Exchange 2013 DCOM Event ID 10028

I am running two virtual Exchange 2013 Std servers (CAS and MBX on both) on Server 2012 Std in two different sites (no DAG...yet). When connecting from EX01 through ECP or EMS and I try to retrieve configuration for something from the other server (EX02)
it will take up to 5 minutes before I get the information and the System Event viewer will have the following:
Log Name:      System
Source:        Microsoft-Windows-DistributedCOM
Date:          8/21/2013 9:08:47 AM
Event ID:      10028
Task Category: None
Level:         Error
Keywords:      Classic
User:          SYSTEM
Computer:      EX02.domain.com
Description:
DCOM was unable to communicate with the computer EX02.domain.com using any of the configured protocols; requested by PID     26ec (c:\windows\system32\inetsrv\w3wp.exe).
Event Xml:
<Event xmlns="http :// schemas.microsoft.com/win/2004/08/events/event">
  <System>
    <Provider Name="Microsoft-Windows-DistributedCOM" Guid="{1B562E86-B7AA-4131-BADC-B6F3A001407E}" EventSourceName="DCOM" />
    <EventID Qualifiers="0">10028</EventID>
    <Version>0</Version>
    <Level>2</Level>
    <Task>0</Task>
    <Opcode>0</Opcode>
    <Keywords>0x8080000000000000</Keywords>
    <TimeCreated SystemTime="2013-08-21T14:08:47.915595500Z" />
    <EventRecordID>15029</EventRecordID>
    <Correlation />
    <Execution ProcessID="744" ThreadID="19976" />
    <Channel>System</Channel>
    <Computer>EX02.domain.com</Computer>
    <Security UserID="S-1-5-18" />
  </System>
  <EventData>
    <Data Name="param1">EX02.domain.com</Data>
    <Data Name="param2">    26ec</Data>
    <Data Name="param3">c:\windows\system32\inetsrv\w3wp.exe</Data>
    <Binary>3C5265636F726423313A20436F6D70757465723D286E756C6C293B5069643D3734343B382F32312F323031332031343A383A34373A3931353B5374617475733D313832353B47656E636F6D703D323B4465746C6F633D313436313B466C6167733D303B506172616D733D303B3E3C5265636F726423323A20436F6D70757465723D286E756C6C293B5069643D3734343B382F32312F323031332031343A383A34373A3931353B5374617475733D313832353B47656E636F6D703D323B4465746C6F633D3135333B466C6167733D303B506172616D733D343B7B506172616D23303A2D323134363839333030367D7B506172616D23313A347D7B506172616D23323A36383132367D7B506172616D23333A317D3E</Binary>
  </EventData>
</Event>
This error can be repeatedly triggered with no problem. If I'm on EX01 on EMS and run:
Get-OWAVirtualDirectory -Server EX02
it will take nearly 4 minutes before I get the details and the System Event ID 10028 DistributedCOM will appear on EX01. Same occurs if I reverse the process from EX02. I have turned off the Windows Firewall to see if that makes a difference - no change.
I have remove AV from both servers - no change.
Any ideas will be appreciated.
~Rick

Having the same setup and running in the same problem. Remote-Powershell doesn't work properly. Any remote query needs minutes.
Two Exchange Server 2013 STD on Windows Server 2012, both with MBX & CAS (no DAG), placed in two different sites. CU2 is installed, the system is fully patched. The sites are connected over a IPSec-Tunnel with a acceptable RTT of 50 to 150ms. The Firewall
in between is open for the whole Servernetwork-Segments. The local Windows Firewall is deactivated by GPO. I can portping all needed ports (TCP/80,443,5985) on remote system with success. AutoDiscover is working properly, the Test-Outlook-Clients can connect
automatically to the server, in each site localy. Im using on both servers SAN-Certificates, created on the internal MS-CA. The external part does not exist until now, but there will be a reverse proxy (netscaler) with the official SAN-Certificate, on both
sites with separate internet access.
Another issue is very strange and I don't understand what causes that behavior: The administrators mailbox is on SRV1. When I connect to ECP over "https://fqdnOfSRV1/ECP/" works perfect. But when I connect over "https://fqdnOfSRV2/ECP/" to the same mailbox,
which is on SRV1, the IIS redirects me to the WebApp of administrator. I did test it inverse and using a administrator2 account, which is on a DB on SRV2. Same issue when I connect over SRV1.
I have much more issues and hope some of them will be addressed with CU3.
Did you have any update on this case?
Regards
Patrick

Similar Messages

  • Exchange 2013 logging event 15004 daily 5-10 times per day causing email delay?

    Observing following event in the Servers (3 Servers having multi role with Exchange 2013 CU5)
    Log Name:      Application
    Source:        MSExchangeTransport
    Date:          15/10/2014 3:20:16 PM
    Event ID:      15004
    Task Category: ResourceManager
    Level:         Warning
    Keywords:      Classic
    User:          N/A
    Computer:      SERVER.COM
    Description:
    The resource pressure increased from Medium to High.
    The following resources are under pressure:
    Version buckets = 203 [High] [Normal=80 Medium=120 High=200]
    Physical memory load = 92% [limit is 94% to start dehydrating messages.]
    The following components are disabled due to back pressure:
    Inbound mail submission from Hub Transport servers
    Inbound mail submission from the Internet
    Mail submission from Pickup directory
    Mail submission from Replay directory
    Mail submission from Mailbox server
    Mail delivery to remote domains
    Content aggregation
    Mail resubmission from the Message Resubmission component.
    Mail resubmission from the Shadow Redundancy Component
    The following resources are in normal state:
    Queue database and disk space ("C:\Program Files\Microsoft\Exchange Server\V15\TransportRoles\data\Queue\mail.que") = 61% [Normal] [Normal=95% Medium=97% High=99%]
    Queue database logging disk space ("C:\Program Files\Microsoft\Exchange Server\V15\TransportRoles\data\Queue\") = 75% [Normal] [Normal=95% Medium=97% High=99%]
    Private bytes = 2% [Normal] [Normal=71% Medium=73% High=75%]
    Submission Queue = 0 [Normal] [Normal=2000 Medium=4000 High=10000]
    Temporary Storage disk space ("C:\Program Files\Microsoft\Exchange Server\V15\TransportRoles\data\Temp") = 75% [Normal] [Normal=95% Medium=97% High=99%]
    Event Xml:
    <Event xmlns="http://schemas.microsoft.com/win/2004/08/events/event">
      <System>
        <Provider Name="MSExchangeTransport" />
        <EventID Qualifiers="32772">15004</EventID>
        <Level>3</Level>
        <Task>15</Task>
        <Keywords>0x80000000000000</Keywords>
        <TimeCreated SystemTime="2014-10-15T09:50:16.000000000Z" />
        <EventRecordID>36645321</EventRecordID>
        <Channel>Application</Channel>
        <Computer>SERVER.COM</Computer>
        <Security />
      </System>
      <EventData>
        <Data>Medium</Data>
        <Data>High</Data>
        <Data>
    The following resources are under pressure:
    Version buckets = 203 [High] [Normal=80 Medium=120 High=200]
    Physical memory load = 92% [limit is 94% to start dehydrating messages.]
    The following components are disabled due to back pressure:
    Inbound mail submission from Hub Transport servers
    Inbound mail submission from the Internet
    Mail submission from Pickup directory
    Mail submission from Replay directory
    Mail submission from Mailbox server
    Mail delivery to remote domains
    Content aggregation
    Mail resubmission from the Message Resubmission component.
    Mail resubmission from the Shadow Redundancy Component
    The following resources are in normal state:
    Queue database and disk space ("C:\Program Files\Microsoft\Exchange Server\V15\TransportRoles\data\Queue\mail.que") = 61% [Normal] [Normal=95% Medium=97% High=99%]
    Queue database logging disk space ("C:\Program Files\Microsoft\Exchange Server\V15\TransportRoles\data\Queue\") = 75% [Normal] [Normal=95% Medium=97% High=99%]
    Private bytes = 2% [Normal] [Normal=71% Medium=73% High=75%]
    Submission Queue = 0 [Normal] [Normal=2000 Medium=4000 High=10000]
    Temporary Storage disk space ("C:\Program Files\Microsoft\Exchange Server\V15\TransportRoles\data\Temp") = 75% [Normal] [Normal=95% Medium=97% High=99%]
    </Data>
      </EventData>
    </Event>
    Manju Gowda

    hi manju.. this is because of your resource utilization being very high. please check below two links to check the logs and take appropriate actions
    http://exchangeserverpro.com/exchange-transport-server-back-pressure/
    http://technet.microsoft.com/en-us/library/bb201658%28v=exchg.150%29.aspx
    Mark as useful or answered if my replies helped you solving your query.
    Thanks, Happiness Always
    Jatin
    Skype: jatider2jatin, Email: [email protected]

