Event Log Location

If you are running the E-Business suite (management portion anyway) on win32, can Oracle events be captured by reviewing standard NT event logs or is there an Oracle specific location for events of note ? I am sure that major Oracle events might be written to the NT event log, but I am interested in more subtle events in addtion to the catastrophic.
Thanks

Hi Jose,
Nice article on the Exchange correlation engine.
Based on 1 point mentioned in the article there was a Point there: 
The Exchange 2010 Management Pack doesn't raise alerts that correspond to the health of your Exchange environment when the Correlation Engine is stopped. If the Correlation Engine is stopped,
a general alert is raised to notify you that the Correlation Engine isn’t running.
I need to pull my alert history and the event id for the above alert, need to check if there was any alert for the correlation service stopping / stooped when this event appeared in the event log on my exchange server.
Gautam.75801

Similar Messages

  • Operations Manager Failed to Access the Windows Event Log and management server is showing warning state

    Hi,
    I am monitoring AD server from SCOM 2012 R2. My management server goes into waning state. When i run Health explorer then it come back in the healthy state but after some time it again goes into warning state. After seeing alert i found that a alert is coming
    again and again i.e.  Operations Manager Failed to Access the Windows Event Log.The description of alert is mention below
    The Windows Event Log Provider is still unable to open the DhcpAdminEvents event log on computer 'nc2vws12ad5.corp.nathcorp.com'.
    The Provider has been unable to open the DhcpAdminEvents event log for 64080 seconds.
    Most recent error details: The RPC server is unavailable.
    Please suggest me how to resolve this so that my management server will again come back in healthy state.
    Thanks
    Abhishek

    Hi Abhishek,
    As i mentioned earlier the Alert resolution says the same points.
    Can you give details on the below ?
    Is there really a log named "Dhcpadminevents" in the MS's Event viewer ?
    Did you recently configure any new alert where you mentioned "Dhcpadminevents"
    as a event log location ?
    If yes then what is the target you selected for the rule / monitor there ?
    Can you post the results for analysis ?
    Gautam.75801

  • Events.log file in $APPLCSF/$APPLLOG location

    hi all
    i found Events.log file in the above $APPLCSF/$APPLLOG location whose sizes are in GB
    1)how to remove this files either manually using rm command or any concurrent program ????
    2)how frequently should we delete this logfiles
    ls -ltr Events*
    -rw-r--r-- 1 prodapps dba 443841731 Jan 19 15:22 Events0.log
    -rw-r--r-- 1 prodapps dba 151645160 Jan 21 17:34 Events1.log
    -rw-r--r-- 1 prodapps dba 792108943 Feb 1 11:51 Events2.log
    -rw-r--r-- 1 prodapps dba 649671293 Feb 10 09:20 Events3.log
    -rw-r--r-- 1 prodapps dba 657587225 Feb 19 08:11 Events4.log
    -rw-r--r-- 1 prodapps dba 1261710045 Mar 7 10:15 Events5.log
    -rw-r--r-- 1 prodapps dba 824884703 Mar 18 15:44 Events6.log
    -rw-r--r-- 1 prodapps dba 82789 Mar 18 15:47 Events7.log
    -rw-r--r-- 1 prodapps dba 310619912 Mar 22 21:46 Events8.log
    -rw-r--r-- 1 prodapps dba 1484520 Mar 23 00:53 Events9.log
    -rw-r--r-- 1 prodapps dba 60864861 Mar 23 21:34 Events10.log
    -rw-r--r-- 1 prodapps dba 1060482694 Apr 7 08:03 Events11.log
    -rw-r--r-- 1 prodapps dba 21876 May 19 09:58 Events13.log
    -rw-r--r-- 1 prodapps dba 21844 May 19 09:59 Events14.log
    -rw-r--r-- 1 prodapps dba 21833 May 19 10:01 Events15.log
    -rw-r--r-- 1 prodapps dba 21834 May 19 10:04 Events16.log
    -rw-r--r-- 1 prodapps dba 3116795691 May 19 10:07 Events12.log
    -rw-r--r-- 1 prodapps dba 587718117 May 27 09:58 Events17.log
    Regards

    Pl also see ML Note 601375.1 or a poosible cause of your issue. This is a known "feature" that we also ran into :-)
    HTH
    Srini Chavali

  • How to write to windows event logs from determinations-server under IIS

    This is just an FYI technical bit of information I wish someone had shared with me before I started trying to write OPA errors to the windows event log... Most problems writing to the windows event log from log4net occur because of permissions. Some problems are because determinations-server does not have permissions to create some registry entries. Some problems cannot be resolved unless specific registry entry permissions are actually changed. We had very little consistency with the needed changes across our servers, but some combination of the following would always get the logging to the windows event log working.
    To see log4net errors as log4net attempts to utilize the windows event log, temporarily add the following to the web.config:
    <appSettings>
    <!-- uncomment the following line to send diagnostic messages about the log configuration file to the debug trace.
    Debug trace can be seen when attached to IIS in a debugger, or it can be redirected to a file, see
    http://logging.apache.org/log4net/release/faq.html in the section "How do I enable log4net internal debugging?" -->
    <add key="log4net.Internal.Debug" value="true"/>
    </appSettings>
    <system.diagnostics>
    <trace autoflush="true">
    <listeners>
    <add
    name="textWriterTraceListener"
    type="System.Diagnostics.TextWriterTraceListener"
    initializeData="logs/InfoDSLog.txt" />
    </listeners>
    </trace>
    </system.diagnostics>
    To add an appender for the windows event viewer, try the following in the log4net.xml:
    <appender name="EventLogAppender" type="log4net.Appender.EventLogAppender" >
    <param name="ApplicationName" value="OPA" />
    <param name="LogName" value="OPA" />
    <param name="Threshold" value="all" />
    <layout type="log4net.Layout.PatternLayout">
    <conversionPattern value="%date [%thread] %-5level %logger [%property{NDC}] - %message%newline" />
    </layout>
    <filter type="log4net.Filter.LevelRangeFilter">
    <levelMin value="WARN" />
    <levelMax value="FATAL" />
    </filter>
    </appender>
    <root>
    <level value="warn"/>
    <appender-ref ref="EventLogAppender"/>
    </root>
    To put the OPA logs under the Application Event Log group, try this:
    Create an event source under the Application event log in Registry Editor. To do this, follow these steps:
    1.     Click Start, and then click Run.
    2.     In the Open text box, type regedit.
    3.     Locate the following registry subkey:
    HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\Eventlog\Application
    4.     Right-click the Application subkey, point to New, and then click Key.
    5.     Type OPA for the key name.
    6.     Close Registry Editor.
    To put the OPA logs under a custom OPA Event Log group (as in the demo appender above), try this:
    Create an event log in Registry Editor. To do this, follow these steps:
    1.     Click Start, and then click Run.
    2.     In the Open text box, type regedit.
    3.     Locate the following registry subkey:
    HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\Eventlog
    4.     Right-click the eventlog subkey, point to New, and then click Key.
    5.     Type OPA for the key name.
    6.     Right-click the new OPA key and add a new DWORD called "MaxSize" and set it to "1400000" which is about 20 Meg in order to keep the log file from getting too large.
    7.     The next steps either help or sometimes cause an error, but you can try these next few steps... If you get an error about a source already existing, then you can delete the key.
    8.     Right-click the OPA subkey, point to New, and then click Key.
    9.     Type OPA for the key name.
    10.     Close Registry Editor.
    You might need to change permissions so OPA can write to the event log in Registry Editor.  If you get permission errors, try following these steps:
    1.     Click Start, and then click Run.
    2.     In the Open text box, type regedit.
    3.     Locate the following registry subkey:
    HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\Eventlog
    4.     Right-click the EventLog key, select Permissions.
    5.     In the dialog that pops up, click Add...
    6.     Click Advanced...
    7.     Click Locations... and select the current machine by name.
    8.     Click Find Now
    9.     Select both the Network user and IIS_IUSERS user and click OK and OK again. (We never did figure out which of those two users was the one that fixed our permission problem.)
    10.     Change the Network user to have Full Control
    11.     Click Apply and OK
    To verify OPA Logging to the windows event logs from Determinations-Server:
    Go to the IIS determinations-server application within Server Manager.
    Under Manage Application -> Browse Application click the http link to pull up the local "Available Services" web page that show the wsdl endpoints.
    Select the /determinations-server/server/soap.asmx?wsdl link
    Go to the URL and remove the "?wsdl" from the end of the url and refresh. This will throw the following error into the logs:
    ERROR Oracle.Determinations.Server.DSServlet [(null)] - Invalid get request: /determinations-server/server/soap.asmx
    That error should show up in the windows event log, OR you can get a message explaining why security stopped you in "logs/InfoDSLog.txt" if you used the web.config settings from above.
    http://msdn.microsoft.com/en-us/library/windows/desktop/aa363648(v=vs.85).aspx
    Edited by: Paul Fowler on Feb 21, 2013 9:45 AM

    Thanks for sharing this information Paul.

