Exchange 2013, Event 1012, MSExchangeIS

on an Exchange 2013 installation I get the following error event reported every 5 minutes:
ID 1012, Error, Source MSExchangeIS:
Exchange Server Information Store has encountered an error while executing a full-text index query ("and(or(itemclass:string("IPM.Note*", mode="and"), itemclass:string("IPM.Schedule.Meeting*", mode="and"), itemclass:string("IPM.OCTEL.VOICE*", mode="and"), itemclass:string("IPM.VOICENOTES*", mode="and")), subject:string("SearchQueryStxProbe*", mode="and"), folderid:string("9805D250E52E1C4BAEEF88B84AC1BDFE00000000000E0000"))"). Error information: System.ServiceModel.FaultException`1[System.ServiceModel.ExceptionDetail]: Internal error while processing request (Fault Detail is equal to An ExceptionDetail, likely created by IncludeExceptionDetailInFaults=true, whose value is:
Microsoft.Ceres.InteractionEngine.Component.ProcessingEngineException: Internal error while processing request
at Microsoft.Ceres.InteractionEngine.Component.CieProcessingEngine.LogAndRethrowException(Exception e)
at Microsoft.Ceres.InteractionEngine.Component.CieProcessingEngine.GetItems(Guid flowIdentifier, String outputName)
at SyncInvokeGetItems(Object , Object[] , Object[] )
at System.ServiceModel.Dispatcher.SyncMethodInvoker.Invoke(Object instance, Object[] inputs, Object[]& outputs)
at System.ServiceModel.Dispatcher.DispatchOperationRuntime.InvokeBegin(MessageRpc& rpc)
at System.ServiceModel.Dispatcher.ImmutableDispatchRuntime.ProcessMessage5(MessageRpc& rpc)
at System.ServiceModel.Dispatcher.ImmutableDispatchRuntime.ProcessMessage31(MessageRpc& rpc)
at System.ServiceModel.Dispatcher.MessageRpc.Process(Boolean isOperationContextSet)).
I do not really have an idea how to approach this and can't find any related information.
Thanks for your help.

I'm also getting the same error, tried the solution to no effect.
Exchange Server Information Store has encountered an error while executing a full-text index query ("and(or(itemclass:string("IPM.Note*", mode="and"), itemclass:string("IPM.Schedule.Meeting*", mode="and"), itemclass:string("IPM.OCTEL.VOICE*", mode="and"), itemclass:string("IPM.VOICENOTES*", mode="and")), subject:string("SearchQueryStxProbe*", mode="and"), folderid:string("D6A06323C909134BB77B2FE2114D06EA00000000000E0000"))"). Error information: System.ServiceModel.FaultException`1[System.ServiceModel.ExceptionDetail]: Internal error while processing request (Fault Detail is equal to An ExceptionDetail, likely created by IncludeExceptionDetailInFaults=true, whose value is:
Microsoft.Ceres.InteractionEngine.Component.ProcessingEngineException: Internal error while processing request
at Microsoft.Ceres.InteractionEngine.Component.CieProcessingEngine.LogAndRethrowException(Exception e)
at Microsoft.Ceres.InteractionEngine.Component.CieProcessingEngine.ExecuteSearchFlow(String flowName, IEnumerable`1 inputData)
at SyncInvokeExecuteSearchFlow(Object , Object[] , Object[] )
at System.ServiceModel.Dispatcher.SyncMethodInvoker.Invoke(Object instance, Object[] inputs, Object[]& outputs)
at System.ServiceModel.Dispatcher.DispatchOperationRuntime.InvokeBegin(MessageRpc& rpc)
at System.ServiceModel.Dispatcher.ImmutableDispatchRuntime.ProcessMessage5(MessageRpc& rpc)
at System.ServiceModel.Dispatcher.ImmutableDispatchRuntime.ProcessMessage31(MessageRpc& rpc)
at System.ServiceModel.Dispatcher.MessageRpc.Process(Boolean isOperationContextSet)).
My ContentIndexState is Unknown.
I've also noticed this warning in the logs:
Event 1010, MSExchangeFastSearch
An operation attempted against a FAST endpoint exprienced an exception. This operation may be retried. Error details: Microsoft.Exchange.Search.Fast.PerformingFastOperationException: An Exception was received during a FAST operation. ---> System.ServiceModel.FaultException: Failed to create operator of type Microsoft.Exchange.Search.OperatorSchema.TransportRetrieverOperator. The operator type is not known to the system.
Server stack trace:
at System.ServiceModel.Channels.ServiceChannel.HandleReply(ProxyOperationRuntime operation, ProxyRpc& rpc)
at System.ServiceModel.Channels.ServiceChannel.Call(String action, Boolean oneway, ProxyOperationRuntime operation, Object[] ins, Object[] outs, TimeSpan timeout)
at System.ServiceModel.Channels.ServiceChannelProxy.InvokeService(IMethodCallMessage methodCall, ProxyOperationRuntime operation)
at System.ServiceModel.Channels.ServiceChannelProxy.Invoke(IMessage message)
Exception rethrown at [0]:
at System.Runtime.Remoting.Proxies.RealProxy.HandleReturnMessage(IMessage reqMsg, IMessage retMsg)
at System.Runtime.Remoting.Proxies.RealProxy.PrivateInvoke(MessageData& msgData, Int32 type)
at Microsoft.Ceres.ContentEngine.Admin.FlowService.IFlowServiceManagementAgent.PutFlow(String name, String serializedFlow)
at Microsoft.Exchange.Search.Fast.IndexManagementClient.<>c__DisplayClass1.<PerformFastOperation>b__0()
at Microsoft.Exchange.Search.Fast.IndexManagementClient.PerformFastOperation[T](Func`1 function, String eventLogKey)
--- End of inner exception stack trace ---
Help would be much appreciated!

