Events 5719, NETLOGON, Event 1129, Microsoft-Windows-GroupPolicy

I have been seeing these events lately on our Windows 7 PCs. We have 2 domain controllers, Server 2012 and 2003.  I think most of these events started after I added the 2012 DC.  We were running just the one 2003 DC.  I moved DHCP from
the 2003 to the 2012.  Both servers are AD integrated DNS servers and a third server is a DNS secondary server.
I tried the hotfix from here...
http://support.microsoft.com/kb/2459530
on one PC as a test.  It appears to have solved the 1129 event but I still get the 5719 NETLOGON event.  I also tried updating the Gigabit NIC drivers on this system but it didn't help.  What should I try next?
 


Hi,
According to the following article,
this behavior can occur when your server is connected to a switch that has the spanning tree "portfast" setting disabled.
To work around this behavior, enable the spanning tree "portfast" setting on the switch.
A “Netlogon event ID 5719” event message is logged when you start a Windows based computer
http://support.microsoft.com/kb/247922
Hope this helps.

Similar Messages

  • Event Message missing (replaced by %% EventID ) in Microsoft-Windows-GroupPolicy provider

    Hi,
    Does anyone know why some of the events in ETL (created using WPRUI) generated through Microsoft-Windows-GroupPolicy provider have '%%<EventID>' instead of the event description? Is there a way
    to fix it?
    I wonder if the standard 'First Level Triage' profile doesn't have some necessary option configured to have these collected and the log should be collected using command line?
    Thanks,
    Ivan
    Ivan Seriavin

    Hi,
    Does anyone know why some of the events in ETL (created using WPRUI) generated through Microsoft-Windows-GroupPolicy provider have '%%<EventID>' instead of the event description? Is there a way
    to fix it?
    I wonder if the standard 'First Level Triage' profile doesn't have some necessary option configured to have these collected and the log should be collected using command line?
    Thanks,
    Ivan
    Ivan Seriavin

  • Event ID 10016 - DCOM Error | Source - Microsoft-Windows-DistributedCOM | Level: Error

    Hi there... I am getting the above mentioned error with the
    Description: dows-DistributedCOM cannot be found. Either the component that raises this event is not installed on your local computer or the installation is corrupted. You can install or repair the component on the local computer.
    Full message is -
    Log Name:      System
    Source:        Microsoft-Windows-DistributedCOM
    Date:          5/15/2012 1:18:44 PM
    Event ID:      10016
    Task Category: None
    Level:         Error
    Keywords:      Classic
    User:          NT AUTHORITY\IUSR
    Computer:      Server.domain.com
    Description:
    The description for Event ID 10016 from source Microsoft-Windows-DistributedCOM cannot be found. Either the component that raises this event is not installed on your local computer or the installation is corrupted. You can install or repair the component on
    the local computer.
    If the event originated on another computer, the display information had to be saved with the event.
    The following information was included with the event:
    application-specific
    Local
    Activation
    {2D527A8C-A4B6-4E74-A63F-E867360D401C}
    {B13EFBAE-7504-4938-9ED7-8E8B53E51221}
    NT AUTHORITY
    IUSR
    S-1-5-17
    LocalHost (Using LRPC)
    Event Xml:
    <Event xmlns="http://schemas.microsoft.com/win/2004/08/events/event">
      <System>
        <Provider Name="Microsoft-Windows-DistributedCOM" Guid="{1B562E86-B7AA-4131-BADC-B6F3A001407E}" EventSourceName="DCOM" />
        <EventID Qualifiers="49152">10016</EventID>
        <Version>0</Version>
        <Level>2</Level>
        <Task>0</Task>
        <Opcode>0</Opcode>
        <Keywords>0x80000000000000</Keywords>
        <TimeCreated SystemTime="2012-05-15T19:18:44.000000000Z" />
        <EventRecordID>43121</EventRecordID>
        <Correlation />
        <Execution ProcessID="0" ThreadID="0" />
        <Channel>System</Channel>
        <Computer>Server.Domain.com</Computer>
        <Security UserID="S-1-5-17" />
      </System>
      <EventData>
        <Data Name="param1">application-specific</Data>
        <Data Name="param2">Local</Data>
        <Data Name="param3">Activation</Data>
        <Data Name="param4">{2D527A8C-A4B6-4E74-A63F-E867360D401C}</Data>
        <Data Name="param5">{B13EFBAE-7504-4938-9ED7-8E8B53E51221}</Data>
        <Data Name="param6">NT AUTHORITY</Data>
        <Data Name="param7">IUSR</Data>
        <Data Name="param8">S-1-5-17</Data>
        <Data Name="param9">LocalHost (Using LRPC)</Data>
      </EventData>
    </Event>
    Please let me know any solutions to fix....
    Steps, I did try from one of the blogs -
    Open Component Services. Got oStart --> Control Panel --> Administrative Tools --> Components Services. Expand the Component Services branch then expand Computers, My Computer and DCOM Config. Right-click on "sms agent host" (my case) and click
    Properties. Click on the Security tab and under “Launch and Activation Permissions” select "edit" and add user Local Service (Local lunch). Click OK, close the Component Services window.
    In the Launch Permission dialog box, make sure that the Everyone group has Remote Launch and Remote Activation permissions.
    In the Launch Permission dialog box, make sure that the SMS Reporting Users local group has following permissions:
    Local Launch / Remote Launch / Local Activation / Remote Activation
    Also added Remote Launch / Remote Activation permission for Network Service (for the SMS_Reporting_Point)
    Added Admin Group to the "ConfigMgr Remote Control Users"
    VT

