Exchange 2013: Event ID 2937 - MSExchangeSubmission.exe - edgetransport.exe - MSExchangeDelivery.exe - MSExchangeFrontendTransport.exe

Hi
I realise that there are a few threads about this specific ID, but all the solutions are unique to the particular occurrence. Could any of you gentleman or ladies have a look and tell me how to fix it please. Thanks in Advance
Process MSExchangeFrontendTransport.exe (PID=6120). Object [CN=VSAT-PM Group,OU=Users,OU=Connecting Africa,DC=connectingafrica,DC=local]. Property [ArbitrationMailbox] is set to value [connectingafrica.local/Deleted Objects/SystemMailbox{1f05a927-9036-4018-a6c3-5c29c152f5ac}
DEL:f068d90d-28c9-4eea-9e5b-e786bb7ff87d], it is pointing to the Deleted Objects container in Active Directory. This property should be fixed as soon as possible.
Process MSExchangeDelivery.exe (PID=5532). Object [CN=VSAT-PM Group,OU=Users,OU=Connecting Africa,DC=connectingafrica,DC=local]. Property [ArbitrationMailbox] is set to value [connectingafrica.local/Deleted Objects/SystemMailbox{1f05a927-9036-4018-a6c3-5c29c152f5ac}
DEL:f068d90d-28c9-4eea-9e5b-e786bb7ff87d], it is pointing to the Deleted Objects container in Active Directory. This property should be fixed as soon as possible.
Process edgetransport.exe (Transport) (PID=15260). Object [CN=VSAT-PM Group,OU=Users,OU=Connecting Africa,DC=connectingafrica,DC=local]. Property [ArbitrationMailbox] is set to value [connectingafrica.local/Deleted Objects/SystemMailbox{1f05a927-9036-4018-a6c3-5c29c152f5ac}
DEL:f068d90d-28c9-4eea-9e5b-e786bb7ff87d], it is pointing to the Deleted Objects container in Active Directory. This property should be fixed as soon as possible.
Process MSExchangeSubmission.exe (PID=3888). Object [CN=VSAT-PM Group,OU=Users,OU=Connecting Africa,DC=connectingafrica,DC=local]. Property [ArbitrationMailbox] is set to value [connectingafrica.local/Deleted Objects/SystemMailbox{1f05a927-9036-4018-a6c3-5c29c152f5ac}
DEL:f068d90d-28c9-4eea-9e5b-e786bb7ff87d], it is pointing to the Deleted Objects container in Active Directory. This property should be fixed as soon as possible.

Hi,
First verify that you have all 5 Arbitration Mailboxes with: Get-Mailbox -Arbitration
The error you see indicates that the database they were on was deleted, possibly in ADSIEdit,and now you have recipients with an old value set. Can't say for sure, but it looks like groups and since they do have an ArbitrationMailbox configured by
default and to fix them all in one go, just run:
Get-DistributionGroup -resultsize unlimited | Set-DistributionGroup -ArbitrationMailbox "SystemMailbox{1f05a927*"
Similar issue here:
http://social.technet.microsoft.com/Forums/exchange/en-US/4378e410-c2c5-47a9-abc2-eb2926ff40da/the-recipient-is-configured-to-use-arbitration-mailbox-but-that-mailbox-has-been-deleted?forum=exchange2010
Martina Miskovic

