Exchange 2010 - deleting IIS Advanced log entries

Hi
I am trying to increase the free space on the system drive of our Exchange 2010 servers.  Is it OK to delete the entries in
inetpub - Logs - Advanced Logs?
Thanks
J.

Hello,
You can also use a scheduled script:
https://social.technet.microsoft.com/Forums/systemcenter/en-US/d989b249-0159-41fc-b78c-1f1d91ce8bb3/inetpublogslogfilesw3svc1-getting-very-large?forum=configmgrgeneral
Thanks,
Simon Wu
TechNet Community Support

Similar Messages

  • How do i delete single phone log entries

    The iphone only lets me delete all phone log entries. However, I would like to delete single entries without deleting the entire list.
    Is this possible? If not could you please add this in the next IOS release?
    THX

    In iOS 5, go to your recent calls list and tap edit, then select the call to delete. You can also swipe individual calls to delete.

  • Exchange 2010 DAG backup & Transaction logs

    Hi, 
    What is Microsoft recommended best practise for Exchange DAG group backup in an environment where there are Active & multiple (2-3) passive copies of the databases?
    Is it a good practice to backup transaction logs as frequently as possible in addition to daily full backup ? This I belive will allow to restore the DB to the latest possible state
    using last good full backup & transaction logs (Like restoring SQL databases)
    Thanks

    Hi,
    Windows Server Backup can't backup passive copy. If you want to backup both active and passive copies, you need to use DPM or other third party.
    Here is a similar thread for your reference.
    Exchange 2010 DAG Backup Best Practices
    http://social.technet.microsoft.com/Forums/exchange/en-US/269c195f-f7d7-488c-bb2e-98b98c7e8325/exchange-2010-dag-backup-best-practices
    Besides, here is a related blog below which may help you.
    Backup issues and limitations with Exchange 2010 and DAG
    http://blogs.technet.com/b/ehlro/archive/2010/02/13/backup-issues-and-limitations-with-exchange-2010-and-dag.aspx
    Hope this helps.
    Best regards,
    Belinda
    Belinda Ma
    TechNet Community Support

  • Exchange 2010 Excessive Archive Transaction Logs

    I've got an Exchange 2010 environment with about 225 users over 6 mailbox DB's with corresponding Archive DB's.
    They're seeing log files for the archive DB's growing by about 25-30% of the total DB size daily. Those logs are generally about 8 x the logs generated by the corresponding primary mailbox database.
    Something like
    DB1 = 20GB  daily average logs 2GB
    DB1Archive = 90GB daily average logs ~28GB
    I don't see any Retention policies that have duplicated Tags and the Default policy has no tags assigned.
    The customer wants to continue with their existing backup process of weekly fulls and daily incremental/differentials, and missing two days is enough to max out their transaction log volumes. (which are as large as their combined database size).
    The archive db's have been in place for at least 12 weeks now so it's not just initial population, which is obvious by the fact that the archive db's are much larger than the original db's and the total logs in a week exceed the DB volumes by 2-3 times.

    Hi,
    First, please make sure there is no corruption in the retention policies.
    If there is no corruption, I recommend you create a new archive mailbox database and move archive mailbox to this new database to check result.
    Besides, here is a similar thread for your reference.
    http://social.technet.microsoft.com/Forums/en-US/77845ba9-96c4-4b94-8d55-b47c51ef8974/exchange-2010-archive-transaction-logs?forum=exchange2010
    Hope this is helpful to you.
    Best regards,
    Belinda Ma
    TechNet Community Support

  • Apple Mail 6.2 Exchange 2010 Delete Fail

    When deleteting an email in Apple Mail 6.2 setup to use Exchange 2010 with MAPI, the following error message is displayed:
    The message "X" could not be moved to the mailbox "Trash folder name".
    An error occurred while moving messages to mailbox "Trash folder name".
    To reproduce this problem I loaded a mailbox with 30k of emails. I then deleted 4000 messages, and while the client was still syncing (visibly you could see it syncing the activity window) - I deleted some of the same messages again.
    The sync process stopped, the activity window stopped showing any activity and my emails which were previously marked for deletion remained visible.
    Now when I try to delete the emails I previously deleted, I receive the error as above and the messages are not deleted.
    If I delete other messages that were not previously marked for deletion I do not receive the error.
    To remove the messages that were causing the error I had to "Command-X" to cut them from the folder and bypass the trash.