  • Exchange 2013 CU6 Event ID 4999

    After installing CU6 on the exchange 2013 mailbox server we keep getting the below event error message
    Log Name:      Application
    Source:        MSExchange Common
    Date:          10/2/2014 1:06:25 PM
    Event ID:      4999
    Task Category: General
    Level:         Error
    Keywords:      Classic
    User:          N/A
    Computer:     
    Description:
    Watson report about to be sent for process id: 30632, with parameters: E12, c-RTL-AMD64, 15.00.0995.029, M.E.RpcClientAccess.Service, M.E.Data.ApplicationLogic, M.E.D.A.U.HttpPhotoRequestBuilder.Build, System.NotSupportedException, 4e29, 15.00.0995.027.
    ErrorReportingEnabled: True
    Event Xml:
    <Event xmlns="">
      <System>
        <Provider Name="MSExchange Common" />
        <EventID Qualifiers="16388">4999</EventID>
        <Level>2</Level>
        <Task>1</Task>
        <Keywords>0x80000000000000</Keywords>
        <TimeCreated SystemTime="2014-10-02T20:06:25.000000000Z" />
        <EventRecordID>7826297</EventRecordID>
        <Channel>Application</Channel>
        <Computer></Computer>
        <Security />
      </System>
      <EventData>
        <Data>30632</Data>
        <Data>E12</Data>
        <Data>c-RTL-AMD64</Data>
        <Data>15.00.0995.029</Data>
        <Data>M.E.RpcClientAccess.Service</Data>
        <Data>M.E.Data.ApplicationLogic</Data>
        <Data>M.E.D.A.U.HttpPhotoRequestBuilder.Build</Data>
        <Data>System.NotSupportedException</Data>
        <Data>4e29</Data>
        <Data>15.00.0995.027</Data>
        <Data>True</Data>
        <Data>False</Data>
        <Data>Microsoft.Exchange.RpcClientAccess.Service</Data>
        <Data>
        </Data>
      </EventData>
    </Event>
    Services seem to be fine but i do have a group of users that complain that their outlook 2013 email clients will go non-responsive a few times a days. Wondering if this is related. Also this error is appearing every few minutes. Anyone else experiencing
    this?

    Hi,
    I would like to add some information to this, in case others are facing the same circumstance. I too received the same errors on my Exchange 2013 CU5 and CU6 servers mentioned above. I ended up calling Microsoft Premiere support because there was a very
    large impact in our environment as we had Outlook 2010 clients that were having Exchange 2013 connectivity issues. Long story short, since Outlook 2010 was trying to use RPC to connect to the Exchange 2013 servers and in the Event Viewer we were seeing the
    4999 Event ID multiple times per minute, RPC was crashing on the Exchange servers resulting in client connectivity issues.
    Microsoft ran a ProcDump on the PID for RPC crash and basically came back with nothing only saying that it was a result of someone uploading a picture via Lync that was either corrupt or too large cause the photo store to crash the RPC Service. They also
    were firm in saying that this should have no impact. I was not convinced because this happened after installing CU5 and the client connectivity issues also appeared in conjunction with these 4999 RPC errors. In my mind that is a bug and I asked that something
    be published to address this as it seems silly that one user uploading a Lync profile picture could cripple our environment.
    You would need to navigate to the following location to see this Photo Store. (D:\Program Files\Microsoft\Exchange Server\V15\ClientAccess\photos) Change the path to point to your local Exchange install instance. Most of the files in my location are 0K but
    there are a few that are 4K so it seems they are not large enough to affect anything. We have 4 CAS+MBX servers so I looked at all 4 servers.
    What I ended up doing to resolve the 4999 event ID which actually ended up fixing my client connectivity issues also was to edit the following file. "D:\Program Files\Microsoft\Exchange Server\V15\Bin\Microsoft.Exchange.RpcClientAccess.Service.exe.config"
    Back the above file up and when you open it scroll about 3/4 to 7/8 of the way down and find the following lines:
        <!-- Enables retrieval of the HD photo in DOMT. -->
        <add key="HDPhotoEnabled" value="true" />
    Set the line to "false" like so:
        <!-- Enables retrieval of the HD photo in DOMT. -->
        <add key="HDPhotoEnabled" value="false" />
    Then restart the Microsoft Exchange RPC Client Access service and refresh the Event Viewer and the 4999 errors should stop and client connectivity should be restored.
    I noticed this error with CU5 and then subsequently after I installed CU6, so I had to perform this change after I installed CU6 and probably do the same once CU7 comes out. I do not know the adverse effects of making this change as Microsoft really could
    not explain more than what I wrote above, but I had to get Outlook connectivity restored and this was my only option. It appears that Lync 2010 photos and Outlook 2010 photos stayed intact so no users were complaining that their self-uploaded profile pictures
    were gone. We never had this problem with Outlook 2013 SP1 as we have MAPI enabled and the crashing RPC service would not have effected those clients. OWA was also working just fine.
    Hopefully Microsoft can offer me more of an explanation as I ended up fixing my own issue but I raised concern with how this happened. I hope this helps someone else as it helped me.
    Thanks.
    Alan

  • Exchange 2013 CU6 event id 1003

    Installed cu6, after that OWA and ECP stopped to work, with a redirection loop, when I check my eventlogs I see thousands of this error message:
    RpcHttp] An internal server error occurred. The unhandled exception was: System.MissingMethodException: Method not found: 'System.String Microsoft.Exchange.Security.Authentication.IIdentityExtensions.GetSafeName(System.Security.Principal.IIdentity)'.
       at Microsoft.Exchange.HttpProxy.ProxyModule.<>c__DisplayClasse.<OnEndRequest>b__d()
       at Microsoft.Exchange.Common.IL.ILUtil.DoTryFilterCatch(TryDelegate tryDelegate, FilterDelegate filterDelegate, CatchDelegate catchDelegate)
    Cant find a workaround, anyone else seen this error?

    Maybe this can help someone.