Similar Messages

  • Exchange 2013 event ID 36888 SChannel error 12 and 1203

    I am running Windows Server 2012 STD with Exchange 2013 installed on the same server. I know that Microsoft doesnt recommend to do this, but I had no choice. Errors are follow:
    A fatal alert was generated and sent to the remote endpoint. This may result in termination of the connection. The TLS protocol defined fatal error code is 10. The Windows SChannel error state is 12.
    A fatal alert was generated and sent to the remote endpoint. This may result in termination of the connection. The TLS protocol defined fatal error code is 10. The Windows SChannel error state is 1203.
    - System
    - Provider
    [ Name] Schannel
    [ Guid] {1F678132-5938-4686-9FDC-C8FF68F15C85}
    EventID 36888
    Version 0
    Level 2
    Task 0
    Opcode 0
    Keywords 0x8000000000000000
    - TimeCreated
    [ SystemTime] 2014-11-25T23:30:34.120233400Z
    EventRecordID 121125
    Correlation
    - Execution
    [ ProcessID] 1064
    [ ThreadID] 20184
    Channel System
    Computer server
    - Security
    [ UserID] S-1-5-18
    - EventData
    AlertDesc 10
    ErrorState 12
    System
    - Provider
    [ Name] Schannel
    [ Guid] {1F678132-5938-4686-9FDC-C8FF68F15C85}
    EventID 36888
    Version 0
    Level 2
    Task 0
    Opcode 0
    Keywords 0x8000000000000000
    - TimeCreated
    [ SystemTime] 2014-11-26T05:45:22.650086300Z
    EventRecordID 121230
    Correlation
    - Execution
    [ ProcessID] 1064
    [ ThreadID] 45336
    Channel System
    Computer SERVER
    - Security
    [ UserID] S-1-5-18
    - EventData
    AlertDesc 10
    ErrorState 1203
    Process ID 1064 is Isass.exe
    I found somewhere that error 1203 could be ignored, but nothing about error 12. 
    Server is running with selfsigned SAN certificate, hosted 2 exchange domains (10 mailboxes, 5 local, 5 linked for remote domain connected via external 2 way non transitive domain trust).
    Thank you very much for any advise.
    Regards,
    Jan
    Šerý

    Hi Jan,
    Based on my research for the Event 36888, the issue may be caused by not standard or corrupted behavior of web browsers or users, such as user use HTTP protocol to access Exchange service which is a SSL site on port 443.
    Please check whether there is a HTTP redirect configured in your IIS Manager of Exchange server. Also reset web browsers to have a try. Here are some similar thread for this issue:
    https://social.technet.microsoft.com/Forums/forefront/en-US/92c63737-c2a3-41f7-8878-3b0cf5ee95ff/new-install-event-log-schannel-event-id-36888?forum=Forefrontedgegeneral
    http://ficility.net/2013/10/21/exchange-2013-exchange-2010-windows-server-2012-schannel-event-id36888-1203-tlsssl-error-the-root-cause/
    Note: Microsoft is providing this information as a convenience to you. The sites are not controlled by Microsoft. Microsoft cannot make any representations regarding the quality, safety, or suitability of any software or information found there. Please make
    sure that you completely understand the risk before retrieving any suggestions from the above link.
    Regards,
    Winnie Liang
    TechNet Community Support