    Hi Andrew,
    I tried to understand your message but failed to. I'm sorry. Just clicking "rebuild" worked for me to restore behavior that hadn't been working. It only took a few seconds.
    That said, it was only days later that all of my correspondance stored on the Exchange server disappeared, and 123Together, my Exchange service provider, said "Since you are on a Mac the database may gotten corrupted and synched to the server that is why the data in the mailbox and subfolder you may not see. We can have our admin do a restore of the mailbox as we can go back for a restore point up to 5 days, there is a admin fee of 160.00 hr anywhere from 1-3 hours of work please let us know if you would like to proceed." I was not happy.
    So I probably agree with what you are saying!
    Larry

  • Exchange 2010 - Load balancing transaction logs in a DAG

    I have a single Exchange 2010 DAG.  Within the DAG, I have two mailbox servers.  I have 2 DB's mounted on server A, and 3 DB's mounted on server B.
    The size and quantity of transaction logs on server A always seem to be larger.  It might be the nature of the mailboxes on server A, but I was wondering if there is a tool or script to verify best practices for how the transaction logs should be configured.
    Thanks
    Ron

    I have a single Exchange 2010 DAG.  Within the DAG, I have two mailbox servers.  I have 2 DB's mounted on server A, and 3 DB's mounted on server B.
    The size and quantity of transaction logs on server A always seem to be larger.  It might be the nature of the mailboxes on server A, but I was wondering if there is a tool or script to verify best practices for how the transaction logs should be configured.
    Thanks
    Ron
    So one of the DBs is not replicated? Im not sure what you mean by "how the transaction logs should be configured".
    You only real choices are disk location, whether you want to lag a copy or if you want to enable circular logging. Things that with 2 mailbox servers you wouldn't want do other than define the disk location. Otherwise, there isn't much to configure as far
    as the logging.
    Twitter!: Please Note: My Posts are provided “AS IS” without warranty of any kind, either expressed or implied.

  • Exchange 2010 Mail Submission Service Logging

    Hi,
    Is there a way to log all submitted messages from outlook clients (online mode) so I can see what is happening to messages that are getting stuck in the Outbox from the server's perspective?
    Thank you.

    If you look at the logging section in this post
    http://blogs.technet.com/b/rmilne/archive/2013/11/20/exchange-2010-tweaks.aspx
    add key="LoggingTag" value="ConnectDisconnect, Logon, Failures, ApplicationData, Warnings, Throttling" />.
    You can also add ROP logging, which are the individual Outlook commands sent, by adding the tag to the above line.
    This gets *VERY* busy.  *VERY* quickly, so maybe try this out on a test box first to see what that gives you.
    Cheers,
    Rhoderick
    Microsoft Senior Exchange PFE
    Blog:
    http://blogs.technet.com/rmilne 
    Twitter:   LinkedIn:
      Facebook:
      XING:
    Note: Posts are provided “AS IS” without warranty of any kind, either expressed or implied, including but not limited to the implied warranties of merchantability and/or fitness for a particular purpose.

  • Since applying Feb 2013 Sharepoint 2010 CUs - Critical event log entries for Blob cache and missing images

    Hi,
    Since applying the February 2013 SharePoint 2010 updates, we are getting lots of entries in our event logs along the following:
    Content Management     Publishing Cache         
    5538     Critical 
    An error occurred in the blob cache.  The exception message was 'The system cannot find the file specified. (Exception from HRESULT: 0x80070002)’
    In pretty much all of these cases the image/ file in question that is reported in the ULS logs as missing is not actually in the collaboration site, master page / html etc so the fix needs to go back to the site owner to make the correction to avoid
    the 404 (if they make it!). This has only started happening, I believe since feb 2013 sp2010 cumulative updates updates
    I didn’t see this mentioned as a change / in the Fix list of the February updates. i.e. it flags up a critical error in our event logs. So with a lot of sites and a lot of missing images your event log can quickly fill up.
    Obviously you can suppress them in the monitoring -> web content management ->publishing cache = none & none which is not ideal.
    So my question is... are others seeing this and was a change made by Microsoft to flag a 404 missing image / file up a critical error in event log when blob cache is enabled?
    If i log this with MS they will just say, you need to fix it up the missing files in the site but would be nice to know this had changed prior! I also deleted and recreated the blob cache and this made no diffference
    thanks
    Brad

    I'm facing the same error on our SharePoint 2013 farm. We are on Aug 2013 CU and if the Dec CU (which is supposed to be the latest) doesn't solve it then what else could be done.
    Some users started getting the message "Server is busy now try again later" with a corelation id. I looked up ULS with that corelation id and found these two errors in addition to hundreds of "Micro Trace Tags (none)" and "forced
    due to logging gap":
    "GetFileFromUrl: FileNotFoundException when attempting get file Url /favicon.ico The system cannot find the file specified. (Exception from HRESULT: 0x80070002)"
    "Error in blob cache. System.IO.FileNotFoundException: The system cannot find the file specified. (Exception from HRESULT: 0x80070002)"
    "Unable to cache URL /FAVICON.ICO.  File was not found" 
    Looks like this is a bug and MS hasn't fixed it in Dec CU..
    "The opinions expressed here represent my own and not those of anybody else"

  • Exchange 2010 / Outlook 2010 "client error in synchronization log"

    Exchange
    2010:
    Error
    in Synchronization Log
    19:28:32 Error synchronizing
    folder
    19:28:32                               [8004010F-501-8004010F-0]
    19:28:32                               The
    client operation failed.
    19:28:32                               Microsoft
    Exchange Information Store
    19:28:32                               For
    more information on this failure, click the URL below:
    19:28:32                               http://www.microsoft.com/support/prodredirect/outlook2000_us.asp?err=8004010f-501-8004010f-0
    Please
    assist with this error. Is it serious? The URL provided does not offer nor reflect any worthwhile information. Thanks.