    In addition, In the security policy the ‘Local Service’ need to be configured for the following Policies
    - Generate security audits
    - Create global objects
    - Replace a process level token
    - Adjust memory quotas for a process
    - Impersonate a client after authentication
    - Log on as a service
    - Bypass traverse checking
    Hope this helps.
    Regards,
    Yan Li
    hi,
    i m having similiar error but with another APPID 
    i did what u said in 1st part but i couldnt get what u mean in additional settings ? i couldnt do that. 
    Error details :
    Log Name:      System
    Source:        Microsoft-Windows-DistributedCOM
    Date:          7/2/2013 4:03:20 PM
    Event ID:      10016
    Task Category: None
    Level:         Error
    Keywords:      Classic
    User:          LOCAL SERVICE
    Computer:      THINK
    Description:
    The machine-default permission settings do not grant Local Activation permission for the COM Server application with CLSID 
    {7160A13D-73DA-4CEA-95B9-37356478588A}
     and APPID 
    {7160A13D-73DA-4CEA-95B9-37356478588A}
     to the user NT AUTHORITY\LOCAL SERVICE SID (S-1-5-19) from address LocalHost (Using LRPC) running in the application container Unavailable SID (Unavailable). This security permission can be modified using the Component Services administrative tool.
    Event Xml:
    <Event xmlns="http://schemas.microsoft.com/win/2004/08/events/event">
      <System>
        <Provider Name="Microsoft-Windows-DistributedCOM" Guid="{1B562E86-B7AA-4131-BADC-B6F3A001407E}" EventSourceName="DCOM" />
        <EventID Qualifiers="0">10016</EventID>
        <Version>0</Version>
        <Level>2</Level>
        <Task>0</Task>
        <Opcode>0</Opcode>
        <Keywords>0x8080000000000000</Keywords>
        <TimeCreated SystemTime="2013-02-07T14:03:20.356793400Z" />
        <EventRecordID>1465</EventRecordID>
        <Correlation />
        <Execution ProcessID="868" ThreadID="2832" />
        <Channel>System</Channel>
        <Computer>THINK</Computer>
        <Security UserID="S-1-5-19" />
      </System>
      <EventData>
        <Data Name="param1">machine-default</Data>
        <Data Name="param2">Local</Data>
        <Data Name="param3">Activation</Data>
        <Data Name="param4">{7160A13D-73DA-4CEA-95B9-37356478588A}</Data>
        <Data Name="param5">{7160A13D-73DA-4CEA-95B9-37356478588A}</Data>
        <Data Name="param6">NT AUTHORITY</Data>
        <Data Name="param7">LOCAL SERVICE</Data>
        <Data Name="param8">S-1-5-19</Data>
        <Data Name="param9">LocalHost (Using LRPC)</Data>
        <Data Name="param10">Unavailable</Data>
        <Data Name="param11">Unavailable</Data>
      </EventData>
    </Event>

  • Event ID: 10009-Microsoft Windows DistributedCOM

    You all ever seen this error from System Logs?
    The description for Event ID 10009 from source Microsoft-Windows-DistributedCOM cannot be found. Either the component that raises this event is not installed on your local computer or the installation is corrupted. You can install or repair the component
    on the local computer.
    If the event originated on another computer, the display information had to be saved with the event.
    The following information was included with the event:
    COMPUTERNAMEHERE

    Thanks Torsten.
    From my research it looks like SCCM is trying to locate some machines that are no longer on the network but yet DNS is reporting it.
    So I have asked DNS Guys to flush or refresh the DNS.
    We often bring these dead\redundant records back from AD via the AD discovery methods ... it is a good idea to get the AD guys to do some house-cleaning or at least set the permissions on dead objects so that the Site serve performing the discovery does not
    have read access on the object.