  • Exchange 2013 Event ID 106 MSExchange Common

    Event ID 106 is generated on Exchange 2013 ,already updated  Perfcounters.ps1 according to this article.still  getting
    same error.
    http://support.microsoft.com/kb/2870416/en-us
    Log Name:      Application
    Source:        MSExchange Common
    Date:          1/13/2014 8:59:30 PM
    Event ID:      106
    Task Category: General
    Level:         Error
    Keywords:      Classic
    User:          N/A
    Computer:      DC4.chickbuns.com
    Description:
    Performance counter updating error. Counter name is Time in Resource per second, category name is MSExchange Activity Context Resources. Optional code: 2. Exception: The exception thrown is : System.InvalidOperationException: Instance 'ad-w3wp-msexchangeowaapppool'
    already exists with a lifetime of Process.  It cannot be recreated or reused until it has been removed or until the process using it has exited.
    Processes running while Performance counter failed to update: 
    3148 MSExchangeDelivery
    388 wininit
    1568 SMSvcHost
    8976 w3wp
    2748 conhost
    6292 w3wp
    380 csrss
    3924 MSExchangeFrontendTransport
    768 svchost
    1948 sftracing
    1156 spoolsv
    956 svchost
    7204 w3wp
    752 LogonUI
    2128 noderunner
    3900 MSExchangeSubmission
    8968 w3wp
    1928 ForefrontActiveDirectoryConnector
    1336 taskeng
    7048 w3wp
    348 svchost
    3692 Microsoft.Exchange.EdgeSyncSvc
    4676 Microsoft.Exchange.RpcClientAccess.Service
    4872 MSExchangeMailboxReplication
    340 csrss
    1556 UMWorkerProcess
    8020 w3wp
    3088 Microsoft.Exchange.AntispamUpdateSvc
    1312 MSExchangeHMHost
    7948 w3wp
    424 winlogon
    1500 rundll32
    4448 MSExchangeMailboxAssistants
    900 svchost
    6700 scanningprocess
    504 lsm
    5816 umservice
    4244 Microsoft.Exchange.ServiceHost
    2736 MSExchangeHMWorker
    496 lsass
    1840 vmtoolsd
    1872 noderunner
    488 services
    1396 inetinfo
    680 svchost
    1296 hostcontrollerservice
    7036 w3wp
    1688 noderunner
    1216 svchost
    6740 scanningprocess
    2364 svchost
    1844 svchost
    856 svchost
    4992 conhost
    6760 w3wp
    7816 w3wp
    4196 Microsoft.Exchange.Pop3Service
    2028 updateservice
    1236 fms
    2220 noderunner
    4976 msexchangerepl
    7544 w3wp
    600 svchost
    5364 MSExchangeTransportLogSearch
    2464 WMSvc
    4376 conhost
    1416 Microsoft.Exchange.Diagnostics.Service
    3580 Microsoft.Exchange.Imap4Service
    6336 scanningprocess
    1016 Microsoft.Exchange.Directory.TopologyService
    4364 Microsoft.Exchange.Imap4
    5992 Microsoft.Exchange.UM.CallRouter
    6920 w3wp
    2388 wlms
    5144 MSExchangeThrottling
    808 svchost
    3760 Microsoft.Exchange.Search.Service
    4744 Microsoft.Exchange.Pop3
    248 smss
    2964 WmiPrvSE
    1584 rundll32
    5840 Microsoft.Exchange.Store.Worker
    4 System
    4336 Microsoft.Exchange.Store.Service

    Hi,
    Based on my  research, the issue can be resolved by removing and re-creating all Exchange performance counters:
    add-pssnapin Microsoft.Exchange.Management.PowerShell.Setup
    $files=get-childitem “C:\Program Files\Microsoft\Exchange Server\V15\Setup\Perf\" *.xml |where-object {!($_.psiscontainer)}
    foreach ($file in $files) {remove-perfcounters -definitionfilename  $file.fullname}
    foreach ($file in $files) {new-perfcounters -definitionfilename  $file.fullname}
    For more information, you can refer to the following thread:
    http://social.technet.microsoft.com/Forums/exchange/en-US/a8e35d2a-5e09-4ec5-b5c8-43554d3b8b78/lots-of-errors-106-msexchange-common?forum=exchangesvradmin
    If you have any question, please feel free to let me know.
    Thanks, 
    Angela Shi
    TechNet Community Support

  • Exchange 2013 Event ID 9646 - MoMT 500 Folder

    Hello,
    I am running Exchange 2013 CU3 and I'm getting an Event ID 9646 in the application event log. Full text below. It would appear it's saying the user is trying to open more than 500 folders but I have looked at her mailbox and while she has a lot of folders,
    it's not over 500. Any suggestions or ideas?
    Thanks,
    Brad
    The description for Event ID 9646 from source MSExchangeIS cannot be found. Either the component that raises this event is not installed on your local computer or the installation is corrupted. You can install or repair the component on the local computer.
    If the event originated on another computer, the display information had to be saved with the event.
    The following information was included with the event:
    /O=xxxxx/OU=xxxxx/cn=Recipients/cn=JRoberts
    MoMT
    500
    Folder
    the message resource is present but the message is not found in the string/message table
    BradG87

    Hi,
    About event 9646, this could be caused when a MAPI session tried to open more than the maximum number of objects that are allowed for the object type specified in the event description.
    To resolve this issue, please try to modify the registry key and set the "objtFolder" value to 1000 to check the result.
    For more details, please refer to the solution in the following article.
    MSExchangeIS 9646
    http://technet.microsoft.com/library/ff980641.aspx
    Best regards,
    Belinda
    Belinda Ma
    TechNet Community Support