    The error means that the client hasn’t located the resource it’s looking for
    Does the error appear on all outlook clients?
    Do you use organizational forms library? (KB
    933358)
    The error can be caused by incorrect permission on the “EFORMS REGISTRY”, so please run the cmdlet below to check the permission on
    the Default group, the permission should be “Reviewer”
    Get-PublicFolderClientPermission “\NON_IPM_SUBTREE\EFORMS REGISTRY”
    Per my research, you can avoid this error by removing all the subfolders in the “EFORMS REGISTRY” folder, if you don’t use organizational
    forms library. But, please use the Get-PublicFolderStatistics cmdlet to verify that no items under the “EFORMS REGISTRY” folder before. And, if the error still appears, please remove the OST file and then recreate the mail profile
    Please run ExBPA against the exchange servers for health/permission check
    Notes: If forms library replicas are added to Exchange 2010 servers, 80004005-501-4B9-560
    will appear in the sync message, yet it can be safely ignored
    Resources:
    “The Organizational Forms Library has been deleted and re-created after the .ost file has synchronized the library” section
    in You receive an error message when you try to synchronize your offline folder file if the Organizational Forms Library on your Exchange computer has
    been re-created or cannot be located
    James Luo
    TechNet Subscriber Support (http://technet.microsoft.com/en-us/subscriptions/ms788697.aspx)
    If you have any feedback on our support, please contact [email protected]

  • Public folders not replicating Exchange 2010

    Earlier this year I did a migration from a single 2003 Exchange server to a single Exchange 2010 server. I didn't notice until recently that my GAL isn't being updated in cached mode in Outlook 2010+ but is in OWA and with cached mode turned off. So,
    I dug a little more, and also noticed that I also having errors when trying to go into Public Folder Management Console when I right click and and select update content on anything under Default Public Folders or System Public Folders I get an error about
    no replica being found.
    Microsoft Exchange Error
    Action 'Update Content' could not be performed on object 'OFFLINE ADDRESS BOOK'.
    OFFLINE ADDRESS BOOK
    Failed
    Error:
    Server 'JASMAIL01' doesn't have a replica of public folder '\NON_IPM_SUBTREE\OFFLINE ADDRESS BOOK'. Public folder content can be synchronized only from a server that has a replica of that public folder.
    When I update anything inside the Offline Address Book Folder I get:
    Microsoft Exchange Error
    Action 'Update Content' could not be performed on object 'EX:/o=AmicalolaEMC/ou=Exchange Administrative Group (FYDIBOHF23SPDLT)'.
    EX:/o=AmicalolaEMC/ou=Exchange Administrative Group (FYDIBOHF23SPDLT)
    Failed
    Error:
    Cannot start content replication against public folder '\NON_IPM_SUBTREE\OFFLINE ADDRESS BOOK\EX:/o=AmicalolaEMC/ou=Exchange Administrative Group (FYDIBOHF23SPDLT)' on public folder database 'Public Folder Database 1904981871'.
    MapiExceptionNoReplicaAvailable: StartContentReplication failed. (hr=0x80004005, ec=1129)
    Diagnostic context:
        Lid: 1494    ---- Remote Context Beg ----
        Lid: 3010    StoreEc: 0x8004010F
        Lid: 3010    StoreEc: 0x8004010F
        Lid: 3650    StoreEc: 0x8004010F
        Lid: 18128   StoreEc: 0x469     
        Lid: 18536   StoreEc: 0x469     
        Lid: 18544   StoreEc: 0x469     
        Lid: 18560   StoreEc: 0x469     
        Lid: 18740   StoreEc: 0x469     
        Lid: 1267    StoreEc: 0x469     
        Lid: 33819   StoreEc: 0x469     
        Lid: 27225   StoreEc: 0x469     
        Lid: 1750    ---- Remote Context End ----
        Lid: 26322   StoreEc: 0x469     
    OK
    I've been searching for a month or so and have come up with nothing, any ideas? Thank you!

    This is what happens when I try to run that command:
    Identity: Default Global Address List
    WARNING: The recipient "amicalolaemc.com/Microsoft Exchange System Objects/OAB Version 2" is invalid and couldn't be
    updated.
    WARNING: The recipient "amicalolaemc.com/Microsoft Exchange System Objects/OAB Version 3a" is invalid and couldn't b
    updated.
    WARNING: The recipient "***.com/Microsoft Exchange System Objects/OAB Version 4" is invalid and couldn't be
    updated.
    WARNING: The recipient "***.com/Microsoft Exchange System Objects/Schedule+ Free Busy Information - First
    Administrative Group" is invalid and couldn't be updated.
    WARNING: The recipient "***.com/Users/SystemMailbox{1f05a927-2cd9-4dbe-8f19-98848d21a898}" is invalid and
    couldn't be updated.
    WARNING: The recipient "***.com/Users/SystemMailbox{e0dc1c29-89c3-4034-b678-e6c29d823ed9}" is invalid and
    couldn't be updated.
    WARNING: The recipient "***.com/Users/FederatedEmail.4c1f4d8b-8179-4148-93bf-00a95fa1e042" is invalid and
    couldn't be updated.
    Hi,
    The error message also mentions that your system mailboxes are invalid. Please run the Get-Mailbox -Arbitration command to check result.
    Besides, please find the following objects under the Microsoft Exchange System Objects container and delete them to check result.
    OAB Version 2
    OAB Version 3a
    OAB Version 4
    Schedule+ Free Busy Information - First Administrative Group
    Here is a related thread for your reference.
    https://social.technet.microsoft.com/Forums/exchange/en-US/92264b4d-56d5-4354-b3aa-828f18e0068f/exchange-2010-orphaned-public-folder-gal-entries
    Hope this is helpful to you.
    Best regards,
    Belinda Ma
    TechNet Community Support