  • How does one clear Custom Views (Administrative Events) in the Event Viewer?

    Windows Logs and Applications and Services Logs have a "clear log" option; however, I am puzzled how to edit/delete Administrative Events?Eighter from Decatur, county seat of Wise (of course it's in Texas)

    Ronnie Vernon said: Hi p010ne
    The Custom View / Administrative Events is a compilation of all the other event logs in the Event Viewer.
    Entries in this log will be removed when the log where the event originated from is cleared.
    Hope this helps.
    Ronnie Vernon MVP
    I thought that was the case; however, I cleared all the other logs! This is an example of an entry in this log: Log Name:      Microsoft-Windows-Dhcpv6-Client/AdminSource:        Microsoft-Windows-DHCPv6-Client
    Date:          1/17/2009 7:52:33 AM
    Event ID:      1001
    Task Category: Address Configuration State Event
    Level:         Error
    Keywords:      
    User:          LOCAL SERVICE
    Computer:      Windows7
    Description:
    Your computer was not assigned an address from the network (by the DHCP Server) for the Network Card with network address 0x000129F558C5.  The following error occurred: 0x79. Your computer will continue to try and obtain an address on its own from the network address (DHCP) server.
    Event Xml:
    <Event xmlns="http://schemas.microsoft.com/win/2004/08/events/event">
      <System>
        <Provider Name="Microsoft-Windows-DHCPv6-Client" Guid="{6A1F2B00-6A90-4C38-95A5-5CAB3B056778}" />
        <EventID>1001</EventID>
        <Version>0</Version>
        <Level>2</Level>
        <Task>3</Task>
        <Opcode>74</Opcode>
        <Keywords>0x8000000000000000</Keywords>
        <TimeCreated SystemTime="2009-01-17T13:52:33.858398400Z" />
        <EventRecordID>202</EventRecordID>
        <Correlation />
        <Execution ProcessID="1088" ThreadID="864" />
        <Channel>Microsoft-Windows-Dhcpv6-Client/Admin</Channel>
        <Computer>Windows7</Computer>
        <Security UserID="S-1-5-19" />
      </System>
      <EventData>
        <Data Name="HWLength">6</Data>
        <Data Name="HWAddress">000129F558C5</Data>
        <Data Name="StatusCode">121</Data>
      </EventData>
    </Event>
    When I search for "Microsoft-Windows-DHCPv6-Client" I do not find that file?
    OK, I found the entrys in the Microsoft section (DHCPv6-Client) and am able to clear them there! 
    Eighter from Decatur, county seat of Wise (of course it's in Texas)

  • Forwarding events and clarifying events format information

    Hello.
    I've set up source initiated subscription for auditing file system usage. I need to know what files are added or deleted to the file share resource and by whom. So, subscription is working, and I get such kind of event on
    source server:
    Log Name: Security
    Source: Microsoft-Windows-Security-Auditing
    Date: 08.07.2014 11:23:01
    Event ID: 4663
    Task Category: File System
    Level: Information
    Keywords: Audit Success
    User: N/A
    Computer: fileserver.example.com
    Description:
    An attempt was made to access an object.
    Subject:
    Security ID: EXAMPLE\username
    Account Name: username
    Account Domain: EXAMPLE
    Logon ID:
    Object:
    Object Server: Security
    Object Type: File
    Object Name: *path_to_file_or_folder_here*
    Handle ID:
    Process Information:
    Process ID: 0x4
    Process Name:
    Access Request Information:
    Accesses: DELETE
    Access Mask: 0x10000
    The main thing I need from such event are username, path to file or folder and access information (delete here).
    After transferring such event by event subscription the resulting event on the
    collector server differs:
    Log Name: Security
    Source: Microsoft-Windows-Security-Auditing
    Date: 08.07.2014 9:54:42
    Event ID: 4663
    Task Category: File System
    Level: Information
    Keywords: Audit Success
    User: N/A
    Computer: fileserver.example.com
    Description:
    An attempt was made to access an object.
    Subject:
    Security ID:
    Account Name: username
    Account Domain: EXAMPLE
    Logon ID:
    Object:
    Object Server: Security
    Object Type: File
    Object Name: *path_to_file_or_folder_here*
    Handle ID:
    Process Information:
    Process ID: 0x4
    Process Name: %12
    Access Request Information:
    Accesses: %9
    Access Mask: %10
    So, I have username and path here, but I don't have Process Name, Accesses and Access Mask information -
    Access I need most of all, without it such event is useless.
    Subscription format is Events (RenderedText doesn't bring normal description and writes The description for Event ID 4663 from source Microsoft-Windows-Security-Auditing cannot be found. Either the component that raises this event is not installed on
    your local computer or...). Dll-s and registry paths are the same, only adtschema.dll.mui creation date differs, but there is no registry link to this file anyway. Windows version on collecting and sending systems are 2008 R2. Locales are the same (US). So,
    it there any solution? Thanks in advance.
    Update. Parsing XML view of the event shows, that <Data Name="AccessList">%%1537</Data>
    corresponding to "DELETE" note in General view presents here, but it's not shown. It is shown on the source server. Also, events with Process Name field displayed correctly on the collecting server, but not all of the events has Process Name
    field. Any ideas?