  • Seemingly successful install of Exchange 2013 SP1 turns into many errors in event logs after upgrade to CU7

    I have a new Exchange 2013 server with plans to migrate from my current Exchange 2007 Server. 
    I installed Exchange 2013 SP1 and the only errors I saw in the event log seemed to be long standing known issues that did not indicate an actual problem (based on what I read online). 
    I updated to CU7 and now lots of errors have appeared (although the old ones seem to have been fixed so I have that going for me). 
    Currently the Exchange 2013 server is not in use and clients are still hitting the 2007 server.
    Issue 1)
    After each reboot I get a Kernel-EventTracing 2 error.  I cannot find anything on this on the internet so I have no idea what it is.
    Session "FastDocTracingSession" failed to start with the following error: 0xC0000035
    I did read other accounts of this error with a different name in the quotes but still can’t tell what this is or where it is coming from.
    Issue 2)
    I am still getting 5 MSExchange Common 106 errors even after reregistering all of the perf counters per this page:
    https://support.microsoft.com/kb/2870416?wa=wsignin1.0
    One of the perf counters fails to register using the script from the link above.
    66 C:\Program Files\Microsoft\Exchange Server\V15\Setup\Perf\InfoWorkerMultiMailboxSearchPerformanceCounters.xml
    New-PerfCounters : The performance counter definition file is invalid.
    At C:\Users\administrator.<my domain>\Downloads\script\ReloadPerfCounters.ps1:19 char:4
    +    New-PerfCounters -DefinitionFileName $f
    +    ~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~
        + CategoryInfo         
    : InvalidData: (:) [New-PerfCounters], TaskException
        + FullyQualifiedErrorId : [Server=VALIS,RequestId=71b6bcde-d73e-4c14-9a32-03f06e3b2607,TimeStamp=12/18/2014 10:09:
       12 PM] [FailureCategory=Cmdlet-TaskException] 33EBD286,Microsoft.Exchange.Management.Tasks.NewPerfCounters
    But that one seems unrelated to the ones that still throw errors. 
    Three of the remaining five errors are (the forum is removing my spacing between the error text so it looks like a wall of text - sorry):
    Performance counter updating error. Counter name is Count Matched LowFidelity FingerPrint, but missed HighFidelity FingerPrint, category name is MSExchange Anti-Malware Datacenter Perfcounters. Optional code: 3. Exception: The
    exception thrown is : System.InvalidOperationException: The requested Performance Counter is not a custom counter, it has to be initialized as ReadOnly.
       at System.Diagnostics.PerformanceCounter.InitializeImpl()
       at System.Diagnostics.PerformanceCounter.set_RawValue(Int64 value)
       at Microsoft.Exchange.Diagnostics.ExPerformanceCounter.set_RawValue(Int64 value)
    Last worker process info : System.ArgumentException: Process with an Id of 7384 is not running.
       at System.Diagnostics.Process.GetProcessById(Int32 processId)
       at Microsoft.Exchange.Diagnostics.ExPerformanceCounter.GetLastWorkerProcessInfo()
    Performance counter updating error. Counter name is Number of items, item is matched with finger printing cache, category name is MSExchange Anti-Malware Datacenter Perfcounters. Optional code: 3. Exception: The exception thrown
    is : System.InvalidOperationException: The requested Performance Counter is not a custom counter, it has to be initialized as ReadOnly.
       at System.Diagnostics.PerformanceCounter.InitializeImpl()
       at System.Diagnostics.PerformanceCounter.set_RawValue(Int64 value)
       at Microsoft.Exchange.Diagnostics.ExPerformanceCounter.set_RawValue(Int64 value)
    Last worker process info : System.ArgumentException: Process with an Id of 7384 is not running.
       at System.Diagnostics.Process.GetProcessById(Int32 processId)
       at Microsoft.Exchange.Diagnostics.ExPerformanceCounter.GetLastWorkerProcessInfo()
    Performance counter updating error. Counter name is Number of items in Malware Fingerprint cache, category name is MSExchange Anti-Malware Datacenter Perfcounters. Optional code: 3. Exception: The exception thrown is : System.InvalidOperationException:
    The requested Performance Counter is not a custom counter, it has to be initialized as ReadOnly.
       at System.Diagnostics.PerformanceCounter.InitializeImpl()
       at System.Diagnostics.PerformanceCounter.set_RawValue(Int64 value)
       at Microsoft.Exchange.Diagnostics.ExPerformanceCounter.set_RawValue(Int64 value)
    Last worker process info : System.ArgumentException: Process with an Id of 7384 is not running.
       at System.Diagnostics.Process.GetProcessById(Int32 processId)
       at Microsoft.Exchange.Diagnostics.ExPerformanceCounter.GetLastWorkerProcessInfo()
    Issue 3)
    I appear to have some issues related to the healthmailboxes. 
    I get MSExchangeTransport 1025 errors for multiple healthmailboxes.
    SMTP rejected a (P1) mail from 'HealthMailbox23b10b91745648819139ee691dc97eb6@<my domain>.local' with 'Client Proxy <my server>' connector and the user authenticated as 'HealthMailbox23b10b91745648819139ee691dc97eb6'. The Active Directory
    lookup for the sender address returned validation errors. Microsoft.Exchange.Data.ProviderError
    I reran setup /prepareAD to try and remedy this but I am still getting some.
    Issue 4)
    I am getting an MSExchange RBAC 74 error. 
    (Process w3wp.exe, PID 984) Connection leak detected for key <my domain>.local/Admins/Administrator in Microsoft.Exchange.Configuration.Authorization.WSManBudgetManager class. Leaked Value 1.
    Issue 5)
    I am getting MSExchange Assistants 9042 warnings on both databases.
    Service MSExchangeMailboxAssistants. Probe Time Based Assistant for database Database02 (c83dbd91-7cc4-4412-912e-1b87ca6eb0ab) is exiting a work cycle. No mailboxes were successfully processed. 2 mailboxes were skipped due to errors. 0 mailboxes were
    skipped due to failure to open a store session. 0 mailboxes were retried. There are 0 mailboxes in this database remaining to be processed.
    Some research suggested this may be related to deleted mailboxes however I have never had any actual user mailboxes on this server. 
    If they are healthmailboxes or arbitration mailboxes that might make sense but I am unsure of what to do on this.
    Issue 6)
    At boot I am getting an MSExchange ActiveSync warning 1033
    The setting SupportedIPMTypes in the Web.Config file was missing. 
    Using default value of System.Collections.Generic.List`1[System.String].
    I don't know why but this forum is removing some of my spacing that would make parts of this easier to read.