    Replaced SharedWebConfig files under the location "V15\FrontEnd\HttpProxy"

    Added the missing permission on Exchange Back End Web Site by comparing the same with our lab

    On IIS
    è Exchange Back End
    è Changed Physical Path
    è it to "V15\ClientAccess"

    Still after which we couldn’t browse OWA under Exchange Back End using Port 444 but found that ECP works fine

    Replaced the SharedWebConfig file from working Exchange 2013 CU6 under the location "V15\ClientAccess"

    Ran IISReset

    Confirmed that OWA and other virtual directories as well started working fine without any issues

  • Exchange 2013 disconnects externally after every hour but works fine internally

    Hello All,
    I have a very strange problem in my office. At the new years eve, there was a disconnection in our Internet from our ISP and everything came back online again after 1 hour. before this happened everything was working fine such as externally all the mobile
    devices were able to connect to exchange 2013 and event owa was working fine and laptop devices as well. All was good, but once the disconnect happened, i am only able to access my emails over 3 G connection but not over the ISP connection, what i mean from
    that is that if i try to connect to owa or my outlook from home DSL connection i cannot connect but with my 3g connection on my phone i can connect and everything works fine. i have re issued the certificates and installed them again, but still the same thing,
    after every hour or sometimes less the exchange 2013 sort of disconnects and starts working when i restart the CAS server where the traffic is routed to.
    Has any one faced this issue, please help, i was thinking that something wrong with my firewall as i was not even able to connect to my ssl vpn so i thought that firewall is culprit, but i have replaced the firewall as well and still the same issue.
    Please help, i am trying to troubleshoot this problem since last 10 days but with no luck.
    Thank You. 

    Have you checked the network settings? Do you have multiple network adapters? May be DNS related also. Check, if you have configured DNS correctly.  
    Regards from ExchangeOnline.in|Windows Administrator Area | Skype:[email protected]

  • Seemingly successful install of Exchange 2013 SP1 turns into many errors in event logs after upgrade to CU7

    I have a new Exchange 2013 server with plans to migrate from my current Exchange 2007 Server. 
    I installed Exchange 2013 SP1 and the only errors I saw in the event log seemed to be long standing known issues that did not indicate an actual problem (based on what I read online). 
    I updated to CU7 and now lots of errors have appeared (although the old ones seem to have been fixed so I have that going for me). 
    Currently the Exchange 2013 server is not in use and clients are still hitting the 2007 server.
    Issue 1)
    After each reboot I get a Kernel-EventTracing 2 error.  I cannot find anything on this on the internet so I have no idea what it is.
    Session "FastDocTracingSession" failed to start with the following error: 0xC0000035
    I did read other accounts of this error with a different name in the quotes but still can’t tell what this is or where it is coming from.
    Issue 2)
    I am still getting 5 MSExchange Common 106 errors even after reregistering all of the perf counters per this page:
    https://support.microsoft.com/kb/2870416?wa=wsignin1.0
    One of the perf counters fails to register using the script from the link above.
    66 C:\Program Files\Microsoft\Exchange Server\V15\Setup\Perf\InfoWorkerMultiMailboxSearchPerformanceCounters.xml
    New-PerfCounters : The performance counter definition file is invalid.
    At C:\Users\administrator.<my domain>\Downloads\script\ReloadPerfCounters.ps1:19 char:4
    +    New-PerfCounters -DefinitionFileName $f
    +    ~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~
        + CategoryInfo         
    : InvalidData: (:) [New-PerfCounters], TaskException
        + FullyQualifiedErrorId : [Server=VALIS,RequestId=71b6bcde-d73e-4c14-9a32-03f06e3b2607,TimeStamp=12/18/2014 10:09:
       12 PM] [FailureCategory=Cmdlet-TaskException] 33EBD286,Microsoft.Exchange.Management.Tasks.NewPerfCounters
    But that one seems unrelated to the ones that still throw errors. 
    Three of the remaining five errors are (the forum is removing my spacing between the error text so it looks like a wall of text - sorry):
    Performance counter updating error. Counter name is Count Matched LowFidelity FingerPrint, but missed HighFidelity FingerPrint, category name is MSExchange Anti-Malware Datacenter Perfcounters. Optional code: 3. Exception: The
    exception thrown is : System.InvalidOperationException: The requested Performance Counter is not a custom counter, it has to be initialized as ReadOnly.
       at System.Diagnostics.PerformanceCounter.InitializeImpl()
       at System.Diagnostics.PerformanceCounter.set_RawValue(Int64 value)
       at Microsoft.Exchange.Diagnostics.ExPerformanceCounter.set_RawValue(Int64 value)
    Last worker process info : System.ArgumentException: Process with an Id of 7384 is not running.
       at System.Diagnostics.Process.GetProcessById(Int32 processId)
       at Microsoft.Exchange.Diagnostics.ExPerformanceCounter.GetLastWorkerProcessInfo()
    Performance counter updating error. Counter name is Number of items, item is matched with finger printing cache, category name is MSExchange Anti-Malware Datacenter Perfcounters. Optional code: 3. Exception: The exception thrown
    is : System.InvalidOperationException: The requested Performance Counter is not a custom counter, it has to be initialized as ReadOnly.
       at System.Diagnostics.PerformanceCounter.InitializeImpl()
       at System.Diagnostics.PerformanceCounter.set_RawValue(Int64 value)
       at Microsoft.Exchange.Diagnostics.ExPerformanceCounter.set_RawValue(Int64 value)
    Last worker process info : System.ArgumentException: Process with an Id of 7384 is not running.
       at System.Diagnostics.Process.GetProcessById(Int32 processId)
       at Microsoft.Exchange.Diagnostics.ExPerformanceCounter.GetLastWorkerProcessInfo()
    Performance counter updating error. Counter name is Number of items in Malware Fingerprint cache, category name is MSExchange Anti-Malware Datacenter Perfcounters. Optional code: 3. Exception: The exception thrown is : System.InvalidOperationException:
    The requested Performance Counter is not a custom counter, it has to be initialized as ReadOnly.
       at System.Diagnostics.PerformanceCounter.InitializeImpl()
       at System.Diagnostics.PerformanceCounter.set_RawValue(Int64 value)
       at Microsoft.Exchange.Diagnostics.ExPerformanceCounter.set_RawValue(Int64 value)
    Last worker process info : System.ArgumentException: Process with an Id of 7384 is not running.
       at System.Diagnostics.Process.GetProcessById(Int32 processId)
       at Microsoft.Exchange.Diagnostics.ExPerformanceCounter.GetLastWorkerProcessInfo()
    Issue 3)
    I appear to have some issues related to the healthmailboxes. 
    I get MSExchangeTransport 1025 errors for multiple healthmailboxes.
    SMTP rejected a (P1) mail from 'HealthMailbox23b10b91745648819139ee691dc97eb6@<my domain>.local' with 'Client Proxy <my server>' connector and the user authenticated as 'HealthMailbox23b10b91745648819139ee691dc97eb6'. The Active Directory
    lookup for the sender address returned validation errors. Microsoft.Exchange.Data.ProviderError
    I reran setup /prepareAD to try and remedy this but I am still getting some.
    Issue 4)
    I am getting an MSExchange RBAC 74 error. 
    (Process w3wp.exe, PID 984) Connection leak detected for key <my domain>.local/Admins/Administrator in Microsoft.Exchange.Configuration.Authorization.WSManBudgetManager class. Leaked Value 1.
    Issue 5)
    I am getting MSExchange Assistants 9042 warnings on both databases.
    Service MSExchangeMailboxAssistants. Probe Time Based Assistant for database Database02 (c83dbd91-7cc4-4412-912e-1b87ca6eb0ab) is exiting a work cycle. No mailboxes were successfully processed. 2 mailboxes were skipped due to errors. 0 mailboxes were
    skipped due to failure to open a store session. 0 mailboxes were retried. There are 0 mailboxes in this database remaining to be processed.
    Some research suggested this may be related to deleted mailboxes however I have never had any actual user mailboxes on this server. 
    If they are healthmailboxes or arbitration mailboxes that might make sense but I am unsure of what to do on this.
    Issue 6)
    At boot I am getting an MSExchange ActiveSync warning 1033
    The setting SupportedIPMTypes in the Web.Config file was missing. 
    Using default value of System.Collections.Generic.List`1[System.String].
    I don't know why but this forum is removing some of my spacing that would make parts of this easier to read.