    Hi Queequack,
    To forward Events, please follow this article and feedback:
    Quick and Dirty Large Scale Eventing for Windows
    Best Regards,
    Anna Wang

  • Event ID: 4, Source: Microsoft-Windows-Kernel-EventTracing, maximum file size for session "ReadyBoot" has been reached.

    Hello,
    I upgraded my machine to Win7 x64 Pro about 3 weeks ago. My HW is an Asus mobo, Intel Q9450 w/8GB RAM. The boot drives are two Raptors configured as RAID01. All the drivers are the latest available from Intel, Asus and 3rd party vendors. My WEI is 5.9, limited by the disk transfer rates, otherwise 7.1 and 7.2 on the other indexes.
    I've been receiving these errors at boot;
    Log Name:      Microsoft-Windows-Kernel-EventTracing/Admin
    Source:        Microsoft-Windows-Kernel-EventTracing
    Date:          11/10/2009 7:51:03 AM
    Event ID:      4
    Task Category: Logging
    Level:         Warning
    Keywords:      Session
    User:          SYSTEM
    Computer:      herbt-PC
    Description:
    The maximum file size for session "ReadyBoot" has been reached. As a result, events might be lost (not logged) to file "C:\Windows\Prefetch\ReadyBoot\ReadyBoot.etl". The maximum files size is currently set to 20971520 bytes.
    Event Xml:
    <Event xmlns="http://schemas.microsoft.com/win/2004/08/events/event">
      <System>
        <Provider Name="Microsoft-Windows-Kernel-EventTracing" Guid="{B675EC37-BDB6-4648-BC92-F3FDC74D3CA2}" />
        <EventID>4</EventID>
        <Version>0</Version>
        <Level>3</Level>
        <Task>1</Task>
        <Opcode>10</Opcode>
        <Keywords>0x8000000000000010</Keywords>
        <TimeCreated SystemTime="2009-11-10T12:51:03.393985600Z" />
        <EventRecordID>28</EventRecordID>
        <Correlation />
        <Execution ProcessID="4" ThreadID="164" />
        <Channel>Microsoft-Windows-Kernel-EventTracing/Admin</Channel>
        <Computer>herbt-PC</Computer>
        <Security UserID="S-1-5-18" />
      </System>
      <EventData>
        <Data Name="SessionName">ReadyBoot</Data>
        <Data Name="FileName">C:\Windows\Prefetch\ReadyBoot\ReadyBoot.etl</Data>
        <Data Name="ErrorCode">3221225864</Data>
        <Data Name="LoggingMode">0</Data>
        <Data Name="MaxFileSize">20971520</Data>
      </EventData>
    </Event>
    The image for PID 4 is listed as System.
    My searches have turned up similar events listed but no solutions.
    Any help would be appreciated.
    Cheers!

    Session "Circular Kernel Context Logger" failed to start with the following error: 0xC0000035
    As suggested above I assume this is a microsoft issue?  It has been discussed here and other forums for quite some time.  I never have seen a fix?  I wish when we received errors of this nature microsoft would tell us what they were.  How is this related to superfetch?  What is superfetch?  Why would superfetch have changed?
    BY THE WAY....  Superfetch is on(started) is on automatic and logs on as local system.  So this is not the cause of my issue.  Also what is readyboot?  Does the average computer really know what these programs/services or unique microsoft words/terms are?
    System
    Provider
    [ Name]
    Microsoft-Windows-Kernel-EventTracing
    [ Guid]
    {B675EC37-BDB6-4648-BC92-F3FDC74D3CA2}
    EventID
    2
    Version
    0
    Level
    2
    Task
    2
    Opcode
    12
    Keywords
    0x8000000000000010
    TimeCreated
    [ SystemTime]
    2010-04-11T14:35:49.829600000Z
    EventRecordID
    25
    Correlation
    Execution
    [ ProcessID]
    4
    [ ThreadID]
    48
    Channel
    Microsoft-Windows-Kernel-EventTracing/Admin
    Computer
    Daddy-PC
    Security
    [ UserID]
    S-1-5-18
    EventData
    SessionName
    Circular Kernel Context Logger
    FileName
    ErrorCode
    3221225525
    LoggingMode
    268436608
    Windows7, Windows, Win7

  • The event logging service encountered an error while processing an incoming event published from Microsoft-Windows-Security-Auditing.