  • Exchange 2013 Event ID 9646 - MoMT 500 Folder

    I am running Exchange 2013 CU3 and I'm getting an Event ID 9646 in the application event log. Full text below. It would appear it's saying the user is trying to open more than 500 folders but I have looked at her mailbox and while she has a lot of folders,
    it's not over 500. Any suggestions or ideas?
    The description for Event ID 9646 from source MSExchangeIS cannot be found. Either the component that raises this event is not installed on your local computer or the installation is corrupted. You can install or repair the component on the local computer.
    If the event originated on another computer, the display information had to be saved with the event.
    The following information was included with the event:
    the message resource is present but the message is not found in the string/message table

    About event 9646, this could be caused when a MAPI session tried to open more than the maximum number of objects that are allowed for the object type specified in the event description.
    To resolve this issue, please try to modify the registry key and set the "objtFolder" value to 1000 to check the result.
    For more details, please refer to the solution in the following article.
    MSExchangeIS 9646
    Best regards,
    Belinda Ma
    TechNet Community Support

  • Exchange 2013 event ID 36888 SChannel error 12 and 1203

    I am running Windows Server 2012 STD with Exchange 2013 installed on the same server. I know that Microsoft doesnt recommend to do this, but I had no choice. Errors are follow:
    A fatal alert was generated and sent to the remote endpoint. This may result in termination of the connection. The TLS protocol defined fatal error code is 10. The Windows SChannel error state is 12.
    A fatal alert was generated and sent to the remote endpoint. This may result in termination of the connection. The TLS protocol defined fatal error code is 10. The Windows SChannel error state is 1203.
    - System
    - Provider
    [ Name] Schannel
    [ Guid] {1F678132-5938-4686-9FDC-C8FF68F15C85}
    EventID 36888
    Version 0
    Level 2
    Task 0
    Opcode 0
    Keywords 0x8000000000000000
    - TimeCreated
    [ SystemTime] 2014-11-25T23:30:34.120233400Z
    EventRecordID 121125
    - Execution
    [ ProcessID] 1064
    [ ThreadID] 20184
    Channel System
    Computer server
    - Security
    [ UserID] S-1-5-18
    - EventData
    AlertDesc 10
    ErrorState 12
    - Provider
    [ Name] Schannel
    [ Guid] {1F678132-5938-4686-9FDC-C8FF68F15C85}
    EventID 36888
    Version 0
    Level 2
    Task 0
    Opcode 0
    Keywords 0x8000000000000000
    - TimeCreated
    [ SystemTime] 2014-11-26T05:45:22.650086300Z
    EventRecordID 121230
    - Execution
    [ ProcessID] 1064
    [ ThreadID] 45336
    Channel System
    Computer SERVER
    - Security
    [ UserID] S-1-5-18
    - EventData
    AlertDesc 10
    ErrorState 1203
    Process ID 1064 is Isass.exe
    I found somewhere that error 1203 could be ignored, but nothing about error 12. 
    Server is running with selfsigned SAN certificate, hosted 2 exchange domains (10 mailboxes, 5 local, 5 linked for remote domain connected via external 2 way non transitive domain trust).
    Thank you very much for any advise.

    Hi Jan,
    Based on my research for the Event 36888, the issue may be caused by not standard or corrupted behavior of web browsers or users, such as user use HTTP protocol to access Exchange service which is a SSL site on port 443.
    Please check whether there is a HTTP redirect configured in your IIS Manager of Exchange server. Also reset web browsers to have a try. Here are some similar thread for this issue:
    Note: Microsoft is providing this information as a convenience to you. The sites are not controlled by Microsoft. Microsoft cannot make any representations regarding the quality, safety, or suitability of any software or information found there. Please make sure that you completely understand the risk before retrieving any suggestions from the above link.
    sure that you completely understand the risk before retrieving any suggestions from the above link.
    Winnie Liang
    TechNet Community Support

  • Exchange 2013 - Event ID 4999 MS Exchange Common - Watson report about to be sent for process id: 5816

    We have a single Exchange 2013 server and are getting this error many times in a day.  I haven't been able to find a solution and was wondering if anyone came across this error or have any suggestions.
    Edition             : Standard
    AdminDisplayVersion : Version 15.0 (Build 913.22)
    Watson report about to be sent for process id: 5816, with parameters: E12IIS, c-RTL-AMD64, 15.00.0913.022, M.Exchange.Imap4, M.Exchange.Net, M.E.N.NetworkConnection.BeginNegotiateTlsAsClient, System.InvalidOperationException, 99a4, 15.00.0913.007.
    ErrorReportingEnabled: True 

    We have exchange 2013 cu6 mailbox server and we keep getting the below event error message
    Log Name:      Application
    Source:        MSExchange Common
    Date:          10/2/2014 1:06:25 PM
    Event ID:      4999
    Task Category: General
    Level:         Error
    Keywords:      Classic
    User:          N/A
    Watson report about to be sent for process id: 30632, with parameters: E12, c-RTL-AMD64, 15.00.0995.029, M.E.RpcClientAccess.Service, M.E.Data.ApplicationLogic, M.E.D.A.U.HttpPhotoRequestBuilder.Build, System.NotSupportedException, 4e29, 15.00.0995.027.
    ErrorReportingEnabled: True
    Event Xml:
    < Event xmlns="">
        <Provider Name="MSExchange Common" />
        <EventID Qualifiers="16388">4999</EventID>
        <TimeCreated SystemTime="2014-10-02T20:06:25.000000000Z" />
        <Security />
    < /Event>
    Services seem to be fine (Via test-servicehealth), but i do have a group of users that complain that their outlook 2013 email clients will go non-responsive a few times a days. Wondering if this is related. Also this error is appearing every few minutes.
    Anyone else experiencing this?