  • Exchange 2010 SP3 Installation Failed

    I have Exchange 2010 SP2 RU8. We tried to install SP3 but continue to get a failure.
    The upgrade cannot be installed by the Windows Installer service because the program to be upgraded may be missing, or the upgrade may update a different version of the program. Verify that the program to be upgraded exists on your computer and that you
    have the correct upgrade.
    Error code: 1642
    Here is the MSI log:
    === Verbose logging started: 5/30/2014  17:44:11  Build type: SHIP UNICODE 5.00.7601.00  Calling process: C:\Windows\System32\msiexec.exe ===
    MSI (c) (F4:C8) [17:44:11:684]: Font created.  Charset: Req=0, Ret=0, Font: Req=MS Shell Dlg, Ret=MS Shell Dlg
    MSI (c) (F4:C8) [17:44:11:684]: Font created.  Charset: Req=0, Ret=0, Font: Req=MS Shell Dlg, Ret=MS Shell Dlg
    MSI (c) (F4:CC) [17:44:11:699]: Resetting cached policy values
    MSI (c) (F4:CC) [17:44:11:699]: Machine policy value 'Debug' is 0
    MSI (c) (F4:CC) [17:44:11:699]: ******* RunEngine:
               ******* Product: {4934D1EA-BE46-48B1-8847-F1AF20E892C1}
               ******* Action: 
               ******* CommandLine: **********
    MSI (c) (F4:CC) [17:44:11:699]: Machine policy value 'DisableUserInstalls' is 0
    MSI (c) (F4:CC) [17:44:11:699]: Cloaking enabled.
    MSI (c) (F4:CC) [17:44:11:699]: Attempting to enable all disabled privileges before calling Install on Server
    MSI (c) (F4:CC) [17:44:11:699]: End dialog not enabled
    MSI (c) (F4:CC) [17:44:11:699]: Original package ==> C:\Windows\Installer\48e783.msi
    MSI (c) (F4:CC) [17:44:11:699]: Package we're running from ==> C:\Windows\Installer\48e783.msi
    MSI (c) (F4:CC) [17:44:11:715]: APPCOMPAT: Uninstall Flags override found.
    MSI (c) (F4:CC) [17:44:11:715]: APPCOMPAT: Uninstall VersionNT override found.
    MSI (c) (F4:CC) [17:44:11:715]: APPCOMPAT: Uninstall ServicePackLevel override found.
    MSI (c) (F4:CC) [17:44:11:715]: APPCOMPAT: looking for appcompat database entry with ProductCode '{4934D1EA-BE46-48B1-8847-F1AF20E892C1}'.
    MSI (c) (F4:CC) [17:44:11:715]: APPCOMPAT: no matching ProductCode found in database.
    MSI (c) (F4:CC) [17:44:11:715]: MSCOREE not loaded loading copy from system32
    MSI (c) (F4:CC) [17:44:11:731]: Opening existing patch 'C:\Windows\Installer\f63d4979.msp'.
    MSI (c) (F4:CC) [17:44:11:731]: Opening existing patch 'C:\Windows\Installer\596a3.msp'.
    MSI (c) (F4:CC) [17:44:11:731]: Original patch ==> C:\Temp\ExchSP3_RU6.msp
    MSI (c) (F4:CC) [17:44:11:731]: Patch we're running from ==> C:\Temp\ExchSP3_RU6.msp
    MSI (c) (F4:CC) [17:44:11:731]: SOFTWARE RESTRICTION POLICY: Verifying patch --> 'C:\Temp\ExchSP3_RU6.msp' against software restriction policy
    MSI (c) (F4:CC) [17:44:11:731]: SOFTWARE RESTRICTION POLICY: C:\Temp\ExchSP3_RU6.msp has a digital signature
    MSI (c) (F4:CC) [17:44:11:996]: SOFTWARE RESTRICTION POLICY: C:\Temp\ExchSP3_RU6.msp is permitted to run at the 'unrestricted' authorization level.
    MSI (c) (F4:CC) [17:44:11:996]: SequencePatches starts. Product code: {4934D1EA-BE46-48B1-8847-F1AF20E892C1}, Product version: 14.2.247.5, Upgrade code: {A4A259AB-A77F-4039-832A-27B431DDFFEA}, Product language 1033
    MSI (c) (F4:CC) [17:44:11:996]: Full optimizations are not possible in the patch sequencer because new patch[es] had been added in the current transaction.
    MSI (c) (F4:CC) [17:44:11:996]: The patch sequencer will optimize its execution by not checking the applicability of applied patches.
    MSI (c) (F4:CC) [17:44:11:996]: PATCH SEQUENCER: verifying the applicability of QFE patch C:\Temp\ExchSP3_RU6.msp against product code: {4934D1EA-BE46-48B1-8847-F1AF20E892C1}, product version: 14.2.247.5, product language 1033 and upgrade code: {A4A259AB-A77F-4039-832A-27B431DDFFEA}
    MSI (c) (F4:CC) [17:44:11:996]: Validating transform 'E14_DAT_RTMToE14_DAT_UPG' with validation bits 0x922
    MSI (c) (F4:CC) [17:44:11:996]: Note: 1: 2749 2: E14_DAT_RTMToE14_DAT_UPG 3: C:\Temp\ExchSP3_RU6.msp 4: 14.3.123.4 5: 14.2.247.5 
    MSI (c) (F4:CC) [17:44:11:996]: 1: 2749 2: E14_DAT_RTMToE14_DAT_UPG 3: C:\Temp\ExchSP3_RU6.msp 4: 14.3.123.4 5: 14.2.247.5 
    MSI (c) (F4:CC) [17:44:11:996]: PATCH SEQUENCER: QFE patch C:\Temp\ExchSP3_RU6.msp is not applicable.
    MSI (c) (F4:CC) [17:44:11:996]: The original #_QFESequence table:
    MSI (c) (F4:CC) [17:44:11:996]: PatchGUID: {2D4DEC16-9DFE-4A3F-89C7-8D19F374B426}
    ResultantVersion: 14.2.247.5 PatchFamily: E14_DAT