    Hi Eric
    Yes I have uninstalled and reinstalled Exchange 2013 CU7 for the 3<sup>rd</sup> time. 
    I realize you said one issue per forum thread but since I already started this thread with many issues I will at least post what I have discovered on them in case someone finds their way here from a web search.
    I have an existing Exchange 2007 server in the environment so I am unable to create email address policies that are defined by “recipient container”. 
    If I try and do so I get “You can't specify the recipient container because legacy servers are detected.”
     So I cannot create a normal email address policy and restrict it to an OU without resorting to some fancy filtering. 
    Instead what I have done is use PS to modify extensionAttribute1 (otherwise known as Custom Attribute 1 to exchange) for all of my users. 
    I then applied an address policy to them and gave it the highest priority. 
    Then I set a default email address policy for the entire organization. 
    After reinstalling Exchange all of my system mailboxes were created with the internal domain name. 
    So issue number 3 above has not come up. 
    For issue number one above I have created a new thread:
    https://social.technet.microsoft.com/Forums/office/en-US/7eb12b89-ae9b-46b2-bd34-e50cd52a4c15/microsoftwindowskerneleventtracing-error-2-happens-twice-at-boot-ex2013cu7?forum=exchangesvrdeploy
    For issue number four I have posted to this existing thread where there is so far no resolution:
    https://social.technet.microsoft.com/Forums/exchange/en-US/2343730c-7303-4067-ae1a-b106cffc3583/exchange-error-id-74-connection-leak-detected-for-key?forum=exchangesvradmin
    Issue number Five I have managed to recreate and get rid of in more than one way. 
    If I create a new database in ECP and set the database and log paths where I want, then this error will appear. 
    If I create the database in the default location and then use EMS to move it and set the log path, then the error will not appear. 
    The error will also appear (along with other errors) if I delete the health mailboxes and let them get recreated by restarting the server or the Health Manager service. 
    If I then go and set the retention period for deleted mailboxes to 0 days and wait a little while, these will all go away. 
    So my off hand guess is that these are caused by orphaned system mailboxes.
    For issue number six I have posted to this existing thread where there is so far no resolution:
    https://social.technet.microsoft.com/Forums/exchange/en-US/dff62411-fad8-4d0c-9bdb-037374644845/event-1033-msexchangeactivesync-warning?forum=exchangesvrmobility
    So for the remainder of this thread we can try and tackle issue number two which is the perf counters. 
    The exact same 5 perf counter were coming up and this had been true each time I have uninstalled and reinstalled Exchange 2013CU7. 
    Actually to be more accurate a LOT of perf counter errors come up after the initial install, but reloading the perf counters using the script I posted above reduces it to the same five. 
    Using all of your suggestions so far has not removed these 5 remaining errors either.  Since there is no discernible impact other than these errors at boot I am not seriously bothered by them but as will all event log errors, I would prefer
    to make them go away if possible.

  • File history stopped working after a warning message in the event log

    I have encountered this twice that File history stopped working, the event log says:
    Unusual condition was encountered during finalization of a backup cycle for configuration C:\Users\xxxx\AppData\Local\Microsoft\Windows\FileHistory\Configuration\Config
    If I re-run it, it consumes the backup disk space but still failed to backup.
    I have to manually delete all backup, turn off File History and re-configure it again to make it work.
    This happened twice already, so all my file history lost after re-config.
    Anyone encounter the same situation?

    MICROSOFT is plagued by idiots!!!!
    - Just turn it off
    - then click  "select drive"
    - and when it asks you the retarded question... just click >>>>>"NO"<<<<<<<    -_-
    Seriously... this is the answer.... frigging retards at microsoft... to think it takes an army of programmers and billions of dollars to create such idiocy!
    http://answers.microsoft.com/en-us/windows/forum/windows_8-performance/cannot-change-drive-in-file-history-windows-8/6dbeca54-d05e-4f93-9262-45a56d6a82d1?page=2&msgId=f1792c5e-c5d0-4163-b449-c7165d72f88d&tab=question&status=AllReplies&status=AllReplies%2CAllReplies
    I cant believe these morons put everyone through such hell and then don't even bother to follow up with the correct solution.
    To top it of the moron moderator marks this as an answer??!!!
    What a pathetic joke - I hope everyone reads this message before being punished by the miles of bullcrap in this thread -_-
    Microsoft = ridiculous
    Thanks! I guess the TL;DR version is "to change your file history drive you need to discard the current temp files."
    Exactly :)
    It's the bad wording in the messages.
    the first message (which I can only vaguely remember so can't quote exactly) that gives you the impression you can continue
    something but doesn't make clear that to so will need the "old drive" configured the way the "old drive" was.
    Then the next message is just confusing:
    “we can't copy files to this location.  Your current File History drive is disconnected.  Reconnect the drive and try again” 
    sounds like 
    “we can't copy files to this location. [because there's a problem with the new location]
    Your current File History drive is disconnected. [the new location is disconnected]
    Reconnect the drive and try again [reconnect your new location and try again]” 
    When it should be reworded to say something along the lines of (in more formal language):
    "You asked us to continue...give us the drive you were previously using...or if it's no longer available, click here to start from scratch"
    (I know that's all the opposite of tldr but I'm trying again to put into words what I think was happening).

  • Reporting Services not automatically starting. System event log 7009, Application event: 18456

    For the past month (since Oct 11,2012)  reporting services (SSRS 2008R2) is not starting after the server is rebooted. The service is set to automatically start and starts manually without a problem.  The system event log contains the following error:
    Event ID 7009: A timeout was reached (30000 milliseconds) while waiting for the SQL Server Reporting Services (MSSQLSERVER) service to connect.
    SQL logs :
    The SQL logs has many "Event 18456 Login Failed, State 38" errors when the database engine starts. I assume clients conections are failing because the databases  aren't online yet. None of these 18456 errors coorespond to the account reporting services
    runs under.
    The SQL logs indication Event 7009 occures before the "ReportingServer" database is online so im assuming there is a dependancy but I don't know how to avoid this.
    This problem is occuring on a number of our servers running SSRS (if not all)
    Any ideas?
    Paul

    Hi A141695,
    For Event ID 7009, you can try to do the steps below to resolve it.
        1. Click Start, click Run, type regedit, and then click OK.
        2. Locate and then click the following registry subkey:
            HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control
        3. Right-click Control, point to New, and then click DWORD Value.
        4. In the New Value #1 box, type ServicesPipeTimeout, and then press ENTER.
        5. Right-click ServicesPipeTimeout, and then click Modify.
        6. Click Decimal, type the number of milliseconds that you want to wait until the service times out, and then click OK.
    For example, to wait 60 seconds before the service times out, type 60000.
    Quit Registry Editor, and then restart the computer. For more information about it, please see:
    http://www.sqlservercentral.com/Forums/Topic850540-1550-1.aspx#bm851211
    http://myitforum.com/myitforumwp/2012/08/22/configmgr-2012-sms_srs_reporting_point-component-failure/
    If you have any questions, please feel free to ask.
    Regards,
    Charlie Liao
    TechNet Subscriber Support
    If you are TechNet Subscription user and have any feedback on our support quality, please send your feedback
    here.

  • Event log errors after upgrading Aironet 1100

    We have upgraded an Aironet 1100 to 12.3(8)JA. We used TFTP for the upgrade and everything seems to be working properly.
    However, the event log shows the following message every four seconds: "System running-config write error; configuration failed" This has Error as the severity.
    Every thirty minutes another, Critical error is logged "Memory allocation of 900000 bytes failed from 0x22DC78, alignment 0"
    I've searched the site and can't seem to locate applicable information on these errors and what they mean. Can someone help?
    Thanks!

    Oddly enough, this is the most stable AP we have! A PDA can connect to it and stay connnected, whereas our other 1100s (which have not been upgraded and generate the same error messages but only once or twice a day)will permit a device to connect then boot it off after a few seconds to several minutes. We thought the upgrade would make the AP connections more stable but were surprised to see the error messages being generated so rapidly.

  • Connection Timeout Expired in Windows Event Logs

    I just recently installed SharePoint 2013 SP1 on a Windows Server 2008 R2 SP1 server and have been receiving this error message in the Windows Event logs:
    Cannot connect to SQL Server.  <database server name> not found.  Additional error information from SQL Server is included below.
    Connection Timeout Expired.  The timeout period elapsed during the post-login phase.  The connection could have timed out while waiting for server to complete the login process and respond; Or it could have timed out while attempting to create
    multiple active connections.  The duration spent while attempting to connect to this server was - [Pre-Login] initialization=12; handshake=6; [Login] initialization=0; authentication=0; [Post-Login] complete=14000;
    I have never seen this error message before in my life on any prior installation of SharePoint that I have ever done.  It is only occurring on this one particular installation of SharePoint.  The environment is corporate built, so I have no idea
    as to how to troubleshoot or determine the root cause of this error message.
    I looked at the value of the database-connection-timeout in stsadm and it gets back a value of 15, however, I am unable to alter the database connection timeout using stsadm since I either get an "Object reference not sent to an instance of an object"
    error message or "This operation can be performed only on a computer that is joined to a server farm by users who have permissions in SQL Server to read from the configuration database.  To connect this server to the server farm, use the SharePoint
    Products Configuration Wizard, located on the Start menu in Microsoft SharePoint 2010 Products."
    Please advise. 