  • Exchange 2013 Event ID 106 MSExchange Common

    Event ID 106 is generated on Exchange 2013 ,already updated  Perfcounters.ps1 according to this article.still  getting
    same error.
    Log Name:      Application
    Source:        MSExchange Common
    Date:          1/13/2014 8:59:30 PM
    Event ID:      106
    Task Category: General
    Level:         Error
    Keywords:      Classic
    User:          N/A
    Performance counter updating error. Counter name is Time in Resource per second, category name is MSExchange Activity Context Resources. Optional code: 2. Exception: The exception thrown is : System.InvalidOperationException: Instance 'ad-w3wp-msexchangeowaapppool'
    already exists with a lifetime of Process.  It cannot be recreated or reused until it has been removed or until the process using it has exited.
    Processes running while Performance counter failed to update: 
    3148 MSExchangeDelivery
    388 wininit
    1568 SMSvcHost
    8976 w3wp
    2748 conhost
    6292 w3wp
    380 csrss
    3924 MSExchangeFrontendTransport
    768 svchost
    1948 sftracing
    1156 spoolsv
    956 svchost
    7204 w3wp
    752 LogonUI
    2128 noderunner
    3900 MSExchangeSubmission
    8968 w3wp
    1928 ForefrontActiveDirectoryConnector
    1336 taskeng
    7048 w3wp
    348 svchost
    3692 Microsoft.Exchange.EdgeSyncSvc
    4676 Microsoft.Exchange.RpcClientAccess.Service
    4872 MSExchangeMailboxReplication
    340 csrss
    1556 UMWorkerProcess
    8020 w3wp
    3088 Microsoft.Exchange.AntispamUpdateSvc
    1312 MSExchangeHMHost
    7948 w3wp
    424 winlogon
    1500 rundll32
    4448 MSExchangeMailboxAssistants
    900 svchost
    6700 scanningprocess
    504 lsm
    5816 umservice
    4244 Microsoft.Exchange.ServiceHost
    2736 MSExchangeHMWorker
    496 lsass
    1840 vmtoolsd
    1872 noderunner
    488 services
    1396 inetinfo
    680 svchost
    1296 hostcontrollerservice
    7036 w3wp
    1688 noderunner
    1216 svchost
    6740 scanningprocess
    2364 svchost
    1844 svchost
    856 svchost
    4992 conhost
    6760 w3wp
    7816 w3wp
    4196 Microsoft.Exchange.Pop3Service
    2028 updateservice
    1236 fms
    2220 noderunner
    4976 msexchangerepl
    7544 w3wp
    600 svchost
    5364 MSExchangeTransportLogSearch
    2464 WMSvc
    4376 conhost
    1416 Microsoft.Exchange.Diagnostics.Service
    3580 Microsoft.Exchange.Imap4Service
    6336 scanningprocess
    1016 Microsoft.Exchange.Directory.TopologyService
    4364 Microsoft.Exchange.Imap4
    5992 Microsoft.Exchange.UM.CallRouter
    6920 w3wp
    2388 wlms
    5144 MSExchangeThrottling
    808 svchost
    3760 Microsoft.Exchange.Search.Service
    4744 Microsoft.Exchange.Pop3
    248 smss
    2964 WmiPrvSE
    1584 rundll32
    5840 Microsoft.Exchange.Store.Worker
    4 System
    4336 Microsoft.Exchange.Store.Service

    Based on my  research, the issue can be resolved by removing and re-creating all Exchange performance counters:
    add-pssnapin Microsoft.Exchange.Management.PowerShell.Setup
    $files=get-childitem “C:\Program Files\Microsoft\Exchange Server\V15\Setup\Perf\" *.xml |where-object {!($_.psiscontainer)}
    foreach ($file in $files) {remove-perfcounters -definitionfilename  $file.fullname}
    foreach ($file in $files) {new-perfcounters -definitionfilename  $file.fullname}
    For more information, you can refer to the following thread:
    If you have any question, please feel free to let me know.
    Angela Shi
    TechNet Community Support

  • Exchange 2013 Event ID 4999

    I have two exchange servers 2013 both running MB and CAS roles. I also have a DAG on my servers. On one of my servers almost every 7-8 minutes I receive the following error event. Could you please assist me with this?
    Event 4999, MSExchange Common
    Watson report about to be sent for process id: 17084, with parameters: E12IIS, c-RTL-AMD64, 15.00.0995.029, MSExchangeMigrationWorkflow, unknown, M.E.M.L.L.<>c__DisplayClass11.<GetLocalServerData>b__10, System.NullReferenceException, 49af, unknown.
    ErrorReportingEnabled: False 
    Thanks a lot.
    Pooriya Aghaalitari

    DAG Network Automatic configuration may cause the Misconfigured Network sometimes. I recommend you to configure DAG Network manually to solve this problem.
    Please refer to the “DAG Networks” section in the following link.
    Similar thread for reference.
    Hope this will be helpful for you.
    Best Regards.

  • Exchange 2013: Event ID 2937 - MSExchangeSubmission.exe - edgetransport.exe - MSExchangeDelivery.exe - MSExchangeFrontendTransport.exe

    I realise that there are a few threads about this specific ID, but all the solutions are unique to the particular occurrence. Could any of you gentleman or ladies have a look and tell me how to fix it please. Thanks in Advance
    Process MSExchangeFrontendTransport.exe (PID=6120). Object [CN=VSAT-PM Group,OU=Users,OU=Connecting Africa,DC=connectingafrica,DC=local]. Property [ArbitrationMailbox] is set to value [connectingafrica.local/Deleted Objects/SystemMailbox{1f05a927-9036-4018-a6c3-5c29c152f5ac}
    DEL:f068d90d-28c9-4eea-9e5b-e786bb7ff87d], it is pointing to the Deleted Objects container in Active Directory. This property should be fixed as soon as possible.
    Process MSExchangeDelivery.exe (PID=5532). Object [CN=VSAT-PM Group,OU=Users,OU=Connecting Africa,DC=connectingafrica,DC=local]. Property [ArbitrationMailbox] is set to value [connectingafrica.local/Deleted Objects/SystemMailbox{1f05a927-9036-4018-a6c3-5c29c152f5ac}
    DEL:f068d90d-28c9-4eea-9e5b-e786bb7ff87d], it is pointing to the Deleted Objects container in Active Directory. This property should be fixed as soon as possible.
    Process edgetransport.exe (Transport) (PID=15260). Object [CN=VSAT-PM Group,OU=Users,OU=Connecting Africa,DC=connectingafrica,DC=local]. Property [ArbitrationMailbox] is set to value [connectingafrica.local/Deleted Objects/SystemMailbox{1f05a927-9036-4018-a6c3-5c29c152f5ac}
    DEL:f068d90d-28c9-4eea-9e5b-e786bb7ff87d], it is pointing to the Deleted Objects container in Active Directory. This property should be fixed as soon as possible.
    Process MSExchangeSubmission.exe (PID=3888). Object [CN=VSAT-PM Group,OU=Users,OU=Connecting Africa,DC=connectingafrica,DC=local]. Property [ArbitrationMailbox] is set to value [connectingafrica.local/Deleted Objects/SystemMailbox{1f05a927-9036-4018-a6c3-5c29c152f5ac}
    DEL:f068d90d-28c9-4eea-9e5b-e786bb7ff87d], it is pointing to the Deleted Objects container in Active Directory. This property should be fixed as soon as possible.