    Hi Eric
    Yes I have uninstalled and reinstalled Exchange 2013 CU7 for the 3<sup>rd</sup> time. 
    I realize you said one issue per forum thread but since I already started this thread with many issues I will at least post what I have discovered on them in case someone finds their way here from a web search.
    I have an existing Exchange 2007 server in the environment so I am unable to create email address policies that are defined by “recipient container”. 
    If I try and do so I get “You can't specify the recipient container because legacy servers are detected.”
     So I cannot create a normal email address policy and restrict it to an OU without resorting to some fancy filtering. 
    Instead what I have done is use PS to modify extensionAttribute1 (otherwise known as Custom Attribute 1 to exchange) for all of my users. 
    I then applied an address policy to them and gave it the highest priority. 
    Then I set a default email address policy for the entire organization. 
    After reinstalling Exchange all of my system mailboxes were created with the internal domain name. 
    So issue number 3 above has not come up. 
    For issue number one above I have created a new thread:
    https://social.technet.microsoft.com/Forums/office/en-US/7eb12b89-ae9b-46b2-bd34-e50cd52a4c15/microsoftwindowskerneleventtracing-error-2-happens-twice-at-boot-ex2013cu7?forum=exchangesvrdeploy
    For issue number four I have posted to this existing thread where there is so far no resolution:
    https://social.technet.microsoft.com/Forums/exchange/en-US/2343730c-7303-4067-ae1a-b106cffc3583/exchange-error-id-74-connection-leak-detected-for-key?forum=exchangesvradmin
    Issue number Five I have managed to recreate and get rid of in more than one way. 
    If I create a new database in ECP and set the database and log paths where I want, then this error will appear. 
    If I create the database in the default location and then use EMS to move it and set the log path, then the error will not appear. 
    The error will also appear (along with other errors) if I delete the health mailboxes and let them get recreated by restarting the server or the Health Manager service. 
    If I then go and set the retention period for deleted mailboxes to 0 days and wait a little while, these will all go away. 
    So my off hand guess is that these are caused by orphaned system mailboxes.
    For issue number six I have posted to this existing thread where there is so far no resolution:
    https://social.technet.microsoft.com/Forums/exchange/en-US/dff62411-fad8-4d0c-9bdb-037374644845/event-1033-msexchangeactivesync-warning?forum=exchangesvrmobility
    So for the remainder of this thread we can try and tackle issue number two which is the perf counters. 
    The exact same 5 perf counter were coming up and this had been true each time I have uninstalled and reinstalled Exchange 2013CU7. 
    Actually to be more accurate a LOT of perf counter errors come up after the initial install, but reloading the perf counters using the script I posted above reduces it to the same five. 
    Using all of your suggestions so far has not removed these 5 remaining errors either.  Since there is no discernible impact other than these errors at boot I am not seriously bothered by them but as will all event log errors, I would prefer
    to make them go away if possible.

  • In exchange 2013 sp1 SUBMITFAIL event id is happening

    Hi ,
    In exchange 2013 sp1 SUBMITFAIL event id is happening for some messages .But at the second time that the same message is delivered perfectly to the end users.
    My question is simple ,is this an bug in exchange 2013 sp1 if so on which CU it will be corrected ?We have to update to our customers so all of us please provide your suggestions as soon as possible.
    Thanks & Regards S.Nithyanandham

    Hi Allen Wang ,
    Thanks a lot for your response.
    Which version are you used? Is this issue arise after install update for Exchange server? 
    We are using exchange 2013 sp1 Ent edition.This issue is been existing in my environment when we start to use exchange 2013 and it is not from sp1 .
    Also, what your means of “second time”, server retry to send or send failed then user click to resend?
    When an user send an email for the first time to some of the recipient's it is reaching only to the few recipient's mailboxes and the email to the remaining recipients gets failed with the event ID "SUBMITFAIL" on the message tracking log.
    Same time if we forward that same message to the failed recipients it went and delivered successfully.
    Note : Apart from message tracking log i didn't found anything helpful in protocol and event viewer logs.
    Below link is for your Reference :
    https://social.technet.microsoft.com/Forums/fr-FR/ae61d80c-58da-4f47-b83c-66b123b2faf4/exchange-2013-mailflow-and-the-hosts-file?forum=exchangesvrgeneral
    Above is the link which is saying that this issue will be resolved in exchange 2013 sp1 and also it says it an bug in exchange 2013 CU3 .But still on my end the problems occurs in exchange 2013 CU3 as well as in exchange 2013 SP1.
    Please help me out yaar this issue is raising in my production environment.
    Thanks & Regards S.Nithyanandham

  • Event ID 2142, 2077, 2069 MSExchangeADTopology Exchange 2013

    Hello,
    I have just inherited a slightly abused new server as part of my job and it looks like the previous admin was using a live single domain as a test bed.
    From what I have been able to determine this windows 2008R2 server started life as a single name domain (no FQDN) that had exchange 2013 running on it (sin I know).  A domain rename was performed and from what I can tell it did change the domain name to
    a FQDN environment.  (it went for COMPANY to COMPANY.COM)
    I have been able to clean up most of the other ghosts in the machine except when it comes to exchange.  I get event ID 2142(error), 2077 (info), and 2069 (info) repeatedly it cycles every 2 minutes:
    Log Name:      Application
    Source:        MSExchangeADTopology
    Date:          4/18/2013 11:42:39 AM
    Event ID:      2142
    Task Category: Topology
    Level:         Error
    Keywords:      Classic
    User:          N/A
    Computer:      SERVER2013.COMPANY
    Description:
    Process Microsoft.Exchange.Directory.TopologyService.exe (PID=13460) Forest COMPANY.com. Topology discovery failed, error details
    No Suitable Directory Servers Found in Forest COMPANY.com Site Default-First-Site-Name..
    Event Xml:
    <Event xmlns="http://schemas.microsoft.com/win/2004/08/events/event">
      <System>
        <Provider Name="MSExchangeADTopology" />
        <EventID Qualifiers="49156">2142</EventID>
        <Level>2</Level>
        <Task>3</Task>
        <Keywords>0x80000000000000</Keywords>
        <TimeCreated SystemTime="2013-04-18T16:42:39.000000000Z" />
        <EventRecordID>4918254</EventRecordID>
        <Channel>Application</Channel>
        <Computer>SERVER2013.COMPANY</Computer>
        <Security />
      </System>
      <EventData>
        <Data>Microsoft.Exchange.Directory.TopologyService.exe</Data>
        <Data>13460</Data>
        <Data>COMPANY.com</Data>
        <Data>No Suitable Directory Servers Found in Forest COMPANY.com Site Default-First-Site-Name.</Data>
      </EventData>
    </Event>
    Log Name:      Application
    Source:        MSExchangeADTopology
    Date:          4/18/2013 11:42:39 AM
    Event ID:      2077
    Task Category: Topology
    Level:         Information
    Keywords:      Classic
    User:          N/A
    Computer:      SERVER2013.COMPANY
    Description:
    Process Microsoft.Exchange.Directory.TopologyService.exe (PID=13460) Forest COMPANY.com. Exchange Active Directory Provider could not find any suitable domain controller servers in either the local site 'Default-First-Site-Name' or the following sites:
    Event Xml:
    <Event xmlns="http://schemas.microsoft.com/win/2004/08/events/event">
      <System>
        <Provider Name="MSExchangeADTopology" />
        <EventID Qualifiers="16388">2077</EventID>
        <Level>4</Level>
        <Task>3</Task>
        <Keywords>0x80000000000000</Keywords>
        <TimeCreated SystemTime="2013-04-18T16:42:39.000000000Z" />
        <EventRecordID>4938976</EventRecordID>
        <Channel>Application</Channel>
        <Computer>SERVER2013.COMPANY</Computer>
        <Security />
      </System>
      <EventData>
        <Data>Microsoft.Exchange.Directory.TopologyService.exe</Data>
        <Data>13460</Data>
        <Data>COMPANY.com</Data>
        <Data>Default-First-Site-Name</Data>
        <Data>
        </Data>
      </EventData>
    </Event>
    Log Name:      Application
    Source:        MSExchangeADTopology
    Date:          4/18/2013 11:42:39 AM
    Event ID:      2069
    Task Category: Topology
    Level:         Information
    Keywords:      Classic
    User:          N/A
    Computer:      SERVER2013.COMPANY
    Description:
    Process Microsoft.Exchange.Directory.TopologyService.exe (PID=13460) Forest COMPANY.com. Exchange Active Directory Provider couldn't find any suitable Global Catalog servers in either the local site 'Default-First-Site-Name' or the following sites:
    Event Xml:
    <Event xmlns="http://schemas.microsoft.com/win/2004/08/events/event">
      <System>
        <Provider Name="MSExchangeADTopology" />
        <EventID Qualifiers="16388">2069</EventID>
        <Level>4</Level>
        <Task>3</Task>
        <Keywords>0x80000000000000</Keywords>
        <TimeCreated SystemTime="2013-04-18T16:42:39.000000000Z" />
        <EventRecordID>4938977</EventRecordID>
        <Channel>Application</Channel>
        <Computer>SERVER2013.COMPANY</Computer>
        <Security />
      </System>
      <EventData>
        <Data>Microsoft.Exchange.Directory.TopologyService.exe</Data>
        <Data>13460</Data>
        <Data>COMPANY.com</Data>
        <Data>Default-First-Site-Name</Data>
        <Data>
        </Data>
      </EventData>
    </Event>
    It looks to me that exchange is still looking for the old domain name.  Does anyone know how to point it to the correct domain name?
    Exchange is currently down and I am unable to log into EAC, OWA or Exchange Management Powershell.  I am also unable to un-install exchange as it is reporting active mailboxes and I can't delete them because I am unable to log in.
    My overall goal is to remove exchange from this server and put it on a separate server but until I can get exchange working to a point where I can remove the mailboxes, I am stuck.
    Any and all help appreciated.
    Hummedan