    Last night, some of our systems installed updates released on 11/13/2014.  
    KB3021674
    KB2901983
    KB3023266
    KB3014029
    KB3022777
    KB3020388
    KB890830
    Today, all of the servers running Windows Server 2008 R2 started logging the following error in the Security log over and over:
    Log Name:      Security
    Source:        Microsoft-Windows-Eventlog
    Date:          1/15/2015 11:12:39 AM
    Event ID:      1108
    Task Category: Event processing
    Level:         Error
    Keywords:      Audit Success
    User:          N/A
    Description:
    The event logging service encountered an error while processing an incoming event published from Microsoft-Windows-Security-Auditing.
    Servers running Windows Server 2008 that also installed the updates are not experiencing the problem.  It looks like one of the updates may have introduced this problem with Server 2008 R2.

    ...Did you for sure confirm that:
    https://technet.microsoft.com/library/security/MS15-001
    is the cause?
    I did.  I had a VM that was not experiencing the problem.  I took a snapshot and tested the patches one by one.  Installing only KB3023266 immediately caused the issue to occur (after reboot).  A similar process was used to confirm that
    installing KB2675611 resolved the problem.
    Note that I found the installation of KB2675611 is usually quick, but it took several hours hours to install on some of our systems.  We had installed this patch a few months ago on a couple of servers and it was always quick to install.  But,
    it seems like installing it on a symptomatic system can cause it to take a long time.

  • Need Help Please Log Name: System Source: Microsoft-Windows-Kernel-Power Date: 11/10/2010 4:31:37 PM Event ID: 41 Task Category: (63)

    Log Name:      System
    Source:        Microsoft-Windows-Kernel-Power
    Date:          11/10/2010 4:31:37 PM
    Event ID:      41
    Task Category: (63)
    Level:         Critical
    Keywords:      (2)
    User:          SYSTEM
    Computer:      Felix-PC
    Description:
    The system has rebooted without cleanly shutting down first. This error could be caused if the system stopped responding, crashed, or lost power unexpectedly.
    Event Xml:
    <Event xmlns="http://schemas.microsoft.com/win/2004/08/events/event">
      <System>
        <Provider Name="Microsoft-Windows-Kernel-Power" Guid="{331C3B3A-2005-44C2-AC5E-77220C37D6B4}" />
        <EventID>41</EventID>
        <Version>2</Version>
        <Level>1</Level>
        <Task>63</Task>
        <Opcode>0</Opcode>
        <Keywords>0x8000000000000002</Keywords>
        <TimeCreated SystemTime="2010-10-11T06:31:37.175213500Z" />
        <EventRecordID>96455</EventRecordID>
        <Correlation />
        <Execution ProcessID="4" ThreadID="8" />
        <Channel>System</Channel>
        <Computer>Felix-PC</Computer>
        <Security UserID="S-1-5-18" />
      </System>
      <EventData>
        <Data Name="BugcheckCode">244</Data>
        <Data Name="BugcheckParameter1">0x3</Data>
        <Data Name="BugcheckParameter2">0xfffffa8002d20b30</Data>
        <Data Name="BugcheckParameter3">0xfffffa8002d20e10</Data>
        <Data Name="BugcheckParameter4">0xfffff80002fcd5d0</Data>
        <Data Name="SleepInProgress">false</Data>
        <Data Name="PowerButtonTimestamp">0</Data>
      </EventData>
    </Event>

        <Data Name="BugcheckCode">244</Data>
    244 (dez) = F4 (hex)
    Bug Check 0xF4: CRITICAL_OBJECT_TERMINATION -
    This indicates that a process or thread crucial to system operation has unexpectedly exited or been terminated.
    Cause
    Several processes and threads are necessary for the operation of the system. When they are terminated for any reason, the system can no longer function.
    Please copy the dmp files from the folder C:\Windows\Minidump first to your desktop, zip all dmp into 1 zip file and upload the zip file to your Skydrive [1] and post a link here, so that I can look at the dumps with the debugger and to to see the cause of
    the crash.
    André
    [1]
    http://social.technet.microsoft.com/Forums/en-US/w7itproui/thread/4fc10639-02db-4665-993a-08d865088d65
    "A programmer is just a tool which converts caffeine into code" CLIP- Stellvertreter http://www.winvistaside.de/