    First verify that you have all 5 Arbitration Mailboxes with: Get-Mailbox -Arbitration
    The error you see indicates that the database they were on was deleted, possibly in ADSIEdit,and now you have recipients with an old value set. Can't say for sure, but it looks like groups and since they do have an ArbitrationMailbox configured by
    default and to fix them all in one go, just run:
    Get-DistributionGroup -resultsize unlimited | Set-DistributionGroup -ArbitrationMailbox "SystemMailbox{1f05a927*"
    Similar issue here:
    Martina Miskovic

  • MailboxInSiteFailoverException - OWA session error on database *over (Exchange 2013 SP1)

    Hi all, I have noticed an issue with OWA when database(s) are failed over between DAG members.  The environments in question (issue can be reproduced in separate implementations of 2013 SP1 all-role servers) are 2 or more DAG members within the same
    AD site/subnet.  These are also fresh implementations with SP1 and not upgraded.  Exchange servers are load balanced via Netscaler. 
    So to the issue - OWA users experience the below "..MailboxInSiteFailoverException" message when the database copy is activated.  Exchange does not immediately proxy the requests to the active database.  You can wait several minutes and
    the issue is resolved by refreshing the browser or if you recycle the MSExchangeOWAAppPool on both DAG members, the issue is resolved immediately (OWA session re-established on refresh).
    Testing so far involved opening multiple OWA sessions and activating a database copy.  At that point, upon refresh of the browser the below error is shown (in all test browsers/sessions below) where I would expect any DAG member to be able to proxy
    the client request to the active database server immediately (and not after several minutes).

    Hi Simon, I have tested with no firewall on the exchange servers and on client machines within the same subnet as the servers.  All with the same results.
    I can see many ASP.NET 4.0.30319.0 Event ID 1309 logs similar to this and other threads (
    IIS logs show similar monitoring mailbox issues but I am still currently looking through the logs.  Thanks for your input.
    2014-03-30 00:00:23 POST /owa/proxylogon.owa - 444 - Mozilla/4.0+(compatible;+MSIE+9.0;+Windows+NT+6.1;+MSEXCHMON;+ACTIVEMONITORING;+OWADEEPTEST) - 401 0 0 13
    2014-03-30 00:00:23 POST /owa/proxylogon.owa - 444 - Mozilla/4.0+(compatible;+MSIE+9.0;+Windows+NT+6.1;+MSEXCHMON;+ACTIVEMONITORING;+OWADEEPTEST) - 401 0 0 13
    2014-03-30 00:00:23 POST /owa/proxylogon.owa - 444 - Mozilla/4.0+(compatible;+MSIE+9.0;+Windows+NT+6.1;+MSEXCHMON;+ACTIVEMONITORING;+OWADEEPTEST) - 401 1 2148074254 0
    2014-03-30 00:00:23 POST /owa/proxylogon.owa - 444 - Mozilla/4.0+(compatible;+MSIE+9.0;+Windows+NT+6.1;+MSEXCHMON;+ACTIVEMONITORING;+OWADEEPTEST) - 401 1 2148074254 0
    2014-03-30 00:01:23 ::1 POST /owa/proxylogon.owa &ex=UE:Microsoft.Exchange.Data.Storage.IllegalCrossServerConnectionException 444 DOMAIN\SM_3ce57cd622aa4655a ::1 Mozilla/4.0+(compatible;+MSIE+9.0;+Windows+NT+6.1;+MSEXCHMON;+ACTIVEMONITORING;+OWADEEPTEST)
    - 302 0 0 47
    2014-03-30 00:01:23 ::1 POST /owa/proxylogon.owa &ex=UE:Microsoft.Exchange.Data.Storage.IllegalCrossServerConnectionException 444 DOMAIN\SM_2891f9d41af2422e8 ::1 Mozilla/4.0+(compatible;+MSIE+9.0;+Windows+NT+6.1;+MSEXCHMON;+ACTIVEMONITORING;+OWADEEPTEST)
    - 302 0 0 47

  • Object-Owner missing in Public Folder Calenders after Transition to Exchange 2013 SP1

    Hi there,
    we transfered all Public Folders from Exchange 2003 to 2010 to 2013 SP1. We have some Calendars with PublicFolderClientPermission Author witch includes EditOwnedItems and DeleteOwnedItems
    Unfortunately the Author Rights wont work after migration. it seems like the creator of the object got lost.
    since i never notices that in transitions from exchange 2003 to 2010, i think that should be related to the exchange 2013 transition.
    Can anybody approve or disprove that behavior?
    thanks alot

    Noticed now in the Exchange 2013 Event Logs that we're getting quite a few of these warnings:
    "Process <Select one exchange releated process>.exe (PID=<whatever>). Object [CN=Public Folder Database,CN=Databases,CN=Exchange Administrative Group (FYDIBOHF23SPDLT),CN=Administrative Groups,CN=Contoso,CN=Microsoft
    Exchange,CN=Services,CN=Configuration,DC=contoso,DC=local]. Property [PublicFolderDatabase] is set to value [contoso.local/Configuration/Deleted Objects/Public Folder Database
    DEL:ca62a715-05b2-4b08-ae0f-7f7c4b7e4cc3], it is pointing to the Deleted Objects container in Active Directory. This property should be fixed as soon as possible."
    If i take a look at that mailbox database it's obvious that it's pointing towards the old Public Folder Database, which is quite interesting as Exchange 2013 isn't supposed to used that value at all (according to
    [PS] C:\Windows\system32>Get-MailboxDatabase -Identity "Mailbox database" | fl
    PublicFolderDatabase                         : contoso.local/Configuration/Deleted Objects/Public Folder Database
    I'm assuming this is what happens when messing around with ADSIEdit :) So, further ADSIEdits to set that value to null on the existing Mailboxdatabases, or anyone have any other suggestions?