    Thank you for your advise on correcting my issue.  I created the subnet and assigned it to the Default-First-Site-Name as there weren't any subnets listed.
    Upon reboot I checked the event log and I am still receiving the event log entries as above; however, I am now receiving a few new errors along with them and they are repeating (4027 error and 3176 action).  Here are the additional errors:
    Log Name:      Application
    Source:        MSExchange ADAccess
    Date:          4/22/2013 9:52:48 AM
    Event ID:      4027
    Task Category: General
    Level:         Error
    Keywords:      Classic
    User:          N/A
    Computer:      SERVER2013.COMPANY
    Description:
    Process msexchangerepl.exe (PID=8016). WCF request (Get Servers for COMPANY.com) to the Microsoft Exchange Active Directory Topology service on server (TopologyClientTcpEndpoint (localhost)) failed. Make sure that the service is running. In addition, make sure
    that the network ports that are used by Microsoft Exchange Active Directory Topology service are not blocked by a firewall. The WCF call was retried 3 time(s). Error Details
     An error occurred during forest discovery (COMPANY.com). ----> No Suitable Directory Servers Found in Forest COMPANY.com Site Default-First-Site-Name.
       at Microsoft.Exchange.Directory.TopologyService.ADTopologyDiscovery.Discover()
       at Microsoft.Exchange.Directory.TopologyService.ADTopologyDiscovery.DoWork(CancellationToken cancellationToken)
       at Microsoft.Exchange.Directory.TopologyService.Common.WorkItem`1.Execute(CancellationToken joinedToken)
       at Microsoft.Exchange.Directory.TopologyService.Common.WorkItem`1.<>c__DisplayClass6.<StartExecuting>b__4()
       at System.Threading.Tasks.Task.Execute()
       at Microsoft.Exchange.Directory.TopologyService.Common.Extensions.WrapAndRethrowException(Exception exception, LocalizedString errorMessage)
       at Microsoft.Exchange.Directory.TopologyService.TopologyDiscoveryManager.EndGetTopology(IAsyncResult ar)
       at Microsoft.Exchange.Directory.TopologyService.TopologyService.InternalEndGetServersForRole(IAsyncResult result)
       at Microsoft.Exchange.Directory.TopologyService.TopologyService.<>c__DisplayClassa.<EndGetServersForRole>b__9()
       at Microsoft.Exchange.Directory.TopologyService.TopologyService.ExecuteServiceCall(Action action)
    Log Name:      Application
    Source:        MSExchangeRepl
    Date:          4/22/2013 9:52:48 AM
    Event ID:      3176
    Task Category: Action
    Level:         Error
    Keywords:      Classic
    User:          N/A
    Computer:      SERVER2013.COMPANY
    Description:
    The Microsoft Exchange Replication service attempted to start the Active Manager RPC server but failed because an error occurred when attempting to read the Exchange Servers universal security group SID from Active Directory. Error:
    The call to Microsoft Exchange Active Directory Topology service on server 'TopologyClientTcpEndpoint (localhost)' returned an error. Error details An error occurred during forest discovery (COMPANY.com)..
    Log Name:      Application
    Source:        MSExchange ADAccess
    Date:          4/22/2013 9:52:48 AM
    Event ID:      4027
    Task Category: General
    Level:         Error
    Keywords:      Classic
    User:          N/A
    Computer:      SERVER2013.COMPANY
    Description:
    Process MSExchangeSubmission.exe (PID=10708). WCF request (Get Servers for COMPANY.com) to the Microsoft Exchange Active Directory Topology service on server (TopologyClientTcpEndpoint (localhost)) failed. Make sure that the service is running. In addition,
    make sure that the network ports that are used by Microsoft Exchange Active Directory Topology service are not blocked by a firewall. The WCF call was retried 3 time(s). Error Details
     An error occurred during forest discovery (COMPANY.com). ----> No Suitable Directory Servers Found in Forest COMPANY.com Site Default-First-Site-Name.
       at Microsoft.Exchange.Directory.TopologyService.ADTopologyDiscovery.Discover()
       at Microsoft.Exchange.Directory.TopologyService.ADTopologyDiscovery.DoWork(CancellationToken cancellationToken)
       at Microsoft.Exchange.Directory.TopologyService.Common.WorkItem`1.Execute(CancellationToken joinedToken)
       at Microsoft.Exchange.Directory.TopologyService.Common.WorkItem`1.<>c__DisplayClass6.<StartExecuting>b__4()
       at System.Threading.Tasks.Task.Execute()
       at Microsoft.Exchange.Directory.TopologyService.Common.Extensions.WrapAndRethrowException(Exception exception, LocalizedString errorMessage)
       at Microsoft.Exchange.Directory.TopologyService.TopologyDiscoveryManager.EndGetTopology(IAsyncResult ar)
       at Microsoft.Exchange.Directory.TopologyService.TopologyService.InternalEndGetServersForRole(IAsyncResult result)
       at Microsoft.Exchange.Directory.TopologyService.TopologyService.<>c__DisplayClassa.<EndGetServersForRole>b__9()
       at Microsoft.Exchange.Directory.TopologyService.TopologyService.ExecuteServiceCall(Action action)

  • Exchange 2013 Event ID 9646 - MoMT 500 Folder

    Hello,
    I am running Exchange 2013 CU3 and I'm getting an Event ID 9646 in the application event log. Full text below. It would appear it's saying the user is trying to open more than 500 folders but I have looked at her mailbox and while she has a lot of folders,
    it's not over 500. Any suggestions or ideas?
    Thanks,
    Brad
    The description for Event ID 9646 from source MSExchangeIS cannot be found. Either the component that raises this event is not installed on your local computer or the installation is corrupted. You can install or repair the component on the local computer.
    If the event originated on another computer, the display information had to be saved with the event.
    The following information was included with the event:
    /O=xxxxx/OU=xxxxx/cn=Recipients/cn=JRoberts
    MoMT
    500
    Folder
    the message resource is present but the message is not found in the string/message table
    BradG87