  • Event ID 1 Error Microsoft-Windows-UAC Microsoft-Windows-UAC/Operational

    This error pops upon every restart of Windows Server 2012.
    Event ID 1 Error Microsoft-Windows-UAC Microsoft-Windows-UAC/Operational
    The process failed to handle ERROR_ELEVATION_REQUIRED during the creation of a child process.
    Event Viewer traces user to S-1-5-18 SYSTEM, Execution ProcessID in Task Manager corresponds to SVCHOST.EXE.
    SYSTEM is the owner of SVCHOST.EXE, even having granted SYSTEM permission Full Control does not fix the error.
    Any help will be appreciated.

    @Dharmesh, thanks for your advice.
    The specific SVCHOST process causing the error runs these services :
     - Application Experience
     - Application Information
     - Certificate Propagation
     - Group Policy Client
     - IKE and AuthIP IPsec Keying Modules
     - IP Helper
     - Multimedia Class Scheduler
     - Remote Access Connection Manager
     - Remote Desktop Configuration
     - Routing and Remote Access
     - Server
     - Shell Hardware Detection
     - System Event Notification Service
     - Task Scheduler
     - Themes
     - User Profile Service
     - Windows Management Instructmentation
     - Windows Update
    I doubted if any of those would actually need the ElevateCreateProcess fix.
    However, I gave it a try, applying the compatibility fixes at Server 2003 and Vista SP2 levels; yet the error was not corrected.
    So, combing through those services seemed unavoidable. Eventually, the culprit was identified.
    For the benefits of people encountering the same issue, this may help save some clueless efforts.
    Somehow, Windows Server setup a RaMgmtUIRestartTask in Task Scheduler, to run ramgmtui.exe as Administrators at log on of any user; but, not granting it the necessary permission. It is supposed to start the Remote Access Management console, failing which
    it logs the Event ID 1 Error, and gives little hint on the whereabouts of the cause.
    To stop the error, one would simply locate the scheduled task, then have it disabled, or check the option to grant it the highest privilege.

  • Windows Operating System; Version: 6.1.7601.18409; Event ID: 36888; Event Source: Schannel; AlertDesc 10; ErrorState10

    The computer consistantly freezes for about one to two seconds over and over, making it difficult to navigate through web pages.  I have looked at the Event log and this is the only consistent error that has taken place that falls in line with this
    issue.  I have tried changing the Security in Internet Explorer and tried every option for SSL and TLS and removed all history and cookies after each change, as well as restarting my computer, and still to no avail.  Please help!  Thank you.

    See the below:
    http://social.technet.microsoft.com/Forums/en-US/67609e1a-ae35-48ef-a91a-a0b06992702f/windows-operating-system-version-61760117940-event-id-36888-event-source-schannel?forum=w7itproperf
    http://social.technet.microsoft.com/Forums/en-US/eca5e2cb-28b2-4170-944b-c4c3ea7c8d72/event-id-36888-event-source-schannel?forum=winservergen
    Rgds

  • The description for Event ID 8306 from source Microsoft-SharePoint Products-SharePoint Foundation cannot be found

    hi,
    can anyone please help me with the following:
    The description for Event ID 8306 from source Microsoft-SharePoint Products-SharePoint Foundation cannot be found. Either the component that raises this event is not installed on your local computer or the installation is corrupted. You can install or repair
    the component on the local computer.
    If the event originated on another computer, the display information had to be saved with the event.
    The following information was included with the event:
    The HTTP service located at http://localhost:32843/SecurityTokenServiceApplication/securitytoken.svc/actas is too busy.
    The publisher has been disabled and its resource is not avaiable. This usually occurs when the publisher is in the process of being uninstalled or upgraded
    _________________________________________________________ Fahad Khan

    Hi,
    Please try the following steps to troubleshoot your issue:
    1.      
    You can try to re-run SharePoint 2010 products configuration wizard to see any problems that still exist.
    2.      
    Go to IIS and see the status of SecurityTokenServiceApplicationPool service, whether it is stopped or not, restart the pool.
    3.      
    Go to manage web application services, review the status of Security Token Service application , try to restart.
    4.      
    In Central Administration>Security>Configure Service Account>Change the service account for the Security Token Service application to some other managed account.
    5.      
    If the issue persists, try the resolution in this blog:
    http://blogs.msdn.com/b/sowmyancs/archive/2010/07/16/sharepoint-2010-service-applications-bcs-metadata-access-service-are-not-working.aspx
    Let me know the result.
    Xue-Mei Chang

  • Event handling operation on other software windows

    Hi friends
    I am able to execute another external program through java code using
    Runtime.getRuntime().exec();
    But now I want to perform Event Handling operation on such a opened external program(software) window.
    Is it possible in Java to perform Event Handling operation on other software windows.
    Thanks

    Can anybody give me some idea. I already gave you hte idea. I told you to write the C++ code to do it. There is no other way. You cannot do that from Java.
    WRT the sockets post:
    whether you use JNI or sockets: the accessing code will still not be written in Java. Hence you still can't do it in Java.