  • Seemingly successful install of Exchange 2013 SP1 turns into many errors in event logs after upgrade to CU7

    I have a new Exchange 2013 server with plans to migrate from my current Exchange 2007 Server. 
    I installed Exchange 2013 SP1 and the only errors I saw in the event log seemed to be long standing known issues that did not indicate an actual problem (based on what I read online). 
    I updated to CU7 and now lots of errors have appeared (although the old ones seem to have been fixed so I have that going for me). 
    Currently the Exchange 2013 server is not in use and clients are still hitting the 2007 server.
    Issue 1)
    After each reboot I get a Kernel-EventTracing 2 error.  I cannot find anything on this on the internet so I have no idea what it is.
    Session "FastDocTracingSession" failed to start with the following error: 0xC0000035
    I did read other accounts of this error with a different name in the quotes but still can’t tell what this is or where it is coming from.
    Issue 2)
    I am still getting 5 MSExchange Common 106 errors even after reregistering all of the perf counters per this page:
    One of the perf counters fails to register using the script from the link above.
    66 C:\Program Files\Microsoft\Exchange Server\V15\Setup\Perf\InfoWorkerMultiMailboxSearchPerformanceCounters.xml
    New-PerfCounters : The performance counter definition file is invalid.
    At C:\Users\administrator.<my domain>\Downloads\script\ReloadPerfCounters.ps1:19 char:4
    +    New-PerfCounters -DefinitionFileName $f
    +    ~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~
        + CategoryInfo         
    : InvalidData: (:) [New-PerfCounters], TaskException
        + FullyQualifiedErrorId : [Server=VALIS,RequestId=71b6bcde-d73e-4c14-9a32-03f06e3b2607,TimeStamp=12/18/2014 10:09:
       12 PM] [FailureCategory=Cmdlet-TaskException] 33EBD286,Microsoft.Exchange.Management.Tasks.NewPerfCounters
    But that one seems unrelated to the ones that still throw errors. 
    Three of the remaining five errors are (the forum is removing my spacing between the error text so it looks like a wall of text - sorry):
    Performance counter updating error. Counter name is Count Matched LowFidelity FingerPrint, but missed HighFidelity FingerPrint, category name is MSExchange Anti-Malware Datacenter Perfcounters. Optional code: 3. Exception: The
    exception thrown is : System.InvalidOperationException: The requested Performance Counter is not a custom counter, it has to be initialized as ReadOnly.
       at System.Diagnostics.PerformanceCounter.InitializeImpl()
       at System.Diagnostics.PerformanceCounter.set_RawValue(Int64 value)
       at Microsoft.Exchange.Diagnostics.ExPerformanceCounter.set_RawValue(Int64 value)
    Last worker process info : System.ArgumentException: Process with an Id of 7384 is not running.
       at System.Diagnostics.Process.GetProcessById(Int32 processId)
       at Microsoft.Exchange.Diagnostics.ExPerformanceCounter.GetLastWorkerProcessInfo()
    Performance counter updating error. Counter name is Number of items, item is matched with finger printing cache, category name is MSExchange Anti-Malware Datacenter Perfcounters. Optional code: 3. Exception: The exception thrown
    is : System.InvalidOperationException: The requested Performance Counter is not a custom counter, it has to be initialized as ReadOnly.
       at System.Diagnostics.PerformanceCounter.InitializeImpl()
       at System.Diagnostics.PerformanceCounter.set_RawValue(Int64 value)
       at Microsoft.Exchange.Diagnostics.ExPerformanceCounter.set_RawValue(Int64 value)
    Last worker process info : System.ArgumentException: Process with an Id of 7384 is not running.
       at System.Diagnostics.Process.GetProcessById(Int32 processId)
       at Microsoft.Exchange.Diagnostics.ExPerformanceCounter.GetLastWorkerProcessInfo()
    Performance counter updating error. Counter name is Number of items in Malware Fingerprint cache, category name is MSExchange Anti-Malware Datacenter Perfcounters. Optional code: 3. Exception: The exception thrown is : System.InvalidOperationException:
    The requested Performance Counter is not a custom counter, it has to be initialized as ReadOnly.
       at System.Diagnostics.PerformanceCounter.InitializeImpl()
       at System.Diagnostics.PerformanceCounter.set_RawValue(Int64 value)
       at Microsoft.Exchange.Diagnostics.ExPerformanceCounter.set_RawValue(Int64 value)
    Last worker process info : System.ArgumentException: Process with an Id of 7384 is not running.
       at System.Diagnostics.Process.GetProcessById(Int32 processId)
       at Microsoft.Exchange.Diagnostics.ExPerformanceCounter.GetLastWorkerProcessInfo()
    Issue 3)
    I appear to have some issues related to the healthmailboxes. 
    I get MSExchangeTransport 1025 errors for multiple healthmailboxes.
    SMTP rejected a (P1) mail from 'HealthMailbox23b10b91745648819139ee691dc97eb6@<my domain>.local' with 'Client Proxy <my server>' connector and the user authenticated as 'HealthMailbox23b10b91745648819139ee691dc97eb6'. The Active Directory
    lookup for the sender address returned validation errors. Microsoft.Exchange.Data.ProviderError
    I reran setup /prepareAD to try and remedy this but I am still getting some.
    Issue 4)
    I am getting an MSExchange RBAC 74 error. 
    (Process w3wp.exe, PID 984) Connection leak detected for key <my domain>.local/Admins/Administrator in Microsoft.Exchange.Configuration.Authorization.WSManBudgetManager class. Leaked Value 1.
    Issue 5)
    I am getting MSExchange Assistants 9042 warnings on both databases.
    Service MSExchangeMailboxAssistants. Probe Time Based Assistant for database Database02 (c83dbd91-7cc4-4412-912e-1b87ca6eb0ab) is exiting a work cycle. No mailboxes were successfully processed. 2 mailboxes were skipped due to errors. 0 mailboxes were
    skipped due to failure to open a store session. 0 mailboxes were retried. There are 0 mailboxes in this database remaining to be processed.
    Some research suggested this may be related to deleted mailboxes however I have never had any actual user mailboxes on this server. 
    If they are healthmailboxes or arbitration mailboxes that might make sense but I am unsure of what to do on this.
    Issue 6)
    At boot I am getting an MSExchange ActiveSync warning 1033
    The setting SupportedIPMTypes in the Web.Config file was missing. 
    Using default value of System.Collections.Generic.List`1[System.String].
    I don't know why but this forum is removing some of my spacing that would make parts of this easier to read.