    Sequence: 14.2.375.0 Type: QFE
    MSI (c) (F4:CC) [17:44:11:996]: PatchGUID: {1B1DA2D5-6EFD-4EF7-B225-EAFBF51ABCBE}
    ResultantVersion: 14.2.247.5 PatchFamily: E14_DAT
    Sequence: 14.2.298.4 Type: QFE
    MSI (c) (F4:CC) [17:44:11:996]: The pre-sorted #_QFESequence table: - this is useful to see if patches had been ordered correctly within resultant versions and patch families
    MSI (c) (F4:CC) [17:44:11:996]: PatchGUID: {1B1DA2D5-6EFD-4EF7-B225-EAFBF51ABCBE}
    ResultantVersion: 14.2.247.5 PatchFamily: E14_DAT
    Sequence: 14.2.298.4 VersionOrder: 0
    SequenceOrder: 0 Type: QFE
    MSI (c) (F4:CC) [17:44:11:996]: PatchGUID: {2D4DEC16-9DFE-4A3F-89C7-8D19F374B426}
    ResultantVersion: 14.2.247.5 PatchFamily: E14_DAT
    Sequence: 14.2.375.0 VersionOrder: 0
    SequenceOrder: 1 Type: QFE
    MSI (c) (F4:CC) [17:44:11:996]: PATCH SEQUENCER: The initial #_Predecessor table:
    MSI (c) (F4:CC) [17:44:11:996]: PatchFamily: E14_DAT,
    PatchGUID: {1B1DA2D5-6EFD-4EF7-B225-EAFBF51ABCBE},
    Predecessor GUID: NULL
    MSI (c) (F4:CC) [17:44:11:996]: PatchFamily: E14_DAT,
    PatchGUID: {2D4DEC16-9DFE-4A3F-89C7-8D19F374B426},
    Predecessor GUID: {1B1DA2D5-6EFD-4EF7-B225-EAFBF51ABCBE}
    MSI (c) (F4:CC) [17:44:11:996]: PATCH SEQUENCER: Step 1
    MSI (c) (F4:CC) [17:44:11:996]: PATCH SEQUENCER: patch {1B1DA2D5-6EFD-4EF7-B225-EAFBF51ABCBE} (PatchFamily E14_DAT) will be sequenced.
    MSI (c) (F4:CC) [17:44:11:996]: PATCH SEQUENCER: Step 2
    MSI (c) (F4:CC) [17:44:11:996]: PATCH SEQUENCER: patch {2D4DEC16-9DFE-4A3F-89C7-8D19F374B426} (PatchFamily E14_DAT) will be sequenced.
    MSI (c) (F4:CC) [17:44:11:996]: PATCH SEQUENCER: The resulting #_OrderedGUIDs table:
    MSI (c) (F4:CC) [17:44:11:996]: Patch: {1B1DA2D5-6EFD-4EF7-B225-EAFBF51ABCBE}
    Order: 0 (Family: E14_DAT)
    MSI (c) (F4:CC) [17:44:11:996]: Patch: {2D4DEC16-9DFE-4A3F-89C7-8D19F374B426}
    Order: 1 (Family: E14_DAT)
    MSI (c) (F4:CC) [17:44:11:996]: The ordered #_QFESequence table: - has the final sequence of QFEs.  It lists each PatchGUID only once.
    MSI (c) (F4:CC) [17:44:11:996]: PatchGUID: {1B1DA2D5-6EFD-4EF7-B225-EAFBF51ABCBE}
    ResultantVersion: 14.2.247.5 PatchFamily: E14_DAT
    Sequence: 14.2.298.4 Order: 0
    MSI (c) (F4:CC) [17:44:11:996]: PatchGUID: {2D4DEC16-9DFE-4A3F-89C7-8D19F374B426}
    ResultantVersion: 14.2.247.5 PatchFamily: E14_DAT
    Sequence: 14.2.375.0 Order: 1
    MSI (c) (F4:CC) [17:44:11:996]: PATCH SEQUENCER: there's no supersedence information available, so no patches will be superseded.
    MSI (c) (F4:CC) [17:44:11:996]: SequencePatches returns success.
    MSI (c) (F4:CC) [17:44:11:996]: Final Patch Application Order:
    MSI (c) (F4:CC) [17:44:11:996]: {1B1DA2D5-6EFD-4EF7-B225-EAFBF51ABCBE} - 
    MSI (c) (F4:CC) [17:44:11:996]: {2D4DEC16-9DFE-4A3F-89C7-8D19F374B426} - 
    MSI (c) (F4:CC) [17:44:11:996]: Other Patches:
    MSI (c) (F4:CC) [17:44:11:996]: Unknown\Absent: {32539431-026C-467E-98AD-9932CAC4B304} - C:\Temp\ExchSP3_RU6.msp
    The upgrade cannot be installed by the Windows Installer service because the program to be upgraded may be missing, or the upgrade may update a different version of the program. Verify that the program to be upgraded exists on your computer and that you have
    the correct upgrade.
    C:\Windows\Installer\48e783.msi
    MSI (c) (F4:CC) [17:44:11:996]: Product: Microsoft Exchange Server - Update '{32539431-026C-467E-98AD-9932CAC4B304}' could not be installed. Error code 1642. Additional information is available in the log file C:\Users\dgates\AppData\Local\Temp\2\MSI4736a.LOG.
    MSI (c) (F4:CC) [17:44:11:996]: Windows Installer installed an update. Product Name: Microsoft Exchange Server. Product Version: 14.2.247.5. Product Language: 1033. Manufacturer: Microsoft Corporation. Update Name: {32539431-026C-467E-98AD-9932CAC4B304}. Installation
    success or error status: 1642.
    MSI (c) (F4:CC) [17:44:11:996]: Note: 1: 1708 
    MSI (c) (F4:CC) [17:44:11:996]: Product: Microsoft Exchange Server -- Installation failed.
    MSI (c) (F4:CC) [17:44:11:996]: Windows Installer installed the product. Product Name: Microsoft Exchange Server. Product Version: 14.2.247.5. Product Language: 1033. Manufacturer: Microsoft Corporation. Installation success or error status: 1642.
    MSI (c) (F4:CC) [17:44:12:011]: MainEngineThread is returning 1642
    === Verbose logging stopped: 5/30/2014  17:44:12 ===
    HossFly, Exchange Administrator