    Hi,
    About event 9646, this could be caused when a MAPI session tried to open more than the maximum number of objects that are allowed for the object type specified in the event description.
    To resolve this issue, please try to modify the registry key and set the "objtFolder" value to 1000 to check the result.
    For more details, please refer to the solution in the following article.
    MSExchangeIS 9646
    http://technet.microsoft.com/library/ff980641.aspx
    Best regards,
    Belinda
    Belinda Ma
    TechNet Community Support

  • Exchange 2013 OWA,Async,And OA error MsExchange BackEndRehydration event id 3002

    Hi team,
    I had issue in My Exchange system.
    I had two Exchange 2013 muli role with CAS and MBX
    Server A had no problem connection when client access OWA directly (https://servernamefqdn/owa)
    but, theres issue when I pointing to server B OWA (https://serverBfqdn/owa). its same when outlook connect (using OA ),and Aysnc connection.
    when I failed to connect OWA, theres event id 3002 MsExchange BackEndRehydration event id 3002.
    the error show at Server A ( server at a good condition )
    heres the error
    Thanks

    Hello Team,
    I have a similar issue with Event ID 3002 filling up the App log on both Mailbox servers.  Here is a snippet of the error.  Any help is greatly appreciated.  Thank you.
    "Protocol /EWS failed to process request from identity DOMAIN\CASServer. Exception: Microsoft.Exchange.Security.OAuth.InvalidOAuthTokenException: The user specified by the user-context in the token is ambiguous.
       at Microsoft.Exchange.Security.OAuth.OAuthActAsUser.InternalCreateFromAttributes(OrganizationId organizationId, Boolean calledAtFrontEnd, Dictionary`2 rawAttributes, Dictionary`2 verifiedAttributes)
       at Microsoft.Exchange.Security.Authentication.BackendAuthenticator.OAuthAuthenticator.ExtractActAsUser(OrganizationId organizationId, CommonAccessToken token)
       at Microsoft.Exchange.Security.Authentication.BackendAuthenticator.OAuthAuthenticator.InternalRehydrate(CommonAccessToken token, Boolean wantAuthIdentifier, String& authIdentifier, IPrincipal& principal)
       at Microsoft.Exchange.Security.Authentication.BackendAuthenticator.Rehydrate(CommonAccessToken token, BackendAuthenticator& authenticator, Boolean wantAuthIdentifier, String& authIdentifier, IPrincipal& principal, IAccountValidationContext&
    accountValidationContext)
       at Microsoft.Exchange.Security.Authentication.BackendRehydrationModule.ProcessRequest(HttpContext httpContext)
       at Microsoft.Exchange.Security.Authentication.BackendRehydrationModule.OnAuthenticateRequest(Object source, EventArgs args).

  • Exchange 2013 event ID 36888 SChannel error 12 and 1203

    I am running Windows Server 2012 STD with Exchange 2013 installed on the same server. I know that Microsoft doesnt recommend to do this, but I had no choice. Errors are follow:
    A fatal alert was generated and sent to the remote endpoint. This may result in termination of the connection. The TLS protocol defined fatal error code is 10. The Windows SChannel error state is 12.
    A fatal alert was generated and sent to the remote endpoint. This may result in termination of the connection. The TLS protocol defined fatal error code is 10. The Windows SChannel error state is 1203.
    - System
    - Provider
    [ Name] Schannel
    [ Guid] {1F678132-5938-4686-9FDC-C8FF68F15C85}
    EventID 36888
    Version 0
    Level 2
    Task 0
    Opcode 0
    Keywords 0x8000000000000000
    - TimeCreated
    [ SystemTime] 2014-11-25T23:30:34.120233400Z
    EventRecordID 121125
    Correlation
    - Execution
    [ ProcessID] 1064
    [ ThreadID] 20184
    Channel System
    Computer server
    - Security
    [ UserID] S-1-5-18
    - EventData
    AlertDesc 10
    ErrorState 12
    System
    - Provider
    [ Name] Schannel
    [ Guid] {1F678132-5938-4686-9FDC-C8FF68F15C85}
    EventID 36888
    Version 0
    Level 2
    Task 0
    Opcode 0
    Keywords 0x8000000000000000
    - TimeCreated
    [ SystemTime] 2014-11-26T05:45:22.650086300Z
    EventRecordID 121230
    Correlation
    - Execution
    [ ProcessID] 1064
    [ ThreadID] 45336
    Channel System
    Computer SERVER
    - Security
    [ UserID] S-1-5-18
    - EventData
    AlertDesc 10
    ErrorState 1203
    Process ID 1064 is Isass.exe
    I found somewhere that error 1203 could be ignored, but nothing about error 12. 
    Server is running with selfsigned SAN certificate, hosted 2 exchange domains (10 mailboxes, 5 local, 5 linked for remote domain connected via external 2 way non transitive domain trust).
    Thank you very much for any advise.
    Regards,
    Jan
    Šerý

    Hi Jan,
    Based on my research for the Event 36888, the issue may be caused by not standard or corrupted behavior of web browsers or users, such as user use HTTP protocol to access Exchange service which is a SSL site on port 443.
    Please check whether there is a HTTP redirect configured in your IIS Manager of Exchange server. Also reset web browsers to have a try. Here are some similar thread for this issue:
    https://social.technet.microsoft.com/Forums/forefront/en-US/92c63737-c2a3-41f7-8878-3b0cf5ee95ff/new-install-event-log-schannel-event-id-36888?forum=Forefrontedgegeneral
    http://ficility.net/2013/10/21/exchange-2013-exchange-2010-windows-server-2012-schannel-event-id36888-1203-tlsssl-error-the-root-cause/
    Note: Microsoft is providing this information as a convenience to you. The sites are not controlled by Microsoft. Microsoft cannot make any representations regarding the quality, safety, or suitability of any software or information found there. Please make
    sure that you completely understand the risk before retrieving any suggestions from the above link.
    Regards,
    Winnie Liang
    TechNet Community Support

  • Exchange 2013 and SCOM False Events

    We are having many problems with the health monitoring of exchange in our SCOM 2012 environment. We have 9 exchange servers, with 3 DAGS across the 9 servers. WE are constantly getting health events in SCOM, even for monitors i've explicitly disabled. For
    example, the FIPS monitor. Following this guide (http://blogs.technet.com/b/exchange/archive/2013/08/13/customizing-managed-availability.aspx) i disabled the FIPS probes/monitors all together across our entire Exchange environment, and yet in SCOM, all 9 servers
    show this monitor as being unhealthy. Is my understanding on this functionality incorrect, or is it just not functioning properly?
    Similarly, even when an Exchange monitor is completely healthy, it shows as unhealthy in SCOM. Right now, HubTransport shows as unhealthy in SCOM For all our Exchange servers, but when i run this command everything shows as healthy, across all servers.
    Get-ServerHealth <server name> | ?{$_.HealthSetName -eq "HubTransport"}
    I understand that these monitors can be unhealthy for a while and correct themselves, but shouldn't that correct them in SCOM as well? And for disabled monitors, like FIPS, they should never be unhealthy at all. So why are they showing as unhealthy in SCOM?
    Am i expected to reset health in SCOM every time an unhealthy flag is thrown in Exchange?
    From what i've seen there is a huge discrepancy between how SCOM works and how Exchange monitors work. They don't seem to integrate well, at all. Does anyone have any suggestions on getting Exchange 2013 monitors to work properly in SCOM? Is this my error
    as a user, or is it just bad software