    Hi Eric
    Yes I have uninstalled and reinstalled Exchange 2013 CU7 for the 3<sup>rd</sup> time. 
    I realize you said one issue per forum thread but since I already started this thread with many issues I will at least post what I have discovered on them in case someone finds their way here from a web search.
    I have an existing Exchange 2007 server in the environment so I am unable to create email address policies that are defined by “recipient container”. 
    If I try and do so I get “You can't specify the recipient container because legacy servers are detected.”
     So I cannot create a normal email address policy and restrict it to an OU without resorting to some fancy filtering. 
    Instead what I have done is use PS to modify extensionAttribute1 (otherwise known as Custom Attribute 1 to exchange) for all of my users. 
    I then applied an address policy to them and gave it the highest priority. 
    Then I set a default email address policy for the entire organization. 
    After reinstalling Exchange all of my system mailboxes were created with the internal domain name. 
    So issue number 3 above has not come up. 
    For issue number one above I have created a new thread:
    For issue number four I have posted to this existing thread where there is so far no resolution:
    Issue number Five I have managed to recreate and get rid of in more than one way. 
    If I create a new database in ECP and set the database and log paths where I want, then this error will appear. 
    If I create the database in the default location and then use EMS to move it and set the log path, then the error will not appear. 
    The error will also appear (along with other errors) if I delete the health mailboxes and let them get recreated by restarting the server or the Health Manager service. 
    If I then go and set the retention period for deleted mailboxes to 0 days and wait a little while, these will all go away. 
    So my off hand guess is that these are caused by orphaned system mailboxes.
    For issue number six I have posted to this existing thread where there is so far no resolution:
    So for the remainder of this thread we can try and tackle issue number two which is the perf counters. 
    The exact same 5 perf counter were coming up and this had been true each time I have uninstalled and reinstalled Exchange 2013CU7. 
    Actually to be more accurate a LOT of perf counter errors come up after the initial install, but reloading the perf counters using the script I posted above reduces it to the same five. 
    Using all of your suggestions so far has not removed these 5 remaining errors either.  Since there is no discernible impact other than these errors at boot I am not seriously bothered by them but as will all event log errors, I would prefer
    to make them go away if possible.

  • In exchange 2013 sp1 SUBMITFAIL event id is happening

    Hi ,
    In exchange 2013 sp1 SUBMITFAIL event id is happening for some messages .But at the second time that the same message is delivered perfectly to the end users.
    My question is simple ,is this an bug in exchange 2013 sp1 if so on which CU it will be corrected ?We have to update to our customers so all of us please provide your suggestions as soon as possible.
    Thanks & Regards S.Nithyanandham

    Hi Allen Wang ,
    Thanks a lot for your response.
    Which version are you used? Is this issue arise after install update for Exchange server? 
    We are using exchange 2013 sp1 Ent edition.This issue is been existing in my environment when we start to use exchange 2013 and it is not from sp1 .
    Also, what your means of “second time”, server retry to send or send failed then user click to resend?
    When an user send an email for the first time to some of the recipient's it is reaching only to the few recipient's mailboxes and the email to the remaining recipients gets failed with the event ID "SUBMITFAIL" on the message tracking log.
    Same time if we forward that same message to the failed recipients it went and delivered successfully.
    Note : Apart from message tracking log i didn't found anything helpful in protocol and event viewer logs.
    Below link is for your Reference :
    Above is the link which is saying that this issue will be resolved in exchange 2013 sp1 and also it says it an bug in exchange 2013 CU3 .But still on my end the problems occurs in exchange 2013 CU3 as well as in exchange 2013 SP1.
    Please help me out yaar this issue is raising in my production environment.
    Thanks & Regards S.Nithyanandham

  • Event ID 2142, 2077, 2069 MSExchangeADTopology Exchange 2013

    I have just inherited a slightly abused new server as part of my job and it looks like the previous admin was using a live single domain as a test bed.
    From what I have been able to determine this windows 2008R2 server started life as a single name domain (no FQDN) that had exchange 2013 running on it (sin I know).  A domain rename was performed and from what I can tell it did change the domain name to
    a FQDN environment.  (it went for COMPANY to COMPANY.COM)
    I have been able to clean up most of the other ghosts in the machine except when it comes to exchange.  I get event ID 2142(error), 2077 (info), and 2069 (info) repeatedly it cycles every 2 minutes:
    Log Name:      Application
    Source:        MSExchangeADTopology
    Date:          4/18/2013 11:42:39 AM
    Event ID:      2142
    Task Category: Topology
    Level:         Error
    Keywords:      Classic
    User:          N/A
    Computer:      SERVER2013.COMPANY
    Process Microsoft.Exchange.Directory.TopologyService.exe (PID=13460) Forest Topology discovery failed, error details
    No Suitable Directory Servers Found in Forest Site Default-First-Site-Name..
    Event Xml:
    <Event xmlns="">
        <Provider Name="MSExchangeADTopology" />
        <EventID Qualifiers="49156">2142</EventID>
        <TimeCreated SystemTime="2013-04-18T16:42:39.000000000Z" />
        <Security />
        <Data>No Suitable Directory Servers Found in Forest Site Default-First-Site-Name.</Data>
    Log Name:      Application
    Source:        MSExchangeADTopology
    Date:          4/18/2013 11:42:39 AM
    Event ID:      2077
    Task Category: Topology
    Level:         Information
    Keywords:      Classic
    User:          N/A
    Computer:      SERVER2013.COMPANY
    Process Microsoft.Exchange.Directory.TopologyService.exe (PID=13460) Forest Exchange Active Directory Provider could not find any suitable domain controller servers in either the local site 'Default-First-Site-Name' or the following sites:
    Event Xml:
    <Event xmlns="">
        <Provider Name="MSExchangeADTopology" />
        <EventID Qualifiers="16388">2077</EventID>
        <TimeCreated SystemTime="2013-04-18T16:42:39.000000000Z" />
        <Security />
    Log Name:      Application
    Source:        MSExchangeADTopology
    Date:          4/18/2013 11:42:39 AM
    Event ID:      2069
    Task Category: Topology
    Level:         Information
    Keywords:      Classic
    User:          N/A
    Computer:      SERVER2013.COMPANY
    Process Microsoft.Exchange.Directory.TopologyService.exe (PID=13460) Forest Exchange Active Directory Provider couldn't find any suitable Global Catalog servers in either the local site 'Default-First-Site-Name' or the following sites:
    Event Xml:
    <Event xmlns="">
        <Provider Name="MSExchangeADTopology" />
        <EventID Qualifiers="16388">2069</EventID>
        <TimeCreated SystemTime="2013-04-18T16:42:39.000000000Z" />
        <Security />
    It looks to me that exchange is still looking for the old domain name.  Does anyone know how to point it to the correct domain name?
    Exchange is currently down and I am unable to log into EAC, OWA or Exchange Management Powershell.  I am also unable to un-install exchange as it is reporting active mailboxes and I can't delete them because I am unable to log in.
    My overall goal is to remove exchange from this server and put it on a separate server but until I can get exchange working to a point where I can remove the mailboxes, I am stuck.
    Any and all help appreciated.