    What is specification of your SQL server? i think its more CPU, RAM, I/O issue with SQL server.
    under which account you are running the stsadm command?
    check this one
    http://stackoverflow.com/questions/21230927/sql-azure-the-timeout-period-elapsed-during-the-post-login-phase
    may be you fall in this bug
    http://connect.microsoft.com/VisualStudio/feedback/details/821803/connection-timeout-expired-the-timeout-period-elapsed-during-the-post-login-phase
    Please remember to mark your question as answered &Vote helpful,if this solves/helps your problem. ****************************************************************************************** Thanks -WS MCITP(SharePoint 2010, 2013) Blog: http://wscheema.com/blog

  • Event Logs of VMs Migration in Failover Cluster of Hyper-V Hosts

    Hello All,
    We're running Failover Cluster of Hyper-V hosts of Windows Server 2012 R2. Using SCVMM 2012 R2 with UR5 for management.
    If any host gets down unexpectedly (due to any reason power/bugcheck/hardware failure or what so ever), then the VMs on that host, of course, get migrated (either quick or live) to some other host within the cluster.
    I want to have logs/events of this VMs migration. I want to know that which of the VMs were residing on that host at that time of failure. Of course, we can't have this info in the Cluster events is Failover Cluster Manager. I am unable to find this info
    anywhere. I have searched in Event Viewer --> Administrative Roles --> Hyper-V. I have searched a lot in the SCVMM, but no success.
    Please help me in finding the exact location of these logs/events. I would also like to know that if the VM was quick migrated or live migrated, and to which host the VM got migrated.
    I'd be highly grateful.
    Thanks in anticipation.
    Regards,
    Hasan Bin Hasib

    This post was cross-posted in the clustering forum.  As noted in that forum, a failure of a host does not initiate a quick or live migration.  Migration requires both the source and destination nodes be operational during the entire migration
    process.  Should a host fail, it is impossible for that host to participate in a migration.  In the case of a host failure, the VM is restarted on another node of the cluster.  You can still use the information provided by Elton for viewing
    events in the event log.  If you want to see the exact sequence of log entries, perform quick/live migrations in a lab and notices the changes in the event log.  You can also fail a host and see the sequence of log entries.
    . : | : . : | : . tim

  • VSS snapshot of 1.1TB is ending after few hours with timeout. No errors in event log

    Hello,
    does someone have experienced issue where starting making snapshot (forum GUI or command line) is taking a lot of time and then it just ends with timeout?
    I have scenario on virtualised Windows Web Server 2008 R2 where backup is being made by Idera Backup Software but since it relies on VSS Snapshots then we can just skip this point because making snapshots from directly Windows command line or drive preferences/GUI
    is ending with timeout for this single drive after few hours. Affected system has 3 drives: C - 95GB, D-1.06TB and E-120GB. C and E can be backuped correctly and only drive D has problems. System is updated with latest drivers vssadmin for writers returns
    list without any errors and snapshot for drive D which ends with timeout is not generating any error in event log. I wanted to configure VSS trace like it is being instructed on this site:
    http://publib.boulder.ibm.com/infocenter/tsminfo/v6/index.jsp?topic=%2Fcom.ibm.itsm.tshoot.doc%2Ft_pdg_traceprfrm.html
    but I don't see any trace.txt file on given location. If I remove drive D from backup process it ends without errors. System was restarted many times. Only thing which is visible in windows Event log (application part) is that "The VSS service is shutting
    down due to idle timeout." about 4 hours after snapshot making proces is starting.
    I've contacted Idera backup about this but they can't help too much if Windows snapshot process is failing. They suggested that something can be wrong with this drive but since this is virtualised machine and all of my VM are being stored on RAID10 disk
    array connected to my server using fiber connections then I don't think that this is hardware issue (especially when other two drives are located on the same LUN on disk array).
    Any suggestions?
    Regards

    Hi,
    Do you create VMs on Hyper-V or VMWare? Based on research, possible causes could be:
    1. Files changes in the volume is very huge. So the shadow size may be big and the current shadow storage my not able to hold it. And that’s cause the shadow copy creation failure. 
    2. The I/O in D drive is heavy and make the shadow copy I/O failed. 
    3. Server is too busy to handle the request.
    4. The disk is heavily defragment.
    Please refer to the articles to troubleshoot the issue:
    Time-out errors occur in Volume Shadow Copy service writers, and shadow copies are lost during backup and during times when there are high levels of input/output
    http://support.microsoft.com/kb/826936/en-us
    VSS timeouts during backup? What could contribute to that?
    https://blogs.technet.com/b/askpfeplat/archive/2012/09/12/vss-timeouts-during-backup-check-fragmentation.aspx
    Regards,
    Mandy
    We
    are trying to better understand customer views on social support experience, so your participation in this
    interview project would be greatly appreciated if you have time.
    Thanks for helping make community forums a great place.

  • VM cannot get IP and shows host MAC in event logs

    I have a strange issue where the VM on a user's laptop worked fine in the office with a Wireless NIC but when he got home we began having some problems (no network in the VM, only get 169.x.x.x IP in the VM, host network connection drops when we try
    to access or configure the networking inside the VM).
    Here is what I know so far:
    Bridge exists on host (wireless NIC to virtual NIC) and is enabled
    Adapter in VM has MAC of 00-15-5D-0A-A5-00, cannot get IP
    VM settings for the wireless NIC show the MAC is Dynamic and the one assigned is within the range setup on the Virtual Switch
    Adapter on host has MAC of 9C-4E-36-AC-83-68, gets IP of 192.168.0.14
    In the VM, you cannot renew or assign an IP, it says the MAC exists on the network and has an address assigned.  Network connectivity also drops if you try to renew the IP
    In the system event logs on the VM, I see TCPIP event 4199, exact message is - The system detected an address conflict for IP address 192.168.0.14 with the system having hardware address 9C-4E-36-AC-83-68.
    There are no errors in the event logs on the host.
    Deleting the NIC inside the VM and removing/re-adding it to the VM settings does not resolve it
    Deleting and recreating the virtual switch does not resolve it
    The option to allow the management OS to also use the wireless NIC is enabled on the virtual switch.
    The wired connection also worked in our office during the build and testing but he doesn't not have a cable at home for me to test the wired there.
    We have another machine which is configured the same way and is working correctly, both in the office and offsite.
    Why is the VM trying to use the host MAC to get an IP, shouldn't it be using the one assigned by Hyper-V?  Could this be an issue with his home office network or maybe specifically with his WAP?  What other items could cause this?
    I have asked my user to go connect to a wireless network in a different location and test it but I haven't heard back from him yet.
    Thanks in advance for any suggestions.

    Hi Milos,
    1 - Unfortunately I can't test this, the router is supplied by his ISP and is not one that we have any management capabilities on.
    2 - Any time I access network information in the VM (even just to run "ipconfig /all" at a command line), the network drops temporarily on the host and I loose access to it.
    3 - I've not used this before, I'll check it out.
    It seemed really odd to me that the VM showed the host MAC in the event logs when everything else in the VM shows the one assigned by Hyper-V.
    Do you know if the "Virtual Networking and Wireless network adapters" entry in Ben Armstrong's Virtualization blog still applies in Windows 8.1?  It won't let me post the link to it directly, sorry.
    I've seen it referred to recent posts but it's from 2005.
    It makes sense if it is since symptom #2 sounds like what I am seeing.

  • Event logs fails to start on Exchange Server 2010

    My Exchange server 2010 R2 SP1 Enterprise single server is down.  All exchange services fail to start.  It appears like the Microsoft Exchange Active Directory Topology service isn't starting which is a dependency for all other services.
    The error I get when trying to start this service is:
    Windows could not start the Microsoft Exchange Active Directory Topology on Local Computer.  For more information, review the System Event Log.  If this is a non-Microsoft service, contact the service vendor, and refer to service-specific error code
    -2147024882
    To make matters worse, the event viewer is not starting either.
    When trying to start the Windows Event Log, I get the error:
    Windows could not start the Windows Event Log service on Local Computer. Displays Error code 5
    This is running on a Windows Server 2008 R2 SP1 Standard box.
    Any assistance is appreciated.