  • Exchange 2013, Event 1012, MSExchangeIS

    Hi,
    on an Exchange 2013 installation I get the following error event reported every 5 minutes:
    ID 1012, Error, Source MSExchangeIS:
    Exchange Server Information Store has encountered an error while executing a full-text index query ("and(or(itemclass:string("IPM.Note*", mode="and"), itemclass:string("IPM.Schedule.Meeting*", mode="and"), itemclass:string("IPM.OCTEL.VOICE*", mode="and"), itemclass:string("IPM.VOICENOTES*", mode="and")), subject:string("SearchQueryStxProbe*", mode="and"), folderid:string("9805D250E52E1C4BAEEF88B84AC1BDFE00000000000E0000"))"). Error information: System.ServiceModel.FaultException`1[System.ServiceModel.ExceptionDetail]: Internal error while processing request (Fault Detail is equal to An ExceptionDetail, likely created by IncludeExceptionDetailInFaults=true, whose value is:
    Microsoft.Ceres.InteractionEngine.Component.ProcessingEngineException: Internal error while processing request
    at Microsoft.Ceres.InteractionEngine.Component.CieProcessingEngine.LogAndRethrowException(Exception e)
    at Microsoft.Ceres.InteractionEngine.Component.CieProcessingEngine.GetItems(Guid flowIdentifier, String outputName)
    at SyncInvokeGetItems(Object , Object[] , Object[] )
    at System.ServiceModel.Dispatcher.SyncMethodInvoker.Invoke(Object instance, Object[] inputs, Object[]& outputs)
    at System.ServiceModel.Dispatcher.DispatchOperationRuntime.InvokeBegin(MessageRpc& rpc)
    at System.ServiceModel.Dispatcher.ImmutableDispatchRuntime.ProcessMessage5(MessageRpc& rpc)
    at System.ServiceModel.Dispatcher.ImmutableDispatchRuntime.ProcessMessage31(MessageRpc& rpc)
    at System.ServiceModel.Dispatcher.MessageRpc.Process(Boolean isOperationContextSet)).
    I do not really have an idea how to approach this and can't find any related information.
    Thanks for your help.

    I'm also getting the same error, tried the solution to no effect.
    Error:
    Exchange Server Information Store has encountered an error while executing a full-text index query ("and(or(itemclass:string("IPM.Note*", mode="and"), itemclass:string("IPM.Schedule.Meeting*", mode="and"), itemclass:string("IPM.OCTEL.VOICE*", mode="and"), itemclass:string("IPM.VOICENOTES*", mode="and")), subject:string("SearchQueryStxProbe*", mode="and"), folderid:string("D6A06323C909134BB77B2FE2114D06EA00000000000E0000"))"). Error information: System.ServiceModel.FaultException`1[System.ServiceModel.ExceptionDetail]: Internal error while processing request (Fault Detail is equal to An ExceptionDetail, likely created by IncludeExceptionDetailInFaults=true, whose value is:
    Microsoft.Ceres.InteractionEngine.Component.ProcessingEngineException: Internal error while processing request
    at Microsoft.Ceres.InteractionEngine.Component.CieProcessingEngine.LogAndRethrowException(Exception e)
    at Microsoft.Ceres.InteractionEngine.Component.CieProcessingEngine.ExecuteSearchFlow(String flowName, IEnumerable`1 inputData)
    at SyncInvokeExecuteSearchFlow(Object , Object[] , Object[] )
    at System.ServiceModel.Dispatcher.SyncMethodInvoker.Invoke(Object instance, Object[] inputs, Object[]& outputs)
    at System.ServiceModel.Dispatcher.DispatchOperationRuntime.InvokeBegin(MessageRpc& rpc)
    at System.ServiceModel.Dispatcher.ImmutableDispatchRuntime.ProcessMessage5(MessageRpc& rpc)
    at System.ServiceModel.Dispatcher.ImmutableDispatchRuntime.ProcessMessage31(MessageRpc& rpc)
    at System.ServiceModel.Dispatcher.MessageRpc.Process(Boolean isOperationContextSet)).
    My ContentIndexState is Unknown.
    I've also noticed this warning in the logs:
    Event 1010, MSExchangeFastSearch
    An operation attempted against a FAST endpoint exprienced an exception. This operation may be retried. Error details: Microsoft.Exchange.Search.Fast.PerformingFastOperationException: An Exception was received during a FAST operation. ---> System.ServiceModel.FaultException: Failed to create operator of type Microsoft.Exchange.Search.OperatorSchema.TransportRetrieverOperator. The operator type is not known to the system.
    Server stack trace:
    at System.ServiceModel.Channels.ServiceChannel.HandleReply(ProxyOperationRuntime operation, ProxyRpc& rpc)
    at System.ServiceModel.Channels.ServiceChannel.Call(String action, Boolean oneway, ProxyOperationRuntime operation, Object[] ins, Object[] outs, TimeSpan timeout)
    at System.ServiceModel.Channels.ServiceChannelProxy.InvokeService(IMethodCallMessage methodCall, ProxyOperationRuntime operation)
    at System.ServiceModel.Channels.ServiceChannelProxy.Invoke(IMessage message)
    Exception rethrown at [0]:
    at System.Runtime.Remoting.Proxies.RealProxy.HandleReturnMessage(IMessage reqMsg, IMessage retMsg)
    at System.Runtime.Remoting.Proxies.RealProxy.PrivateInvoke(MessageData& msgData, Int32 type)
    at Microsoft.Ceres.ContentEngine.Admin.FlowService.IFlowServiceManagementAgent.PutFlow(String name, String serializedFlow)
    at Microsoft.Exchange.Search.Fast.IndexManagementClient.<>c__DisplayClass1.<PerformFastOperation>b__0()
    at Microsoft.Exchange.Search.Fast.IndexManagementClient.PerformFastOperation[T](Func`1 function, String eventLogKey)
    --- End of inner exception stack trace ---
    Help would be much appreciated!