    Thank you for your advise on correcting my issue.  I created the subnet and assigned it to the Default-First-Site-Name as there weren't any subnets listed.
    Upon reboot I checked the event log and I am still receiving the event log entries as above; however, I am now receiving a few new errors along with them and they are repeating (4027 error and 3176 action).  Here are the additional errors:
    Log Name:      Application
    Source:        MSExchange ADAccess
    Date:          4/22/2013 9:52:48 AM
    Event ID:      4027
    Task Category: General
    Level:         Error
    Keywords:      Classic
    User:          N/A
    Computer:      SERVER2013.COMPANY
    Process msexchangerepl.exe (PID=8016). WCF request (Get Servers for to the Microsoft Exchange Active Directory Topology service on server (TopologyClientTcpEndpoint (localhost)) failed. Make sure that the service is running. In addition, make sure
    that the network ports that are used by Microsoft Exchange Active Directory Topology service are not blocked by a firewall. The WCF call was retried 3 time(s). Error Details
     An error occurred during forest discovery ( ----> No Suitable Directory Servers Found in Forest Site Default-First-Site-Name.
       at Microsoft.Exchange.Directory.TopologyService.ADTopologyDiscovery.Discover()
       at Microsoft.Exchange.Directory.TopologyService.ADTopologyDiscovery.DoWork(CancellationToken cancellationToken)
       at Microsoft.Exchange.Directory.TopologyService.Common.WorkItem`1.Execute(CancellationToken joinedToken)
       at Microsoft.Exchange.Directory.TopologyService.Common.WorkItem`1.<>c__DisplayClass6.<StartExecuting>b__4()
       at System.Threading.Tasks.Task.Execute()
       at Microsoft.Exchange.Directory.TopologyService.Common.Extensions.WrapAndRethrowException(Exception exception, LocalizedString errorMessage)
       at Microsoft.Exchange.Directory.TopologyService.TopologyDiscoveryManager.EndGetTopology(IAsyncResult ar)
       at Microsoft.Exchange.Directory.TopologyService.TopologyService.InternalEndGetServersForRole(IAsyncResult result)
       at Microsoft.Exchange.Directory.TopologyService.TopologyService.<>c__DisplayClassa.<EndGetServersForRole>b__9()
       at Microsoft.Exchange.Directory.TopologyService.TopologyService.ExecuteServiceCall(Action action)
    Log Name:      Application
    Source:        MSExchangeRepl
    Date:          4/22/2013 9:52:48 AM
    Event ID:      3176
    Task Category: Action
    Level:         Error
    Keywords:      Classic
    User:          N/A
    Computer:      SERVER2013.COMPANY
    The Microsoft Exchange Replication service attempted to start the Active Manager RPC server but failed because an error occurred when attempting to read the Exchange Servers universal security group SID from Active Directory. Error:
    The call to Microsoft Exchange Active Directory Topology service on server 'TopologyClientTcpEndpoint (localhost)' returned an error. Error details An error occurred during forest discovery (
    Log Name:      Application
    Source:        MSExchange ADAccess
    Date:          4/22/2013 9:52:48 AM
    Event ID:      4027
    Task Category: General
    Level:         Error
    Keywords:      Classic
    User:          N/A
    Computer:      SERVER2013.COMPANY
    Process MSExchangeSubmission.exe (PID=10708). WCF request (Get Servers for to the Microsoft Exchange Active Directory Topology service on server (TopologyClientTcpEndpoint (localhost)) failed. Make sure that the service is running. In addition,
    make sure that the network ports that are used by Microsoft Exchange Active Directory Topology service are not blocked by a firewall. The WCF call was retried 3 time(s). Error Details
     An error occurred during forest discovery ( ----> No Suitable Directory Servers Found in Forest Site Default-First-Site-Name.
       at Microsoft.Exchange.Directory.TopologyService.ADTopologyDiscovery.Discover()
       at Microsoft.Exchange.Directory.TopologyService.ADTopologyDiscovery.DoWork(CancellationToken cancellationToken)
       at Microsoft.Exchange.Directory.TopologyService.Common.WorkItem`1.Execute(CancellationToken joinedToken)
       at Microsoft.Exchange.Directory.TopologyService.Common.WorkItem`1.<>c__DisplayClass6.<StartExecuting>b__4()
       at System.Threading.Tasks.Task.Execute()
       at Microsoft.Exchange.Directory.TopologyService.Common.Extensions.WrapAndRethrowException(Exception exception, LocalizedString errorMessage)
       at Microsoft.Exchange.Directory.TopologyService.TopologyDiscoveryManager.EndGetTopology(IAsyncResult ar)
       at Microsoft.Exchange.Directory.TopologyService.TopologyService.InternalEndGetServersForRole(IAsyncResult result)
       at Microsoft.Exchange.Directory.TopologyService.TopologyService.<>c__DisplayClassa.<EndGetServersForRole>b__9()
       at Microsoft.Exchange.Directory.TopologyService.TopologyService.ExecuteServiceCall(Action action)