    When trying to start the Windows Event Log, I get the error:
    Windows could not start the Windows Event Log service on Local Computer. Displays Error code 5
    Hi,
    Based on this error, this problem happens if any of the following conditions are true:
    The built-in security group EventLog does not have permissions on the folder %SystemRoot%\System32\winevt\Logs
    The Local Service account does not have default permissions on the following registry key: HKLM\Software\Microsoft\Windows\CurrentVersion\Reliability
    To solve this problem, we need to restore the default permissions in the list below on %SystemRoot%\System32\winevt\logs.
    Authenticated user - List folder/read data, Read attributes, Read Extended attributes, Read permissions
    Administrators - Full control
    SYSTEM - Full control
    EventLog - Full control
    Please try the following methods:
    Method 1
    To restore the default permissions on folder %SystemRoot%\System32\winevt\logs, follow these steps.
    Right-click on %SystemRoot%\System32\winevt\logs and select Properties.
    Select the Security tab.
    Click Edit button and click the Add button in the permissions dialog box.
    In Select users, computers, or Groups dialog box ensure that under object types Built in Security Principals and the location as local computer name is selected.
    Enter the object name as "NT SERVICE\EventLog" without quotes. And click OK. This group should have full control on the folder.
    Once EventLog group is added add the rest of the groups with above mentioned permissions.
    Method 2
    Identify a Windows Server 2008 machine with default permissions.
    Click Start, and then type cmd in the Start Search box.
    In the search results list, right-click Command Prompt, and then click Run as Administrator.
    When you are prompted by User Account Control, click Continue.
    Type the command CD %SystemRoot%\SYSTEM32.
    Once the working directory is changed to %SystemRoot%\SYSTEM32 type the command icacls winevt\* /save acl /T.
    This will save a file named ACL in %SystemRoot%\SYSTEM32. Copy this file to the C: drive on the problem computer.
    On the problem computer, open command prompt with administrator privileges (refer to previous steps 1-3).
    Change the working directory to %SystemRoot%\SYSTEM32.
    Execute the command icacls winevt\ /restore acl.
    Default permissions on the registry key HKLM\Software\Microsoft\Windows\CurrentVersion\Reliability should be:
    CREATOR OWNER - Full control
    SYSTEM - Full control
    LOCAL SERVICE - Query Value, Set Value, Create Subkey, Notify and Delete
    Administrators - Full control
    Users - Read
    To set the permission on this registry key:
    Click the Start menu, select Run and type Regedit.
    Go to the location HKLM\Software\Microsoft\Windows\CurrentVersion\Reliability.
    From the Edit menu click Permissions.
    Add the permissions for the accounts as listed above.
    In addition, Exchange 2010 SP1 and SP2 are end of support.
    https://support.microsoft.com/en-us/lifecycle/search/default.aspx?alpha=exchange%20server%202010&Filter=FilterNO
    Best Regards.
    Please remember to mark the replies as answers if they help, and unmark the answers if they provide no help. If you have feedback for TechNet Support, contact [email protected]
    Lynn-Li
    TechNet Community Support

  • Could not add bundle to session / event log full

    Hi!
    ZCM 10.3.3 on SLES 11 SP1, Windows XP SP3.
    So far ZCM 10.3.3 was very stable, must admit, very pleased! But, I start to see some problems on - so far - few clients which I can't solve, seems to.
    Yesterday (and day before) on WXP device in computer room didn't remove DLU volatile client after logoff, yesterday same device additionally did show NAL window empty. I took a look into logs and see there may errors a'la
    [ERROR] [11/24/2011 10:11:43.824] [208] [ZenworksWindowsService] [66] [] [BundleManager] [BUNDLE.CouldNotAddBundle] [Could not add bundle 33d121df8527419ab00096c1a3b9049d to session] [] []
    [DEBUG] [11/24/2011 10:11:43.824] [208] [ZenworksWindowsService] [66] [] [MessageLogger] [] [Unable to write to event log (Application) using source (Novell.Zenworks.Logger) Exception: System.ComponentModel.Win32Exception: The event log file is full
    at System.Diagnostics.EventLog.InternalWriteEvent(UIn t32 eventID, UInt16 category, EventLogEntryType type, String() strings, Byte() rawData, String currentMachineName)
    at System.Diagnostics.EventLog.WriteEntry(String message, EventLogEntryType type, Int32 eventID, Int16 category, Byte() rawData)
    at System.Diagnostics.EventLog.WriteEntry(String source, String message, EventLogEntryType type, Int32 eventID, Int16 category, Byte() rawData)
    at System.Diagnostics.EventLog.WriteEntry(String source, String message, EventLogEntryType type, Int32 eventID)
    at log4net.Appender.EventLogAppender.Append(LoggingEv ent loggingEvent)] [] []
    Also I noticed that device-attached bundles is not working anymore, not set to start at device boot nor after user logoff.
    On another device with same symptoms I see in log many entries a'la
    [ERROR] [11/24/2011 10:26:37.038] [580] [ZenworksWindowsService] [16] [] [BundleManager] [BUNDLE.CouldNotAddBundle] [Could not add bundle 5aed9420cf9a9277fffbdcee2744981b to session] [] []
    On this device client wasn't able to login today.
    Tried zac.exe cc and also on computer room deleted zcm dir in cache folder, nothing, same result. Via ZCC I see both devices in green, I mean, ZCC show device is ok. When I try to refresh device it does it very quickly, usually it takes a little longer. ZCM server (SLES 11 SP1) seems to work ok.
    Any ideas?
    More thanks, Alar.