  • Exchange 2013 - Event ID 4999 MS Exchange Common - Watson report about to be sent for process id: 5816

    Hi,
    We have a single Exchange 2013 server and are getting this error many times in a day.  I haven't been able to find a solution and was wondering if anyone came across this error or have any suggestions.
    Edition             : Standard
    AdminDisplayVersion : Version 15.0 (Build 913.22)
    Watson report about to be sent for process id: 5816, with parameters: E12IIS, c-RTL-AMD64, 15.00.0913.022, M.Exchange.Imap4, M.Exchange.Net, M.E.N.NetworkConnection.BeginNegotiateTlsAsClient, System.InvalidOperationException, 99a4, 15.00.0913.007.
    ErrorReportingEnabled: True 
    Thanks
    Amit

    We have exchange 2013 cu6 mailbox server and we keep getting the below event error message
    Log Name:      Application
    Source:        MSExchange Common
    Date:          10/2/2014 1:06:25 PM
    Event ID:      4999
    Task Category: General
    Level:         Error
    Keywords:      Classic
    User:          N/A
    Computer:     
    Description:
    Watson report about to be sent for process id: 30632, with parameters: E12, c-RTL-AMD64, 15.00.0995.029, M.E.RpcClientAccess.Service, M.E.Data.ApplicationLogic, M.E.D.A.U.HttpPhotoRequestBuilder.Build, System.NotSupportedException, 4e29, 15.00.0995.027.
    ErrorReportingEnabled: True
    Event Xml:
    < Event xmlns="">
      <System>
        <Provider Name="MSExchange Common" />
        <EventID Qualifiers="16388">4999</EventID>
        <Level>2</Level>
        <Task>1</Task>
        <Keywords>0x80000000000000</Keywords>
        <TimeCreated SystemTime="2014-10-02T20:06:25.000000000Z" />
        <EventRecordID>7826297</EventRecordID>
        <Channel>Application</Channel>
        <Computer></Computer>
        <Security />
      </System>
      <EventData>
        <Data>30632</Data>
        <Data>E12</Data>
        <Data>c-RTL-AMD64</Data>
        <Data>15.00.0995.029</Data>
        <Data>M.E.RpcClientAccess.Service</Data>
        <Data>M.E.Data.ApplicationLogic</Data>
        <Data>M.E.D.A.U.HttpPhotoRequestBuilder.Build</Data>
        <Data>System.NotSupportedException</Data>
        <Data>4e29</Data>
        <Data>15.00.0995.027</Data>
        <Data>True</Data>
        <Data>False</Data>
        <Data>Microsoft.Exchange.RpcClientAccess.Service</Data>
        <Data>
        </Data>
      </EventData>
    < /Event>
    Services seem to be fine (Via test-servicehealth), but i do have a group of users that complain that their outlook 2013 email clients will go non-responsive a few times a days. Wondering if this is related. Also this error is appearing every few minutes.
    Anyone else experiencing this?