    Hi,
    I recommend you use the Get-HealthReport cmdlet to check Exchange Server health again.
    What's more, please verify if the account you use has the Organization Management permission and Server Management permission. Also, you can change an account and see the result.
    Moreover, please take your time to post the unhealthy information from SCOM monitor about Exchange server for my further research.
    Hope my clarification is helpful.
    If there is any update, please feel free to let me know.
    Best regards,
    Amy
    Amy Wang
    TechNet Community Support

  • Exchange 2013 Critical Search event 2158 with event 1006

    Hi,
    I'm running Exchange 2013 CU1.  I've noticed in the event logs two errors that continuously keep popping up relating to searching.  Actual searching of mail seems fine and the mail databases are in a healthy state.
    Event ID 2158 Unified logging service
    Event 20 (Search) of severity 'Critical' occurred 11 more time(s) and was suppressed in the event log
    and
    Event ID 1006 General
    The FastFeeder component received a connection exception from FAST. Error details: Microsoft.Exchange.Search.Fast.FastConnectionException: Connection to the Content Submission Service has failed. ---> Microsoft.Ceres.External.ContentApi.ConnectionException:
    Recovery failed after 0 retries
       at Microsoft.Ceres.External.ContentApi.DocumentFeeder.DocumentFeeder.CheckRecoveryFailed()
       at Microsoft.Ceres.External.ContentApi.DocumentFeeder.DocumentFeeder.WaitForAvailable()
       at Microsoft.Ceres.External.ContentApi.DocumentFeeder.DocumentFeeder.SubmitDocument(Document document, TimeSpan timeout)
       at Microsoft.Ceres.External.ContentApi.DocumentFeeder.DocumentFeeder.SubmitDocument(Document document)
       at Microsoft.Exchange.Search.Fast.FastFeeder.SubmitDocumentInternal(Object state)
       --- End of inner exception stack trace ---

    Hi,
    Please take your time to apply the latest CU and see whether the issue fixes.
    Regards,
    Simon Wu
    TechNet Community Support

  • Exchange 2013 Offline Address Book generat failure Event ID 17004

    Hello guys,
    i met the following event id when I tried to update the offline address book on my mailbox server (Exchange 2013),
    i have done the troubleshooting steps as below,
    1 Reboot the mailbox server
    2 restart the mailbox assistant service
    I'd like know what can i do  next step?
           Generation of OAB "\Default Offline Address Book" failed.       
    Dn: CN=Default Offline Address Book,CN=Offline Address Lists,CN=Address Lists Container,CN=zteservices,CN=Microsoft Exchange,CN=Services,CN=Configuration,DC=zteservices,DC=eu       
    ObjectGuid: a603acd4-ea74-47c3-88a5-ebf25cbc663a       
    Stats: S:OAB='\Default Offline Address Book';I32:Status=2147500037;Dt:StartTime=2014-02-04T14:50:14.9300281Z;Dt:EndTime=0001-01-01T00:00:00.0000000;S:DC=ztedomain01.zteservices.eu;I32:Total.Records=1908;Ti:TimeWritingFiles=00:00:04.7035164;S:Wasted=False;Ti:Al.Unsorted.LdapElapsedTime=00:00:04.6206741;Ti:MailboxDownload.StoreRpcLatency=00:00:00.0160000;I32:MailboxDownload.StoreRpcCount=6;Ti:MailboxDownload.CpuTime=00:00:00.0312500;Ti:MailboxDownload.ElapsedTime=00:00:00.0496183;I32:Template.FS.BytesRead=1499956;I32:Template.FS.BytesWritten=2216646;Ti:Template.FS.Reading.ElapsedTime=00:00:00.0077045;Ti:Template.FS.Writing.ElapsedTime=00:00:00.0285458;Ti:Template.CpuTime=00:00:03.2031250;Ti:Template.ElapsedTime=00:00:04.7140032;I32:AL.Unsorted.FS.BytesRead=0;I32:AL.Unsorted.FS.BytesWritten=1874031;Ti:AL.Unsorted.FS.Reading.ElapsedTime=00:00:00;Ti:AL.Unsorted.FS.Writing.ElapsedTime=00:00:00.0224695;Ti:AL.Unsorted.LdapLatency=00:00:14.1220000;I32:AL.Unsorted.LdapCount=4844;Ti:AL.Unsorted.CpuTime=00:00:09.8125000;Ti:AL.Unsorted.ElapsedTime=00:00:23.4694472;I32:AL.Sorted.FS.BytesRead=1866395;I32:AL.Sorted.FS.BytesWritten=1866419;Ti:AL.Sorted.FS.Reading.ElapsedTime=00:00:00.0157892;Ti:AL.Sorted.FS.Writing.ElapsedTime=00:00:00.0104285;Ti:AL.Sorted.CpuTime=00:00:00.0468750;Ti:AL.Sorted.ElapsedTime=00:00:00.0573755;I32:AL.Compress.FS.BytesRead=1866407;I32:AL.Compress.FS.BytesWritten=1866407;Ti:AL.Compress.FS.Reading.ElapsedTime=00:00:00.0009518;Ti:AL.Compress.FS.Writing.ElapsedTime=00:00:01.3330312;Ti:AL.Compress.CpuTime=00:00:01.3593750;Ti:AL.Compress.ElapsedTime=00:00:01.3756676;I32:DiffGen.FS.BytesRead=0;I32:DiffGen.FS.BytesWritten=0;Ti:DiffGen.FS.Reading.ElapsedTime=00:00:00;Ti:DiffGen.FS.Writing.ElapsedTime=00:00:00;Ti:DiffGen.CpuTime=00:00:00;Ti:DiffGen.ElapsedTime=00:00:00.0155622;Ti:AL.Total.CpuTime=00:00:11.2187500;Ti:AL.Total.ElapsedTime=00:00:24.9209864;Ti:Total.CpuTime=00:00:14.5468750;Ti:Total.ElapsedTime=00:00:29.8092411;;     
    System.NullReferenceException: Object reference not set to an instance of an object.
       at Microsoft.Exchange.OAB.BaseStream.Seek(Int64 offset, SeekOrigin origin)
       at Microsoft.Exchange.MailboxAssistants.Assistants.OABGenerator.DiffFileGenerator.ReadFileHeader(Stream stream, Byte[] buffer, Int32& numberOfBytesRead, UInt32& crc)
       at Microsoft.Exchange.MailboxAssistants.Assistants.OABGenerator.DiffFileGenerator.CreatePatch(Stream diffStream)
       at Microsoft.Exchange.MailboxAssistants.Assistants.OABGenerator.DiffFileGenerator.GenerateDiffFile(FileSet fileSet)
       at Microsoft.Exchange.MailboxAssistants.Assistants.OABGenerator.OABGenerator.GenerateDiffFile(OABFile addressListFile, OABFile oldFile)
       at Microsoft.Exchange.MailboxAssistants.Assistants.OABGenerator.OABGenerator.GenerateAddressListFiles(ADObjectId addressList, String habRootLegacyDN)
       at Microsoft.Exchange.MailboxAssistants.Assistants.OABGenerator.OABGenerator.Generate()
       at Microsoft.Exchange.MailboxAssistants.Assistants.OABGenerator.OABGeneratorAssistant.ProcessSingleOAB(MailboxSession mailboxSession, IConfigurationSession perOrgAdSystemConfigSession, OfflineAddressBook oab, SecurityIdentifier mailboxSid, String
    mailboxDomain)
    Exchange Lync Sharepoint

