) library, which also serves as the music source for a Sonos digital music system. A sample of the log entries follow:
4/18/11 8:15:22 PM com.apple.launchd[1] (jp.buffalo.NASPower) Throttling respawn: Will start in 60 seconds
4/18/11 8:15:39 PM com.apple.launchd.peruser.501[131] (jp.buffalo.NASPower[6798]) posix_spawn("/Library/PrivilegedHelperTools/NasNavigator2.app/Contents/MacOS/Na sNavigator2", ...): No such file or directory
4/18/11 8:15:39 PM com.apple.launchd.peruser.501[131] (jp.buffalo.NASPower[6798]) Exited with exit code: 1
4/18/11 8:15:39 PM com.apple.launchd.peruser.501[131] (jp.buffalo.NASPower) Throttling respawn: Will start in 60 seconds
It says that a file isn't found, and that could be because I uninstalled NASNavigator in an attempt to get rid of these extraneous log entries. Uninstalling the software seems to have only resulted in changing the messages (to "no such file"), not reducing or ending them.
This log entry is constant; it occurs even when the computer has no need to access the Buffalo hard drive. It makes it very hard to diagnose any other issues because it both clutters the log and causes it to only recall a couple of hours worth of log info.
Thanks in advance!Ho everyone, just registered as I have a Bold 9900 and am considering a Playbook with the new OS2. Does anyone know whether I will be able to get it to talk to my Buffalo Linkstation. think its a Pro Duo 2 and is about 2-3 years old.
Maybe you are looking for
-
How do I convert a case sensitive drive to a case insensitive drive?
I have recently purchased a MacMini Server, and installed the 2 internal hard drives in a RAID 0 configuration to obtain the speed and 1 TB capacity, but unfortunately (rather stupidly in retrospect) formatted the drive in case sensitive mode. On ins
-
How do i set a background of the button as an image??
hey guys... i was wondering if there is a way i could change the background of spark button component to an image?? ive looked into the icon property of the spark button, but thats not what i need... i need the entire background of an image to be an
-
Need to split the document in 950 line iteam record in LSMW
HI ALL, I am posting documents using LSMW for Tcode FB01. But some documents having more no of line items like 1000. But SAP will allow only 950 line tems for each documents. In this sistuvation we need to split the data as 950 and 50. we need to po
-
Dented case and AppleCare - a few questions
Hey all, I recently found a dent on the side of my computer that came out of nowhere at all. It's above the USB port on the left side, and there seems to be no sign of damage other than the dent protruding like a sore thumb. My questions regards Appl
-
my photo album wont opens in gallery it shows only blck screen while it opens in file manager!!plz help me!!