  • Exchange 2013 Event ID 4999

    Hello,
    I have two exchange servers 2013 both running MB and CAS roles. I also have a DAG on my servers. On one of my servers almost every 7-8 minutes I receive the following error event. Could you please assist me with this?
    Event 4999, MSExchange Common
    Watson report about to be sent for process id: 17084, with parameters: E12IIS, c-RTL-AMD64, 15.00.0995.029, MSExchangeMigrationWorkflow, unknown, M.E.M.L.L.<>c__DisplayClass11.<GetLocalServerData>b__10, System.NullReferenceException, 49af, unknown.
    ErrorReportingEnabled: False 
    Thanks a lot.
    Pooriya Aghaalitari

    Hi,
    DAG Network Automatic configuration may cause the Misconfigured Network sometimes. I recommend you to configure DAG Network manually to solve this problem.
    Please refer to the “DAG Networks” section in the following link.
    http://technet.microsoft.com/en-us/library/dd298065(v=exchg.150).aspx#Dat
    Similar thread for reference.
    https://social.technet.microsoft.com/Forums/exchange/en-US/e0496d08-c82b-4e8d-ae70-f64c69dc3913/add-dag-member-event-4999-msexchange-common?forum=exchangesvravailabilityandisasterrecovery
    Hope this will be helpful for you.
    Best Regards.

  • Object-Owner missing in Public Folder Calenders after Transition to Exchange 2013 SP1

    Hi there,
    we transfered all Public Folders from Exchange 2003 to 2010 to 2013 SP1. We have some Calendars with PublicFolderClientPermission Author witch includes EditOwnedItems and DeleteOwnedItems
    Unfortunately the Author Rights wont work after migration. it seems like the creator of the object got lost.
    since i never notices that in transitions from exchange 2003 to 2010, i think that should be related to the exchange 2013 transition.
    Can anybody approve or disprove that behavior?
    thanks alot

    Noticed now in the Exchange 2013 Event Logs that we're getting quite a few of these warnings:
    "Process <Select one exchange releated process>.exe (PID=<whatever>). Object [CN=Public Folder Database,CN=Databases,CN=Exchange Administrative Group (FYDIBOHF23SPDLT),CN=Administrative Groups,CN=Contoso,CN=Microsoft
    Exchange,CN=Services,CN=Configuration,DC=contoso,DC=local]. Property [PublicFolderDatabase] is set to value [contoso.local/Configuration/Deleted Objects/Public Folder Database
    DEL:ca62a715-05b2-4b08-ae0f-7f7c4b7e4cc3], it is pointing to the Deleted Objects container in Active Directory. This property should be fixed as soon as possible."
    If i take a look at that mailbox database it's obvious that it's pointing towards the old Public Folder Database, which is quite interesting as Exchange 2013 isn't supposed to used that value at all (according to http://technet.microsoft.com/en-us/library/bb123971(v=exchg.150).aspx):
    [PS] C:\Windows\system32>Get-MailboxDatabase -Identity "Mailbox database" | fl
    PublicFolderDatabase                         : contoso.local/Configuration/Deleted Objects/Public Folder Database
        DEL:ca62a715-05b2-4b08-ae0f-7f7c4b7e4cc3
    I'm assuming this is what happens when messing around with ADSIEdit :) So, further ADSIEdits to set that value to null on the existing Mailboxdatabases, or anyone have any other suggestions?