  • Exchange 2013 OWA,Async,And OA error MsExchange BackEndRehydration event id 3002

    Hi team,
    I had issue in My Exchange system.
    I had two Exchange 2013 muli role with CAS and MBX
    Server A had no problem connection when client access OWA directly (https://servernamefqdn/owa)
    but, theres issue when I pointing to server B OWA (https://serverBfqdn/owa). its same when outlook connect (using OA ),and Aysnc connection.
    when I failed to connect OWA, theres event id 3002 MsExchange BackEndRehydration event id 3002.
    the error show at Server A ( server at a good condition )
    heres the error

    Hello Team,
    I have a similar issue with Event ID 3002 filling up the App log on both Mailbox servers.  Here is a snippet of the error.  Any help is greatly appreciated.  Thank you.
    "Protocol /EWS failed to process request from identity DOMAIN\CASServer. Exception: Microsoft.Exchange.Security.OAuth.InvalidOAuthTokenException: The user specified by the user-context in the token is ambiguous.
       at Microsoft.Exchange.Security.OAuth.OAuthActAsUser.InternalCreateFromAttributes(OrganizationId organizationId, Boolean calledAtFrontEnd, Dictionary`2 rawAttributes, Dictionary`2 verifiedAttributes)
       at Microsoft.Exchange.Security.Authentication.BackendAuthenticator.OAuthAuthenticator.ExtractActAsUser(OrganizationId organizationId, CommonAccessToken token)
       at Microsoft.Exchange.Security.Authentication.BackendAuthenticator.OAuthAuthenticator.InternalRehydrate(CommonAccessToken token, Boolean wantAuthIdentifier, String& authIdentifier, IPrincipal& principal)
       at Microsoft.Exchange.Security.Authentication.BackendAuthenticator.Rehydrate(CommonAccessToken token, BackendAuthenticator& authenticator, Boolean wantAuthIdentifier, String& authIdentifier, IPrincipal& principal, IAccountValidationContext&
       at Microsoft.Exchange.Security.Authentication.BackendRehydrationModule.ProcessRequest(HttpContext httpContext)
       at Microsoft.Exchange.Security.Authentication.BackendRehydrationModule.OnAuthenticateRequest(Object source, EventArgs args).

  • Exchange 2013 and SCOM False Events

    We are having many problems with the health monitoring of exchange in our SCOM 2012 environment. We have 9 exchange servers, with 3 DAGS across the 9 servers. WE are constantly getting health events in SCOM, even for monitors i've explicitly disabled. For
    example, the FIPS monitor. Following this guide ( i disabled the FIPS probes/monitors all together across our entire Exchange environment, and yet in SCOM, all 9 servers
    show this monitor as being unhealthy. Is my understanding on this functionality incorrect, or is it just not functioning properly?
    Similarly, even when an Exchange monitor is completely healthy, it shows as unhealthy in SCOM. Right now, HubTransport shows as unhealthy in SCOM For all our Exchange servers, but when i run this command everything shows as healthy, across all servers.
    Get-ServerHealth <server name> | ?{$_.HealthSetName -eq "HubTransport"}
    I understand that these monitors can be unhealthy for a while and correct themselves, but shouldn't that correct them in SCOM as well? And for disabled monitors, like FIPS, they should never be unhealthy at all. So why are they showing as unhealthy in SCOM?
    Am i expected to reset health in SCOM every time an unhealthy flag is thrown in Exchange?
    From what i've seen there is a huge discrepancy between how SCOM works and how Exchange monitors work. They don't seem to integrate well, at all. Does anyone have any suggestions on getting Exchange 2013 monitors to work properly in SCOM? Is this my error
    as a user, or is it just bad software

    I recommend you use the Get-HealthReport cmdlet to check Exchange Server health again.
    What's more, please verify if the account you use has the Organization Management permission and Server Management permission. Also, you can change an account and see the result.
    Moreover, please take your time to post the unhealthy information from SCOM monitor about Exchange server for my further research.
    Hope my clarification is helpful.
    If there is any update, please feel free to let me know.
    Best regards,
    Amy Wang
    TechNet Community Support

  • Exchange 2013 Critical Search event 2158 with event 1006

    I'm running Exchange 2013 CU1.  I've noticed in the event logs two errors that continuously keep popping up relating to searching.  Actual searching of mail seems fine and the mail databases are in a healthy state.
    Event ID 2158 Unified logging service
    Event 20 (Search) of severity 'Critical' occurred 11 more time(s) and was suppressed in the event log
    Event ID 1006 General
    The FastFeeder component received a connection exception from FAST. Error details: Microsoft.Exchange.Search.Fast.FastConnectionException: Connection to the Content Submission Service has failed. ---> Microsoft.Ceres.External.ContentApi.ConnectionException:
    Recovery failed after 0 retries
       at Microsoft.Ceres.External.ContentApi.DocumentFeeder.DocumentFeeder.CheckRecoveryFailed()
       at Microsoft.Ceres.External.ContentApi.DocumentFeeder.DocumentFeeder.WaitForAvailable()
       at Microsoft.Ceres.External.ContentApi.DocumentFeeder.DocumentFeeder.SubmitDocument(Document document, TimeSpan timeout)
       at Microsoft.Ceres.External.ContentApi.DocumentFeeder.DocumentFeeder.SubmitDocument(Document document)
       at Microsoft.Exchange.Search.Fast.FastFeeder.SubmitDocumentInternal(Object state)
       --- End of inner exception stack trace ---

    Please take your time to apply the latest CU and see whether the issue fixes.
    Simon Wu
    TechNet Community Support

Maybe you are looking for