    I'll add here piece of logs where - I think - problem is described. Server info is changed -- server and ip pointing to the same device.
    [DEBUG] [11/25/2011 09:06:45.692] [660] [ZenworksWindowsService] [23] [] [ConnectMan] [] [ Found host server status: Good] [] []
    [DEBUG] [11/25/2011 09:06:45.692] [660] [ZenworksWindowsService] [47] [] [Remote Management Module] [] [<RMSettingsData><RemoteManagementService><RemoteCo ntrolService Enable="true"><Port>5950</Port></RemoteControlService><RemoteLoginService Enable="false"><Port>5951</Port></RemoteLoginService></RemoteManagementService><Session><ViewerDNSLookup> true</ViewerDNSLookup><AllowSessionInUserAbsence>true</AllowSessionInUserAbsence></Session><Performance><AutoBandwidthDetection>true</AutoBandwidthDetection><WallpaperSuppression>true</WallpaperSuppression><EightBitColor>false</EightBitColor><Caching>true</Caching><MirrorDriver>true</MirrorDriver></Performance><RemoteDiagnosticApps><App ID="1"><Name>SystemInformation</Name><Path>C:\Program Files\Common Files\Microsoft Shared\MSInfo\msinfo32.exe</Path></App><App ID="2"><Name>ComputerManagement</Name><Path>C:\WINDOWS\System32\compmgmt.msc</Path></App><App ID="3"><Name>Services</Name><Path>C:\WINDOWS\System32\services.msc</Path></App><App ID="4"><Name>RegistryEditor</Name><Path>C:\WINDOWS\regedit.exe</Path></App></RemoteDiagnosticApps></RMSettingsData>] [] []
    [DEBUG] [11/25/2011 09:06:45.692] [660] [ZenworksWindowsService] [23] [] [ConnectMan] [] [ Found host 199.0.8.11 status: Unknown] [] []
    [DEBUG] [11/25/2011 09:06:45.692] [660] [ZenworksWindowsService] [23] [] [ConnectMan] [] [Trying to locate source location: https://server/zenworks-bundleservice/] [] []
    [DEBUG] [11/25/2011 09:06:45.692] [660] [ZenworksWindowsService] [23] [] [ConnectMan] [] [ Host name to resolve: server] [] []
    [DEBUG] [11/25/2011 09:06:45.692] [660] [ZenworksWindowsService] [23] [] [ConnectMan] [] [ Found host: server, status: Good] [] []
    [DEBUG] [11/25/2011 09:06:45.692] [660] [ZenworksWindowsService] [23] [] [ConnectMan] [] [Marking location https://199.0.8.11/zenworks-bundleservice/ Good at the request of module bundleservice] [] []
    [DEBUG] [11/25/2011 09:06:45.692] [660] [ZenworksWindowsService] [23] [] [ConnectMan] [] [ Setting location name https://199.0.8.11/zenworks-bundleservice/ to status Good] [] []
    [DEBUG] [11/25/2011 09:06:45.692] [660] [ZenworksWindowsService] [23] [] [ConnectMan] [] [ Adding location: https://199.0.8.11/zenworks-bundleservice/, status: Good] [] []
    [DEBUG] [11/25/2011 09:06:45.692] [660] [ZenworksWindowsService] [23] [] [ConnectMan] [] [ Host: server, IP address: 199.0.8.11] [] []
    [DEBUG] [11/25/2011 09:06:45.692] [660] [ZenworksWindowsService] [23] [] [ConnectMan] [] [ Using IP address: 199.0.8.11, status: Good] [] []
    [DEBUG] [11/25/2011 09:06:45.692] [660] [ZenworksWindowsService] [23] [] [ConnectMan] [] [ Built location: https://199.0.8.11/zenworks-bundleservice/ using IP address 199.0.8.11] [] []
    [DEBUG] [11/25/2011 09:06:45.692] [660] [ZenworksWindowsService] [23] [] [ConnectMan] [] [FindFirstContent() returning https://199.0.8.11/zenworks-bundleservice/] [] []
    [DEBUG] [11/25/2011 09:06:45.692] [660] [ZenworksWindowsService] [27] [] [MessageLogger] [] [Settings passed to logger:<ZENSettings Version="1.0"><SettingConfiguration Name="LocalLog" Enabled="True" Revision="0"><Parameter Name="RollingType" Type="String" Value="Size" /><Parameter Name="BackupFiles" Type="Integer" Value="1" /><Parameter Name="FileSize" Type="Integer" Value="10" /><Parameter Name="FileSizeUnit" Type="String" Value="MB" /><Parameter Name="Severity" Type="Integer" Value="8" /></SettingConfiguration></ZENSettings>] [] []
    [DEBUG] [11/25/2011 09:06:45.692] [660] [ZenworksWindowsService] [27] [] [MessageLogger] [] [Ignoring the Settings as the revision number is same] [] []
    [DEBUG] [11/25/2011 09:06:45.692] [660] [ZenworksWindowsService] [27] [] [LOGGERCONFIGURATOR] [] [A new settings has been provided to Logger to change its configuration for localLogging] [] []
    [DEBUG] [11/25/2011 09:06:45.692] [660] [ZenworksWindowsService] [27] [] [MessageLogger] [] [Settings passed to logger:<ZENSettings Version="1.0"><SettingConfiguration Name="SystemLog" Enabled="True" Revision="0"><Parameter Name="Severity" Type="Integer" Value="12" /></SettingConfiguration></ZENSettings>] [] []
    [DEBUG] [11/25/2011 09:06:45.692] [660] [ZenworksWindowsService] [27] [] [MessageLogger] [] [Ignoring the Settings as the revision number is same] [] []
    [DEBUG] [11/25/2011 09:06:45.692] [660] [ZenworksWindowsService] [27] [] [MessageLogger] [] [Ignoring the Settings as the revision number is same] [] []
    [DEBUG] [11/25/2011 09:06:45.692] [660] [ZenworksWindowsService] [27] [] [LOGGERCONFIGURATOR] [] [A new settings has been provided to Logger to change its configuration for sysLogging] [] []
    [DEBUG] [11/25/2011 09:06:45.770] [660] [ZenworksWindowsService] [47] [] [Remote Management Module] [] [Updated the RM Configuration file.] [] []
    [DEBUG] [11/25/2011 09:06:45.848] [660] [ZenworksWindowsService] [47] [] [Remote Management Module] [] [Info: Sent ZRMConfigurationChangeEvent event to WinVNC server.] [] []
    [DEBUG] [11/25/2011 09:06:45.864] [660] [ZenworksWindowsService] [23] [] [ZenCache] [] [(Thread 23) GetObject(PROXY_OVERRIDE, UserContext{_LocalId=none; _RemoteId=(Public)}) called] [] []
    [DEBUG] [11/25/2011 09:06:45.880] [660] [ZenworksWindowsService] [23] [] [ZenCache] [] [(Thread 23) GetObject returning <not cached> in 0 ms] [] []
    [DEBUG] [11/25/2011 09:06:45.880] [660] [ZenworksWindowsService] [23] [] [ZenCache] [] [(Thread 23) GetObject(PROXY_DEFAULT, UserContext{_LocalId=none; _RemoteId=(Public)}) called] [] []
    [DEBUG] [11/25/2011 09:06:45.880] [660] [ZenworksWindowsService] [23] [] [ZenCache] [] [(Thread 23) GetObject returning <not cached> in 0 ms] [] []
    [DEBUG] [11/25/2011 09:06:45.880] [660] [ZenworksWindowsService] [23] [] [BundleManager] [] [ApplicationService GetAppService appContext.GetWebServiceURI() = https://199.0.8.11/zenworks-bundleservice/] [] []
    [DEBUG] [11/25/2011 09:06:45.880] [660] [ZenworksWindowsService] [23] [] [ZMD] [] [Soap Utility: KeepAlive is read from registry. KeepAlive = True] [] []
    [DEBUG] [11/25/2011 09:07:03.230] [660] [ZenworksWindowsService] [23] [] [BundleManager] [] [BUNDLE.CouldNotGetBundleDetailsException] [] []
    [DEBUG] [11/25/2011 09:07:03.230] [660] [ZenworksWindowsService] [23] [] [ZMD] [] [GetCurrentURIFromConnectMan - URI is bad https://199.0.8.11/zenworks-bundleservice/ trying to find another one] [] []
    [DEBUG] [11/25/2011 09:07:03.230] [660] [ZenworksWindowsService] [23] [] [ConnectMan] [] [FindNextContent()] [] []
    [DEBUG] [11/25/2011 09:07:03.230] [660] [ZenworksWindowsService] [23] [] [ConnectMan] [] [ badUri: https://199.0.8.11/zenworks-bundleservice/] [] []
    [DEBUG] [11/25/2011 09:07:03.230] [660] [ZenworksWindowsService] [23] [] [ConnectMan] [] [ Exception: There is an error in XML document (92, 393489).] [] []
    [DEBUG] [11/25/2011 09:07:03.230] [660] [ZenworksWindowsService] [23] [] [ConnectMan] [] [ ] [] []
    [DEBUG] [11/25/2011 09:07:03.230] [660] [ZenworksWindowsService] [23] [] [ConnectMan] [] [https://server/zenworks-bundleservice/ ] [] []
    [DEBUG] [11/25/2011 09:07:03.230] [660] [ZenworksWindowsService] [23] [] [ConnectMan] [] [https://199.0.8.11/zenworks-bundleservice/ ] [] []
    [DEBUG] [11/25/2011 09:07:03.230] [660] [ZenworksWindowsService] [23] [] [ConnectMan] [] [ ] [] []
    [DEBUG] [11/25/2011 09:07:03.230] [660] [ZenworksWindowsService] [23] [] [ConnectMan] [] [Marking IP Location https://server/zenworks-bundleservice/: Bad] [] []
    [DEBUG] [11/25/2011 09:07:03.230] [660] [ZenworksWindowsService] [23] [] [ConnectMan] [] [Unknown Exception] [] []
    [DEBUG] [11/25/2011 09:07:03.230] [660] [ZenworksWindowsService] [23] [] [ConnectMan] [] [There is an error in XML document (92, 393489).] [] []
    [DEBUG] [11/25/2011 09:07:03.230] [660] [ZenworksWindowsService] [23] [] [ConnectMan] [] [ at System.Xml.Serialization.XmlSerializer.Deserialize (XmlReader xmlReader, String encodingStyle, XmlDeserializationEvents events)
    at System.Xml.Serialization.XmlSerializer.Deserialize (XmlReader xmlReader, String encodingStyle)
    at System.Web.Services.Protocols.SoapHttpClientProtoc ol.ReadResponse(SoapClientMessage message, WebResponse response, Stream responseStream, Boolean asyncCall)
    at System.Web.Services.Protocols.SoapHttpClientProtoc ol.Invoke(String methodName, Object() parameters)
    at Novell.Zenworks.AppModule.Schema.ApplicationServic e.getAppDetails(GetAppDetailsRequest GetAppDetailsRequest)
    at Novell.Zenworks.AppModule.WebAppService.GetAppDeta ils(GetAppDetailsRequest request)] [] []
    [DEBUG] [11/25/2011 09:07:03.246] [660] [ZenworksWindowsService] [23] [] [ConnectMan] [] [Marking location https://199.0.8.11/zenworks-bundleservice/ Bad at the request of module bundleservice] [] []
    [DEBUG] [11/25/2011 09:07:03.246] [660] [ZenworksWindowsService] [23] [] [ConnectMan] [] [ Setting location name https://199.0.8.11/zenworks-bundleservice/ to status Bad] [] []
    [DEBUG] [11/25/2011 09:07:03.246] [660] [ZenworksWindowsService] [23] [] [ConnectMan] [] [ Exception causing location name https://199.0.8.11/zenworks-bundleservice/ to be marked Bad: System.InvalidOperationException: There is an error in XML document (92, 393489). ---> System.Xml.XmlException: The 'null' start tag on line 92 does not match the end tag of 'DestDir'. Line 92, position 393489.
    at System.Xml.XmlTextReaderImpl.Throw(Exception e)
    at System.Xml.XmlTextReaderImpl.Throw(String res, String() args)
    at System.Xml.XmlTextReaderImpl.ThrowTagMismatch(Node Data startTag)
    at System.Xml.XmlTextReaderImpl.ParseEndElement()
    at System.Xml.XmlTextReaderImpl.ParseElementContent()
    at System.Xml.XmlTextReaderImpl.Read()
    at System.Xml.XmlTextReader.Read()
    at System.Xml.XmlLoader.LoadNode(Boolean skipOverWhitespace)
    at System.Xml.XmlLoader.ReadCurrentNode(XmlDocument doc, XmlReader reader)
    at System.Xml.XmlDocument.ReadNode(XmlReader reader)
    at System.Xml.Serialization.XmlSerializationReader.Re adXmlNode(Boolean wrapped)
    at Microsoft.Xml.Serialization.GeneratedAssembly.XmlS erializationReaderApplicationService.Read14_AppDat aActionSetsInstall(Boolean isNullable, Boolean checkType)