  • Exchange 2013 mailbox auditing command with showdetails parameter in ps1 script is not working via task scheduler

     
    Hi All ,
    In my environment we are having exchange 2013 enterprise edition with SP1 which is installed in windows server 2012 standard edition.
    We have enabled mailbox auditing for few mailboxes and also we have made simple powershell script with only the below mentioned commands .when i run the  ps1 script  in exchange management shell ,i can able to get the relevant output.
    CMDLETS in powershell script :
    Search-MailboxAuditLog -StartDate ((Get-Date).AddHours(-24)) -EndDate (Get-Date) -showdetails | fl >e:\output.txt
    Note : we are having only the above commands in ps1 script , apart from that we don't have anything in it .
    Sametime i have scheduled the same powershell script via task scheduler .But i cannot able to get the valid output ,instead of that i was getting a blank output file with no data in it . 
    Steps handled on my side to run the powershell script in task scheduler: 
    1.when i remove the parameter showdetails in the ps1 script ,i can able to get the output in the txt file .But in my scenario showdetails is the only parameter which will brought me more and in depth details about mailbox auditing.
    The Difference what i have seen between exchange 2010 and exchange 2013 
    when in run the same powershell script via task scheduler in exchange 2010 enterprise environment installed in windows server 2008 r2 enterprise OS, i can able able to get the proper output without removing the showdetails parameter .
    I am using the below methods to run the ps1 file via task scheduler in exchange 2013 environment .
    program/script : C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe
    Add arguments : -PSConsoleFile "E:\Program Files\Microsoft\Exchange Server\V15\Bin\exshell.psc1" -Command ". 'C:\scripts\MailboxAuditReport\test.ps1'"
    I have mentioned the error below and that is the one what i have faced, when i try to run the PS1 script directly in windows powershell and not in exchange management shell .
    Error message : "the requesting account does not have permission to access the audit log"
    Please help me out to resolve this case .
    Thanks 
    S.Nithyanandham

    Hi All ,
    In my environment we are having exchange 2013 enterprise edition with SP1 which is installed in windows server 2012 standard edition.
    We have enabled mailbox auditing for few mailboxes and also we have made simple powershell script with only the below mentioned commands .when i run the  ps1 script  in
    exchange management shell,i can able to get the relevant output.
    CMDLETS in powershell script :
    Search-MailboxAuditLog -StartDate ((Get-Date).AddHours(-24)) -EndDate (Get-Date) -showdetails | fl >e:\output.txt
    Note : we are having only the above commands in ps1
    script , apart from that we don't have anything in it .
    In case, if i have scheduled the same powershell script via task scheduler .But i cannot able to get the valid output ,instead of that i was getting a blank output file with no data in it . 
    Steps
    handled on my side to run the powershell script in task scheduler: 
    1.when i remove the parameter showdetails
    in the ps1 script ,i can able to get the output in the txt file .But in my scenario showdetails is the only parameter which will brought me more and in depth details about mailbox auditing.
    The
    Difference what i have seen between exchange 2010 and exchange 2013 
    when in run the same powershell script via task scheduler in exchange 2010 enterprise environment installed in windows server 2008 r2 enterprise OS, i can able able to get the proper output without removing the showdetails parameter .
    I
    am using the below methods to run the ps1 file via task scheduler in exchange 2013 environment .
    program/script : C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe
    Add arguments : -PSConsoleFile "E:\Program
    Files\Microsoft\Exchange Server\V15\Bin\exshell.psc1" -Command ". 'C:\scripts\MailboxAuditReport\test.ps1'"
    I have mentioned the error below and that is the one what i have faced, when i try to run the PS1 script directly in windows powershell and not in exchange management shell .
    Error message : "the requesting account does
    not have permission to access the audit log"
    Please help me out to resolve this case .
    Thanks 
    S.Nithyanandham

  • MailboxInSiteFailoverException - OWA session error on database *over (Exchange 2013 SP1)

    Hi all, I have noticed an issue with OWA when database(s) are failed over between DAG members.  The environments in question (issue can be reproduced in separate implementations of 2013 SP1 all-role servers) are 2 or more DAG members within the same
    AD site/subnet.  These are also fresh implementations with SP1 and not upgraded.  Exchange servers are load balanced via Netscaler. 
    So to the issue - OWA users experience the below "..MailboxInSiteFailoverException" message when the database copy is activated.  Exchange does not immediately proxy the requests to the active database.  You can wait several minutes and
    the issue is resolved by refreshing the browser or if you recycle the MSExchangeOWAAppPool on both DAG members, the issue is resolved immediately (OWA session re-established on refresh).
    Testing so far involved opening multiple OWA sessions and activating a database copy.  At that point, upon refresh of the browser the below error is shown (in all test browsers/sessions below) where I would expect any DAG member to be able to proxy
    the client request to the active database server immediately (and not after several minutes).
    https://netscaler_LB/owa
    https://ex2013server-1/owa
    https://ex2013server-2/owa