    As per the below log entries it seems that it is trying to install SP3 UR6 directly and failing saying its not applicable. If you are trying to install just SP3 then it shouldn't try installing UR6 at the same time so that seems strange to me...
    MSI (c) (F4:CC) [17:44:11:731]: SOFTWARE RESTRICTION POLICY: C:\Temp\ExchSP3_RU6.msp has a digital signature
    MSI (c) (F4:CC) [17:44:11:996]: SOFTWARE RESTRICTION POLICY: C:\Temp\ExchSP3_RU6.msp is permitted to run at the 'unrestricted' authorization level.
    MSI (c) (F4:CC) [17:44:11:996]: PATCH SEQUENCER: verifying the applicability of QFE patch C:\Temp\ExchSP3_RU6.msp against product code: {4934D1EA-BE46-48B1-8847-F1AF20E892C1}, product version: 14.2.247.5, product language 1033 and upgrade code: {A4A259AB-A77F-4039-832A-27B431DDFFEA}
    MSI (c) (F4:CC) [17:44:11:996]: Note: 1: 2749 2: E14_DAT_RTMToE14_DAT_UPG 3: C:\Temp\ExchSP3_RU6.msp 4: 14.3.123.4 5: 14.2.247.5 
    MSI (c) (F4:CC) [17:44:11:996]: 1: 2749 2: E14_DAT_RTMToE14_DAT_UPG 3: C:\Temp\ExchSP3_RU6.msp 4: 14.3.123.4 5: 14.2.247.5 
    MSI (c) (F4:CC) [17:44:11:996]: PATCH SEQUENCER: QFE patch C:\Temp\ExchSP3_RU6.msp is not applicable.
    Looks like time to re-download
    SP3 and give it a try.
    Blog |
    Get Your Exchange Powershell Tip of the Day from here

  • Delete Administrator Audit Logging

    How can the system administrator control the Administrator Audit Logging of the Exchange Server.. What I want to do is to check the audit logging ( for some users who get access for an email) and delete some specific operations ( Like search and granting
    access) .. also how can I delete the log directly? 