    at Microsoft.Xml.Serialization.GeneratedAssembly.XmlS erializationReaderApplicationService.Read21_AppDat aActionSets(Boolean isNullable, Boolean checkType)
    at Microsoft.Xml.Serialization.GeneratedAssembly.XmlS erializationReaderApplicationService.Read24_AppDat a(Boolean isNullable, Boolean checkType)
    at Microsoft.Xml.Serialization.GeneratedAssembly.XmlS erializationReaderApplicationService.Read25_GetApp DetailsResponseAppResult(Boolean isNullable, Boolean checkType)
    at Microsoft.Xml.Serialization.GeneratedAssembly.XmlS erializationReaderApplicationService.Read26_GetApp DetailsResponse(Boolean isNullable, Boolean checkType)
    at Microsoft.Xml.Serialization.GeneratedAssembly.XmlS erializationReaderApplicationService.Read32_getApp DetailsResponse()
    at Microsoft.Xml.Serialization.GeneratedAssembly.Arra yOfObjectSerializer5.Deserialize(XmlSerializationR eader reader)
    at System.Xml.Serialization.XmlSerializer.Deserialize (XmlReader xmlReader, String encodingStyle, XmlDeserializationEvents events)
    --- End of inner exception stack trace ---
    at System.Xml.Serialization.XmlSerializer.Deserialize (XmlReader xmlReader, String encodingStyle, XmlDeserializationEvents events)
    at System.Xml.Serialization.XmlSerializer.Deserialize (XmlReader xmlReader, String encodingStyle)
    at System.Web.Services.Protocols.SoapHttpClientProtoc ol.ReadResponse(SoapClientMessage message, WebResponse response, Stream responseStream, Boolean asyncCall)
    at System.Web.Services.Protocols.SoapHttpClientProtoc ol.Invoke(String methodName, Object() parameters)
    at Novell.Zenworks.AppModule.Schema.ApplicationServic e.getAppDetails(GetAppDetailsRequest GetAppDetailsRequest)
    at Novell.Zenworks.AppModule.WebAppService.GetAppDeta ils(GetAppDetailsRequest request)] [] []
    [DEBUG] [11/25/2011 09:07:03.246] [660] [ZenworksWindowsService] [23] [] [ConnectMan] [] [Exiting MarkLocationBad] [] []
    [DEBUG] [11/25/2011 09:07:03.246] [660] [ZenworksWindowsService] [23] [] [ConnectMan] [] [FindFirstContent()] [] []
    [DEBUG] [11/25/2011 09:07:03.246] [660] [ZenworksWindowsService] [23] [] [ConnectMan] [] [ ] [] []
    [DEBUG] [11/25/2011 09:07:03.246] [660] [ZenworksWindowsService] [23] [] [ConnectMan] [] [ ] [] []
    [DEBUG] [11/25/2011 09:07:03.246] [660] [ZenworksWindowsService] [23] [] [ConnectMan] [] [ Found host server status: Good] [] []
    [DEBUG] [11/25/2011 09:07:03.246] [660] [ZenworksWindowsService] [23] [] [ConnectMan] [] [ Found location https://199.0.8.11/zenworks-bundleservice/ status: Bad] [] []
    [DEBUG] [11/25/2011 09:07:03.246] [660] [ZenworksWindowsService] [23] [] [ConnectMan] [] [ Skipping IP location: https://199.0.8.11/zenworks-bundleservice/, status: Bad] [] []
    [DEBUG] [11/25/2011 09:07:03.246] [660] [ZenworksWindowsService] [23] [] [ConnectMan] [] [ Found host 199.0.8.11 status: Unknown] [] []
    [DEBUG] [11/25/2011 09:07:03.246] [660] [ZenworksWindowsService] [23] [] [ConnectMan] [] [ Found location https://199.0.8.11/zenworks-bundleservice/ status: Bad] [] []
    [DEBUG] [11/25/2011 09:07:03.246] [660] [ZenworksWindowsService] [23] [] [ConnectMan] [] [ Skipping IP location: https://199.0.8.11/zenworks-bundleservice/, status: Bad] [] []
    [DEBUG] [11/25/2011 09:07:03.246] [660] [ZenworksWindowsService] [23] [] [ConnectMan] [] [Trying to locate source location: https://server/zenworks-bundleservice/] [] []
    [DEBUG] [11/25/2011 09:07:03.246] [660] [ZenworksWindowsService] [23] [] [ConnectMan] [] [ Host name to resolve: server] [] []
    [DEBUG] [11/25/2011 09:07:03.246] [660] [ZenworksWindowsService] [23] [] [ConnectMan] [] [ Found host: server, status: Good] [] []
    [DEBUG] [11/25/2011 09:07:03.246] [660] [ZenworksWindowsService] [23] [] [ConnectMan] [] [ Skipping location: https://199.0.8.11/zenworks-bundleservice/, status: Bad] [] []
    [DEBUG] [11/25/2011 09:07:03.246] [660] [ZenworksWindowsService] [23] [] [ConnectMan] [] [Trying to locate source location: https://199.0.8.11/zenworks-bundleservice/] [] []
    [DEBUG] [11/25/2011 09:07:03.246] [660] [ZenworksWindowsService] [23] [] [ConnectMan] [] [ Host name to resolve: 199.0.8.11] [] []
    [DEBUG] [11/25/2011 09:07:03.246] [660] [ZenworksWindowsService] [23] [] [ConnectMan] [] [ Found host: 199.0.8.11, status: Unknown] [] []
    [DEBUG] [11/25/2011 09:07:03.246] [660] [ZenworksWindowsService] [23] [] [ConnectMan] [] [ Host: 199.0.8.11, IP address: 199.0.8.11] [] []
    [DEBUG] [11/25/2011 09:07:03.246] [660] [ZenworksWindowsService] [23] [] [ConnectMan] [] [ Using IP address: 199.0.8.11, status: Good] [] []
    [DEBUG] [11/25/2011 09:07:03.246] [660] [ZenworksWindowsService] [23] [] [ConnectMan] [] [Entered FindServerFromBusyList] [] []
    [DEBUG] [11/25/2011 09:07:03.246] [660] [ZenworksWindowsService] [23] [] [ConnectMan] [] [ FindServerFromBusyList() Found host: server, status: Good] [] []
    [DEBUG] [11/25/2011 09:07:03.246] [660] [ZenworksWindowsService] [23] [] [ConnectMan] [] [ IP address 199.0.8.11 marked Good] [] []
    [DEBUG] [11/25/2011 09:07:03.246] [660] [ZenworksWindowsService] [23] [] [ConnectMan] [] [GetGoodOrBusyIp() returning 199.0.8.11] [] []
    [DEBUG] [11/25/2011 09:07:03.246] [660] [ZenworksWindowsService] [23] [] [ConnectMan] [] [ FindServerFromBusyList() Skipping location: https://199.0.8.11/zenworks-bundleservice/, status: Bad] [] []
    [DEBUG] [11/25/2011 09:07:03.246] [660] [ZenworksWindowsService] [23] [] [ConnectMan] [] [ FindServerFromBusyList() Found host: 199.0.8.11, status: Unknown] [] []
    [DEBUG] [11/25/2011 09:07:03.246] [660] [ZenworksWindowsService] [23] [] [ConnectMan] [] [ IP address 199.0.8.11 marked Good] [] []
    [DEBUG] [11/25/2011 09:07:03.246] [660] [ZenworksWindowsService] [23] [] [ConnectMan] [] [GetGoodOrBusyIp() returning 199.0.8.11] [] []
    [DEBUG] [11/25/2011 09:07:03.246] [660] [ZenworksWindowsService] [23] [] [ConnectMan] [] [ FindServerFromBusyList() Skipping location: https://199.0.8.11/zenworks-bundleservice/, status: Bad] [] []
    [DEBUG] [11/25/2011 09:07:03.246] [660] [ZenworksWindowsService] [23] [] [ConnectMan] [] [Exited FindServerFromBusyList with Server = to null] [] []
    [DEBUG] [11/25/2011 09:07:03.246] [660] [ZenworksWindowsService] [23] [] [ConnectMan] [] [FindFirstContent() returning ] [] []
    [DEBUG] [11/25/2011 09:07:03.246] [660] [ZenworksWindowsService] [23] [] [ConnectMan] [] [FindNextContent: Exiting with content null] [] []
    [DEBUG] [11/25/2011 09:07:03.246] [660] [ZenworksWindowsService] [23] [] [ZMD] [] [GetCurrentURIFromConnectMan - New uri is: ] [] []
    [DEBUG] [11/25/2011 09:07:03.246] [660] [ZenworksWindowsService] [23] [] [BundleManager] [] [!!!!!!!!!!! No Bundle Data Retrieved !!!!!!!!!!!!!!!!!] [] []
    [DEBUG] [11/25/2011 09:07:03.246] [660] [ZenworksWindowsService] [23] [] [BundleManager] [] [Exiting GetBundle details] [] []
    [DEBUG] [11/25/2011 09:07:03.246] [660] [ZenworksWindowsService] [23] [] [BundleManager] [] [Time for GeneralRefresh: 553] [] []
    [DEBUG] [11/25/2011 09:07:03.246] [660] [ZenworksWindowsService] [23] [] [BundleManager] [] [Found details for 3 bundles] [] []
    [DEBUG] [11/25/2011 09:07:03.246] [660] [ZenworksWindowsService] [23] [] [BundleManager] [] [ Found bundle Infutik auth; GUID: 5f49e281737695163d4c929d98844c25; Version: 0] [] []
    [DEBUG] [11/25/2011 09:07:03.246] [660] [ZenworksWindowsService] [23] [] [BundleManager] [] [ Found bundle Windows XP default ekraani-asetused; GUID: 3b78a17437ec0c9c9be7b8bb5cf484c5; Version: 2] [] []
    [DEBUG] [11/25/2011 09:07:03.246] [660] [ZenworksWindowsService] [23] [] [BundleManager] [] [ Found bundle Log-kataloog; GUID: 7b78a1535264a515dcb72a8d87485101; Version: 0] [] []
    [ERROR] [11/25/2011 09:07:03.246] [660] [ZenworksWindowsService] [23] [] [BundleManager] [BUNDLE.CouldNotAddBundle] [Could not add bundle 34ddcd7a97507d05b754a1b05be8c19a to session] [] []
    [ERROR] [11/25/2011 09:07:03.261] [660] [ZenworksWindowsService] [23] [] [BundleManager] [BUNDLE.CouldNotAddBundle] [Could not add bundle b1f973c7db610170c53eb630a381236c to session] [] []
    [ERROR] [11/25/2011 09:07:03.261] [660] [ZenworksWindowsService] [23] [] [BundleManager] [BUNDLE.CouldNotAddBundle] [Could not add bundle 0e265efd29dee160013d4030b90ebab3 to session] [] []
    [ERROR] [11/25/2011 09:07:03.261] [660] [ZenworksWindowsService] [23] [] [BundleManager] [BUNDLE.CouldNotAddBundle] [Could not add bundle 53880f0e33e70a863c6acf218814a498 to session] [] []
    [DEBUG] [11/25/2011 09:07:03.261] [660] [ZenworksWindowsService] [23] [] [MessageLogger] [] [Unable to write to event log (Application) using source (Novell.Zenworks.Logger) Exception: System.ComponentModel.Win32Exception: The event log file is full
    at System.Diagnostics.EventLog.InternalWriteEvent(UIn t32 eventID, UInt16 category, EventLogEntryType type, String() strings, Byte() rawData, String currentMachineName)
    at System.Diagnostics.EventLog.WriteEntry(String message, EventLogEntryType type, Int32 eventID, Int16 category, Byte() rawData)
    at System.Diagnostics.EventLog.WriteEntry(String source, String message, EventLogEntryType type, Int32 eventID, Int16 category, Byte() rawData)
    at System.Diagnostics.EventLog.WriteEntry(String source, String message, EventLogEntryType type, Int32 eventID)
    at log4net.Appender.EventLogAppender.Append(LoggingEv ent loggingEvent)] [] []
    [ERROR] [11/25/2011 09:07:03.261] [660] [ZenworksWindowsService] [23] [] [BundleManager] [BUNDLE.CouldNotAddBundle] [Could not add bundle e0b738c3966a354de7cd84e3e76ef366 to session] [] []
    [DEBUG] [11/25/2011 09:07:03.261] [660] [ZenworksWindowsService] [23] [] [MessageLogger] [] [Unable to write to event log (Application) using source (Novell.Zenworks.Logger) Exception: System.ComponentModel.Win32Exception: The event log file is full
    at System.Diagnostics.EventLog.InternalWriteEvent(UIn t32 eventID, UInt16 category, EventLogEntryType type, String() strings, Byte() rawData, String currentMachineName)
    at System.Diagnostics.EventLog.WriteEntry(String message, EventLogEntryType type, Int32 eventID, Int16 category, Byte() rawData)
    at System.Diagnostics.EventLog.WriteEntry(String source, String message, EventLogEntryType type, Int32 eventID, Int16 category, Byte() rawData)
    at System.Diagnostics.EventLog.WriteEntry(String source, String message, EventLogEntryType type, Int32 eventID)
    at log4net.Appender.EventLogAppender.Append(LoggingEv ent loggingEvent)] [] []
    More thanks, Alar.