  • Trigger event on mouse click over image window

    How can I use an event structure to pick up on a mouse click on an IMAQ window in Labview. Specifically, I want to pick up a click with the 'select point' tool.

    To work in a Winddraw window, will not want to use the Event Structure, but instead the WindLastEvent. This will allow you to capture the events that occur in the Winddraw window. Attached are two examples, one I wrote using events so users can set up ROI's and the other is using events in LabVIEW with a picture control on the front panel so user can select an ROI.
    I hope this helps!
    Chris D
    Ni Application Engineer
    Attachments:
    Line_Profile_of_Live_Image.vi ‏145 KB
    ROI_from_Picture_Control_using_Events.vi ‏111 KB

  • Microsoft-Windows-Folder Redirection Error 502. CSC database locked by another user

    Dear all,
    We are finalizing our Windows 7 migration where we migrated 500+ clients. In our enterprise concept we implemented RUP (Roaming User Profiles) and Redirected Folders for all
    users. The Redirected Folders have been by enabled by a single GPO which redirects all folders from
    AppData to
    Searches \\servername.domain.name\documents$\%username%.
    Problem:
    The RUP and Redirected folders solution works fine until a new user wants to logon. This new user has been migrated to RUP and Redirected on another system and
    he just wants to work on another workplace or gets a temporary pc. What happens is that redirected folders do not work. The user gets a message that the folder is not reachable and desktop is empty.
    Troubleshooting:
    Soon I found out that something was being locked. If we used a user account which had working Redirect Folders than this
    worked for that user. An event of 10 was logged in OfflineFiles area of EventViewer to reconnect the path which was configured in the GPO.
    This is example screenshot. It says "Error on Open Folder. \\server.domain.name\documents$\%username%\Desktop refers to a location that is unavailable. It could be on a hard disk
    on this computer, or a on a network. Check to make sure that the disk is properly inserted, or that you are connected to the Internet or your network, and then try again. If it still cannot be located, the information might have been moved to a different location."
    These symptoms happen randomly and not on all workstations. The pain here is when it happens on a portable computer. For desktop we disabled the "Disable Offline Files' in "Manage
    Offline Files" control panel and then reboot. After the reboot the folders are directed
    and it works without these errors... On portable computer we can't use this work around as they need to work offline.
    If I connect to the share without the FQDN like \\servername\documents$\%username%\Desktop than this works fine and user can access all folders. When I try the FQDN path which is
    configured in the GPO to redirect user to like \\servername.domain.name\documents$\%username%\Desktop than it fails with this message. I personally think because the C:\Windows\CSC database is locked by the previous user who has been logged on this system.
    An example of the event generated in the Applications Event viewer part (I removed some username and server path):
    Log Name:      Application
    Source:        Microsoft-Windows-Folder Redirection
    Date:          1-2-2011 17:40:11
    Event ID:      502
    Task Category: None
    Level:         Error
    Keywords:     
    User:          domain\ivan
    Computer:      computer.domain.name
    Description:
    Failed to apply policy and redirect folder "Videos" to "\\servername.domain.name\documents$\ivan\Documents\My Videos".
     Redirection options=0x1001.
     The following error occurred: "Can not create folder "\\\servername.domain.name\documents$\ivan\Documents\My Videos"".
     Error details: "Access is denied.
    Event Xml:
    <Event xmlns="http://schemas.microsoft.com/win/2004/08/events/event">
      <System>
        <Provider Name="Microsoft-Windows-Folder Redirection" Guid="{7D7B0C39-93F6-4100-BD96-4DDA859652C5}" />
        <EventID>502</EventID>
        <Version>0</Version>
        <Level>2</Level>
        <Task>0</Task>
        <Opcode>0</Opcode>
        <Keywords>0x8000000000000000</Keywords>
        <TimeCreated SystemTime="2011-02-01T16:40:11.486983400Z" />
        <EventRecordID>2754</EventRecordID>
        <Correlation ActivityID="{3211E6FB-2801-456D-BE6E-66AAE150A4DC}" />
        <Execution ProcessID="968" ThreadID="5856" />
        <Channel>Application</Channel>
        <Computer>computer.domain.name</Computer>
        <Security UserID="S-1-5-21-3705223304-2632712944-1292073641-26755" />
      </System>
      <EventData Name="EVENT_FDEPLOY_FailedToApplyPolicy">
        <Data Name="FromFolder">Videos</Data>
        <Data Name="ToFolder">\\servername.domain.name\documents$\ivan\Documents\My Videos</Data>
        <Data Name="Options">0x1001</Data>
        <Data Name="Error">Can not create folder "\\servername.domain.name\documents$\ivan\Documents\My Videos"</Data>
        <Data Name="ErrorDetails">Access is denied.
    </Data>
      </EventData>
    </Event> 
    Something like this I see in the Application Eventviewer:
    Environment:
    Windows 7 Enterprise client with patches until 1-Nov-2010
    Windows Server 2008 R2 for the Documents$ share
    Windows Server 2003 R2 as the domain controller
    I have tried all different option even to rebuild the CSC database but this also was not helping. I hope we are not dealing with a bug.
    Any help is much appreciated.
    Best regards, Ivan Versluis http://www.networknet.nl