    Hi,
    Based on my research, to delete the audit log entries which are over 7 days, we can set the AdminAuditLogAgeLimit parameter. Thus, let’s firstly try to double check the property by the following command:
    Get-AdminAuditLogConfig | FL  AdminAuditLogAgeLimit
    If  the value is 02.00:00:00, let’s check if there is any error in the event log to narrow down the cause.
    If you have any question, please feel free to let me know.
    Thanks,
    Angela Shi
    TechNet Community Support

  • CMD=Ping&log query is taking long time-taken when checked in IIS logs.... Exchange 2010 SP3..

    Query regarding the ActiveSync and parameter time-taken from ActiveSync IIS logs.
    Here what I see for from the logs.
    [email protected] 45.101.90.185 Apple-iPad2C3/1202.410 200 0 0 1501129
    443 [email protected] 45.101.90.185 Apple-iPad2C3/1202.410 200
    0 0 22105
    443 [email protected] 45.101.90.185 Apple-iPad2C3/1202.410 200
    0 0 452
    443 [email protected] 45.101.90.185 Apple-iPad2C3/1202.410 200
    0 0 936
    443 [email protected] 45.101.90.185 Apple-iPad2C3/1202.410 200
    0 0 656238 
    In the above log, highlighted are the time-taken and I just want to check what is the ideal time-taken value, some value above should be causing some problem, like the one of the top 1501129 ?
    ?AND I see its for POST event and CMD=Ping&log query.......
    We have Mobile Iron in the environment and we are seeing few timeout errors on MobileIron server and for users intermittently. They usually see below error... However we don't see any end users issues, but just want to get rid of below error. MobileIron guys
    are pointing it to time-taken value which is high intermittently.
    IOException connection to server [email protected] -- java.io.IOException:
    awaitUninterruptibly was stopped by timeout
    @BALA

    Hi,
    To understand more about the issue, I’d like to confirm the following information:
    1. What’s your Exchange 2010 version? 
    http://support.microsoft.com/kb/2536517/en-us
    2. Do you install other software, like SQL, on the same Exchange Server?
    3. Change another admin account to access EMS.
    Thanks,
    Angela Shi
    TechNet Community Support

  • Event IDs 136 and 137 0x80000000000000 in System Log on Windows 2008 R2 Server, Exchange 2010 in Cluster

    Hi,
    I'm having an issue with one of my exchange 2010 Servers. We had a power outage and upon recovery, I cannot start Services Net.Pipe Listener Adapter and Net.Tcp Listener Adapter (And thus cannot Start IIS and provide Exchange Client Services.) This is a
    physical server (Not VMWare or Hyper-V)
    The System event log has lots of Event 136's and 137s on Ntfs with the keyword - 0x80000000000000 - The General Messages are: The default transaction resource manager on volume C: encountered an error while starting and its metadata was
    reset.  The data contains the error code.
    and
    The default transaction resource manager on volume OS encountered a non-retryable error and could not start.  The data contains the error code.
    XML Output as follows:
    - <Event xmlns="http://schemas.microsoft.com/win/2004/08/events/event">
    - <System>
      <Provider Name="Ntfs" />
      <EventID Qualifiers="32772">136</EventID>
      <Level>3</Level>
      <Task>2</Task>
      <Keywords>0x80000000000000</Keywords>
      <TimeCreated
    SystemTime="2014-11-17T18:10:37.788942300Z" />
      <EventRecordID>315532</EventRecordID>
      <Channel>System</Channel>
      <Computer>server.domain.com</Computer>
      <Security />
      </System>
    - <EventData>
      <Data />
      <Data>C:</Data>
      <Binary>1C00040002003000020000008800048000000000060019C000000000000000000000000000000000060019C0</Binary>
      </EventData>
     </Event>
    - <Event xmlns="http://schemas.microsoft.com/win/2004/08/events/event">
    - <System>
      <Provider Name="Ntfs" />
      <EventID Qualifiers="49156">137</EventID>
      <Level>2</Level>
      <Task>2</Task>
      <Keywords>0x80000000000000</Keywords>
      <TimeCreated
    SystemTime="2014-11-17T18:10:37.788942300Z" />
      <EventRecordID>315531</EventRecordID>
      <Channel>System</Channel>
      <Computer>server.domain.com</Computer>
      <Security />
      </System>
    - <EventData>
      <Data />
      <Data>OS</Data>
      <Binary>1C0004000200300002000000890004C000000000020100C000000000000000000000000000000000020100C0</Binary>
      </EventData>
      </Event>
    When I attempt to start the services - I get the following errors:
    The Net.Pipe Listener Adapter service depends on the Windows Process Activation Service service which failed to start because of the following error: 
    Transaction support within the specified resource manager is not started or was shut down due to an error.
    The Net.Pipe Listener Adapter service depends on the Windows Process Activation Service service which failed to start because of the following error: 
    Transaction support within the specified resource manager is not started or was shut down due to an error.
    I have tried the "fsutil resource setautoreset true" fix without success.
    Any ideas or direction would be much appreciated. Restoring this server will be extremely difficult.
    Thanks!