  • Forwarded events log empty

    Hi all,
    I have a frustrating issue with forwarded events log which still empty when I change the location of this one to the D partition rather than the defaut setting C: (it works fine in C:)
    once I change the location in the proerties of forwarded events to D: a new log is created but still empty.
    Any ideas, please, Thanks

    Hi Justin, 
    I checked the file key in the registry and I have well the new location set as value (D:\forwardedEvts.evtx)
    In the event viewer, on the forwarded events I have this message "event
    viewer cannot open the event log or custom view. verify that event log service is running or query is too long. access is denied (5)"
    Thanks,

Maybe you are looking for

  • How to pool web services in BEA 8.1

    All, I would like to have multiple instances of the web service running in the same server. Does Weblogic 8.1 do this? How? Thanks so much for your any help. Weili

  • File is not downloading!!!

    Hello In my WDA (ABAP) i have a file upload and file download UI elements/functionality, actually, my business requirement is ditto to the below link and hence i did the same in my WDA as suggested in the below wiki link [url] http://wiki.sdn.sap.com

  • Need to create template to delete sections (in a batch of images, if possible)

    I was given a batch of photos (all the same size) that need notches punched into each side. The result are notches with deleted space on both sides. Since there is a stack of them to do--and the notches need to be precise--I was trying to figure out;

  • I don't know what Final Cut Pro Academic Version 4.0 I have.

    Hi. im interested in upgrading to Final cut studio, but I do not know if i qualify. No where on my install disc does it say waht numer it is. I've looked at the download order forms for the crossgrades etc. But i'm still not sure what model no# miine

  • HR_INFOTYPE_OPERATION within Dynamic Action

    Hello, I am calling HR_INFOTYPE_OPERATION from within the Dynamic Action.  I can debug through it and even have it display the screens and everything appears to work fine.  The return structure is clear of any errors and the key structure indicates t