    Hi,
    Do you mean the new Offline Address Book has been set to default and can be updated successfully? And now, the new issue is that send/receive hang on "Offline address book Connecting to Microsoft Exchange" and will never finish. Is it right?
    The following link is a general discussion thread about the same issue. Please refer to it for more helpful suggestions or you can run Test E-mail AutoConfiguration tool and collect some error descriptions to open a new case
    for more troubleshooting.
    http://social.technet.microsoft.com/Forums/exchange/en-US/548f2ecc-faae-4744-8b33-7de536196d7d/sendreceive-hang-on-offline-address-book-connecting-to-microsoft-exchange-and-will-never-finish?forum=exchangesvrgenerallegacy
    Thanks,
    Winnie Liang
    TechNet Community Support

  • Exchange 2013, Event 1012, MSExchangeIS

    Hi,
    on an Exchange 2013 installation I get the following error event reported every 5 minutes:
    ID 1012, Error, Source MSExchangeIS:
    Exchange Server Information Store has encountered an error while executing a full-text index query ("and(or(itemclass:string("IPM.Note*", mode="and"), itemclass:string("IPM.Schedule.Meeting*", mode="and"), itemclass:string("IPM.OCTEL.VOICE*", mode="and"), itemclass:string("IPM.VOICENOTES*", mode="and")), subject:string("SearchQueryStxProbe*", mode="and"), folderid:string("9805D250E52E1C4BAEEF88B84AC1BDFE00000000000E0000"))"). Error information: System.ServiceModel.FaultException`1[System.ServiceModel.ExceptionDetail]: Internal error while processing request (Fault Detail is equal to An ExceptionDetail, likely created by IncludeExceptionDetailInFaults=true, whose value is:
    Microsoft.Ceres.InteractionEngine.Component.ProcessingEngineException: Internal error while processing request
    at Microsoft.Ceres.InteractionEngine.Component.CieProcessingEngine.LogAndRethrowException(Exception e)
    at Microsoft.Ceres.InteractionEngine.Component.CieProcessingEngine.GetItems(Guid flowIdentifier, String outputName)
    at SyncInvokeGetItems(Object , Object[] , Object[] )
    at System.ServiceModel.Dispatcher.SyncMethodInvoker.Invoke(Object instance, Object[] inputs, Object[]& outputs)
    at System.ServiceModel.Dispatcher.DispatchOperationRuntime.InvokeBegin(MessageRpc& rpc)
    at System.ServiceModel.Dispatcher.ImmutableDispatchRuntime.ProcessMessage5(MessageRpc& rpc)
    at System.ServiceModel.Dispatcher.ImmutableDispatchRuntime.ProcessMessage31(MessageRpc& rpc)
    at System.ServiceModel.Dispatcher.MessageRpc.Process(Boolean isOperationContextSet)).
    I do not really have an idea how to approach this and can't find any related information.
    Thanks for your help.

    I'm also getting the same error, tried the solution to no effect.
    Error:
    Exchange Server Information Store has encountered an error while executing a full-text index query ("and(or(itemclass:string("IPM.Note*", mode="and"), itemclass:string("IPM.Schedule.Meeting*", mode="and"), itemclass:string("IPM.OCTEL.VOICE*", mode="and"), itemclass:string("IPM.VOICENOTES*", mode="and")), subject:string("SearchQueryStxProbe*", mode="and"), folderid:string("D6A06323C909134BB77B2FE2114D06EA00000000000E0000"))"). Error information: System.ServiceModel.FaultException`1[System.ServiceModel.ExceptionDetail]: Internal error while processing request (Fault Detail is equal to An ExceptionDetail, likely created by IncludeExceptionDetailInFaults=true, whose value is:
    Microsoft.Ceres.InteractionEngine.Component.ProcessingEngineException: Internal error while processing request
    at Microsoft.Ceres.InteractionEngine.Component.CieProcessingEngine.LogAndRethrowException(Exception e)
    at Microsoft.Ceres.InteractionEngine.Component.CieProcessingEngine.ExecuteSearchFlow(String flowName, IEnumerable`1 inputData)
    at SyncInvokeExecuteSearchFlow(Object , Object[] , Object[] )
    at System.ServiceModel.Dispatcher.SyncMethodInvoker.Invoke(Object instance, Object[] inputs, Object[]& outputs)
    at System.ServiceModel.Dispatcher.DispatchOperationRuntime.InvokeBegin(MessageRpc& rpc)
    at System.ServiceModel.Dispatcher.ImmutableDispatchRuntime.ProcessMessage5(MessageRpc& rpc)
    at System.ServiceModel.Dispatcher.ImmutableDispatchRuntime.ProcessMessage31(MessageRpc& rpc)
    at System.ServiceModel.Dispatcher.MessageRpc.Process(Boolean isOperationContextSet)).
    My ContentIndexState is Unknown.
    I've also noticed this warning in the logs:
    Event 1010, MSExchangeFastSearch
    An operation attempted against a FAST endpoint exprienced an exception. This operation may be retried. Error details: Microsoft.Exchange.Search.Fast.PerformingFastOperationException: An Exception was received during a FAST operation. ---> System.ServiceModel.FaultException: Failed to create operator of type Microsoft.Exchange.Search.OperatorSchema.TransportRetrieverOperator. The operator type is not known to the system.
    Server stack trace:
    at System.ServiceModel.Channels.ServiceChannel.HandleReply(ProxyOperationRuntime operation, ProxyRpc& rpc)
    at System.ServiceModel.Channels.ServiceChannel.Call(String action, Boolean oneway, ProxyOperationRuntime operation, Object[] ins, Object[] outs, TimeSpan timeout)
    at System.ServiceModel.Channels.ServiceChannelProxy.InvokeService(IMethodCallMessage methodCall, ProxyOperationRuntime operation)
    at System.ServiceModel.Channels.ServiceChannelProxy.Invoke(IMessage message)
    Exception rethrown at [0]:
    at System.Runtime.Remoting.Proxies.RealProxy.HandleReturnMessage(IMessage reqMsg, IMessage retMsg)
    at System.Runtime.Remoting.Proxies.RealProxy.PrivateInvoke(MessageData& msgData, Int32 type)
    at Microsoft.Ceres.ContentEngine.Admin.FlowService.IFlowServiceManagementAgent.PutFlow(String name, String serializedFlow)
    at Microsoft.Exchange.Search.Fast.IndexManagementClient.<>c__DisplayClass1.<PerformFastOperation>b__0()
    at Microsoft.Exchange.Search.Fast.IndexManagementClient.PerformFastOperation[T](Func`1 function, String eventLogKey)
    --- End of inner exception stack trace ---
    Help would be much appreciated!

Maybe you are looking for

  • Target coupons will no longer print....error message?

    I get this message when I try to print Target coupons now. I have the latest version of Java. I used to be able to print coupons no problem, but something has changed and I don't know how to fix it. I did figure out that the icon represented in the e

  • Switching airport cards to solve 10.5.2 network issue

    Ever since 10.5.2, i can no longer get online on various routers. my friend who has also updated can get on these same networks that i can't. i have a macbook w/ the following airport card: AirPort Extreme (0x168C, 0x87) Firmware Version: 1.2.2 Wirel

  • Caller ID does not work when calling from Jabber

    We have the following results when doing calls within the company: Desk Phone A (4567-X-Smith): 7801234567 Desk Phone B (4568-Y-Miller): 7801234568 Main Company Line: 7801230000 All desk phones have the following type of configuration: Under the phon

  • Messages Does Not Display Contact Card

    When I message someone or they message me to/from my Messages App on my MBP Messages will not fill in their contact information from my contacts. The only exception to this is when I am messaging someone who uses their email as their iMessage/Message

  • Sync or Sleep – dozing Mac prevents long Apple TV syncs

    *Should iTunes prevent the host Mac going into sleep mode when syncing?* Lengthy syncs between iTunes and my Apple TV are interrupted by my Mac going to sleep. When I wake the laptop, unsurprisingly the sync has stopped. Am I right in thinking that i