    We can close this question.
    From an elevated prompt, I ran 'fsutil resource setautoreset true' and attempted to remove the files with .blf and regtrans-ms file extensions from C:\Windows\System32\config\TxR. but these files were locked by system processes. (They are also
    tagged with the hidden file attrib so you may not see them at first)
    So, I booted the system with a Windows 2008 R2 Install Disk, selected repair OS and selected the command prompt. I then performed a chkdsk /f c: and selected "Y" to unmount the drive. It made some repairs.
    With the system booted from the install disk, and chkdsk executed, the locks were freed and I was able to delete the files from C:\Windows\System32\config\TxR.
    Once the system rebooted, the services came back fine and everything was back to normal.

  • Exchange 2010 SP3 - "500 5.3.3 Unrecognized command" in SMTP Receive Log. Senders get message with the same problem

    Hi
    My exchange environment consist with "Server Exchange 2010 SP3" and "Edge Server with Exchange 2010 SP3".
    On Edge server in SMTP receive log i get every now and then an entry: xxxxxx 500 5.3.3 Unrecognized command.
    It is serius problem because I got few e-mails from senders that they had problem with sending e-mail messages to our e-mail domain. They receive e-mail report, for example
    Technical details of permanent failure:
    Google tried to deliver your message, but it was rejected by the server for the recipient domain domena.plby
    mail.domena.pl.
    [95.xxx.xxx.xx].
    The error that the other server returned was:
    500 5.3.3 Unrecognized command
    Could you help me to solve this problem? What could cause this problem?
    Thank you in advance
    Tomasz
    Kind Regards Tomasz

    I have the same issue, but there is plenty of hard disk storage on the Exchange Server. This seems to only be happening from Google Business account/ Postini. If I send message from my personal Gmail account it works fine, but an agency who is on Google
    business seems to have issues sending to us and they are delayed, sometimes they get through and other times they just don't. 
    Results from Mail Acceptance Test:
    I enter my internal address and the remote users postini account as the test setup I received two emails from the tool but the end results of the test are:
     Error submitting mail
            Mail submission failed: Error message: Syntax error, command unrecognized. The server response was: 5.3.3 Unrecognized command.
    Google support stated this:
    Here are the logs from Postini trying to connect to mydomain.com (IP x.x.x.x) :
    1. 2014/08/09 03:26:28 IP:209.85.218.50 SMTP-STLS:OK <null> TLSv1:RC4-SHA Validate:None 2. 2014/08/09 03:26:28 IP:209.85.218.50 SMTP LOG: Sender => FFD:MAIL FROM:<[email protected]>
    3. 2014/08/09 03:26:28 IP:209.85.218.50 Fdal:Customer has null root_iid outbound default at org 100000001 4, 2014/08/09 03:26:28 IP:209.85.218.50 SMTP LOG: Sender <= FFD:250 Ok 5. 2014/08/09 03:26:28 IP:209.85.218.50 SMTP LOG: Sender => FFD:RCPT TO:[email protected]>
    6. 2014/08/09 03:26:34 IP:209.85.218.50 To:[email protected] SMTP LOG: FFD => mydomain.com (x.x.x.x):Connection established 7. 2014/08/09 03:26:34 IP:209.85.218.50 To:[email protected] SMTP LOG: FFD <= mydomain.com (x.x.x.x):220 server.mydomain.com
    ESMTP Service ready 8. 2014/08/09 03:26:34 IP:209.85.218.50 To:[email protected] SMTP LOG: Sender <= FFD:250 Ok 9. 2014/08/09 03:26:35 IP:209.85.218.50 To:[email protected] SMTP LOG: Sender => FFD:968 last bytes of data with dot 10. 2014/08/09 03:28:05
    IP:209.85.218.50 To:[email protected] From:[email protected]:1119780 FP:2603ec6d38c69886eb1000e516fb745a0384e50b SMTP:Delivery still in progress after 90 seconds, recording FP 11. 2014/08/09 03:31:17 IP:209.85.218.50 To:[email protected] SMTP
    LOG: FFD => mydomain.com (x.x.x.x):failed to send the last period(.) 12. 2014/08/09 03:31:17 IP:209.85.218.50 To:[email protected] oremote:Skipping Archive for Sender because did not deliver message 13. 2014/08/09 03:31:17 IP:209.85.218.50 To:[email protected]
    SMTP:451 Remote connection lost - psmtp 14. 2014/08/09 03:31:17 IP:209.85.218.50 To:[email protected] SMTP LOG: Sender <= FFD:451 Remote connection lost - psmtp
    As you can see, on line 9, at 03:26:35, we declared to the receiving server what we were about to send. At the line number 10, almost two minutes passed without an authorization (250 OK) from the receiving server. You can see our status being pushed back
    at that moment to the receiving mail server: SMTP:Delivery still in progress after 90 seconds. Two more minutes later the connection was simply dropped and so we generated a 400 error message to encourage the sending server to try again later (since no bounce
    was given per say from the receiving server, we won't hard-bounce it but defer it).
    I hope this will help. you can try to look in the mydomain.com  inbound logs and see at that exact time what happened? Unfortunately, our visibility pretty much ends there as we don't have full visibility of your mail environment. You'll need to investigate
    within your own environment unfortunately. If you have any more information to share with me, in case it might help me help you, feel free to do so. I'll leave this case opened for now.
    Sincerely,
    Patricia
    Google Enterprise Support

Maybe you are looking for