    Ivan and SteveDIG - Thanks for taking the time to post detailed information about what you have found.  I have found the same things over the past few months and have been working with Microsoft to resolve this.  Like Ivan, I have been told by
    MS that this is a design problem in Windows 7, but they did admit it is a bug and did not charge me for the case.  That was the good news.  The bad news was that the problem is so 'deep' in Windows 7 that it will not be fixed until Windows 8 and
    the CSC engineering team in Redmond has rejected several requests to fix this issue in Windows 7 from several customers.  I personally feel we should have hauled our TAM in over this, but that wasn't my call so we haven't attempted to get an attitude
    change from MS.
    <RANT> I find this completely outrageous.  Windows is supposed to be a multi-user operating system suitable for deployment to mobile workforces spread around the world and often using slow VPN links.  Offline folders, folder redirection,
    slow link detection, etc. are all great on paper and as I did the design work for the W7 solution I've just built I sold these advantages heavily.  I now have serious egg on my face and am not happy.  Like others here I missed this in testing as
    multiple users are a fringe for us, but still important, I unfortunately didn't think to specifically test for multiple users, though I tested the features thoroughly and was happy with the results when used on single user machines.</RANT>
    As identified above, this issue manifests when more than one user uses a machine and their Offline folders (all redirected folders are configured this way by default) are in an offline state when the first user logs off.  The second user cannot access
    this 'offline' share so folder redirection fails.  We get burnt as we have latency=0 configured for slow link detection with Offline folders so users always work offline.  This is partly because of WAN optimisers in the network that lie to Windows
    so the online/offline transition doesn't work on slow links (not MS's fault), and partly because it made sense for other reasons.
    The workaround Microsoft and I came up with for our environment was to use individual file shares for each user.  We had been using a common file share with each user folder under that file share.  Changing to an individual share for each users
    means the share is not locked by the previous user.
    Examples
    This would cause a problem if John then Emma logged on to the same machine. Folder redirection would fail for Emma:
    \\FileServer1\Users$\john
    \\FileServer1\Users$\emma
    So would this if DFS was used
    \\my.domain\users\john            (points to \\FileServer1\Users$\John)
    \\my.domain\users\emma          (points to \\FileServer1\Users$\Emma)
    This would fix the problem:
    \\FileServer1\John$
    \\FileServer1\Emma$
    Unfortunately we then figured we could move these shares behind DFS like so:
    \\my.domain\homes\john             (points to \\FileServer1\John$)
    \\my.domain\homes\emma          (points to \\FileServer1\emma$)
    This was wrong.  The problem returned.  I assume the share that is being locked is now the DFS root and not the user share.
    The operations team here is very reluctant to go with direct access to the file servers and not use DFS as that will create issues for them in the future when they need to make file server changes.  I sympathise with them but can't see an alternative
    at the moment as we are deploying W7 and can't stop.  If I'd picked this up earlier a third party product might have been the solution (MS actually suggested this when I opened my case).
    I hope the information about individual shares above is helpful to someone.  Otherwise I don't really have more to add but I needed the rant :-)
    <RANT>BTW.  Has anyone tested changing a user’s home directory path once it is cached?  Try it. Test a scenario where you move the user from one file server to another.  You will not enjoy the results.  I'll say no more
    than this as it is off topic, but it shows the lack of investment in the CSC feature in Windows.  Very disappointing</RANT>

Maybe you are looking for