    Hi Simon, I have tested with no firewall on the exchange servers and on client machines within the same subnet as the servers.  All with the same results.
    I can see many ASP.NET 4.0.30319.0 Event ID 1309 logs similar to this and other threads (http://social.technet.microsoft.com/Forums/windowsserver/en-US/c938dda0-b3bc-4544-851e-f27b503cf4ed/exchange-2013-event-id-1309-source-aspnet-40303190).
    IIS logs show similar monitoring mailbox issues but I am still currently looking through the logs.  Thanks for your input.
    2014-03-30 00:00:23 127.0.0.1 POST /owa/proxylogon.owa - 444 - 127.0.0.1 Mozilla/4.0+(compatible;+MSIE+9.0;+Windows+NT+6.1;+MSEXCHMON;+ACTIVEMONITORING;+OWADEEPTEST) - 401 0 0 13
    2014-03-30 00:00:23 127.0.0.1 POST /owa/proxylogon.owa - 444 - 127.0.0.1 Mozilla/4.0+(compatible;+MSIE+9.0;+Windows+NT+6.1;+MSEXCHMON;+ACTIVEMONITORING;+OWADEEPTEST) - 401 0 0 13
    2014-03-30 00:00:23 127.0.0.1 POST /owa/proxylogon.owa - 444 - 127.0.0.1 Mozilla/4.0+(compatible;+MSIE+9.0;+Windows+NT+6.1;+MSEXCHMON;+ACTIVEMONITORING;+OWADEEPTEST) - 401 1 2148074254 0
    2014-03-30 00:00:23 127.0.0.1 POST /owa/proxylogon.owa - 444 - 127.0.0.1 Mozilla/4.0+(compatible;+MSIE+9.0;+Windows+NT+6.1;+MSEXCHMON;+ACTIVEMONITORING;+OWADEEPTEST) - 401 1 2148074254 0
    2014-03-30 00:01:23 ::1 POST /owa/proxylogon.owa &ex=UE:Microsoft.Exchange.Data.Storage.IllegalCrossServerConnectionException 444 DOMAIN\SM_3ce57cd622aa4655a ::1 Mozilla/4.0+(compatible;+MSIE+9.0;+Windows+NT+6.1;+MSEXCHMON;+ACTIVEMONITORING;+OWADEEPTEST)
    - 302 0 0 47
    2014-03-30 00:01:23 ::1 POST /owa/proxylogon.owa &ex=UE:Microsoft.Exchange.Data.Storage.IllegalCrossServerConnectionException 444 DOMAIN\SM_2891f9d41af2422e8 ::1 Mozilla/4.0+(compatible;+MSIE+9.0;+Windows+NT+6.1;+MSEXCHMON;+ACTIVEMONITORING;+OWADEEPTEST)
    - 302 0 0 47

  • Exchange 2013 /m:recoverserver constantly failing due to MSExchangeSubmission.exe

    Hi all,
    I am trying to recover my lab Exchange 2013 server after removing a component of IIS messed all IIS functions, including all virtual directories.
    The server is running on Hyper-V so I have removed and rebuilt the OS disk whilst the Exchange data resides on a separate disk. I've reset the computer account in AD and then run the command:
    setup /m:recoverserver /targetdir:"d:\Program Files\Microsoft Exchange\v15" /DoNotStartTransport /IAcceptExchangeServerLicenseTerms
    I have now done this a number of times and on each occasion it fails when attempting to start the Microsoft Exchange Transport Submission service. The error in the event log is as follows:
    Log Name:      Application
    Source:        Application Error
    Date:          30/03/2013 20:18:53
    Event ID:      1000
    Task Category: (100)
    Level:         Error
    Keywords:      Classic
    User:          N/A
    Computer:      HV-E2K13
    Description:
    Faulting application name: MSExchangeSubmission.exe, version: 15.0.516.29, time stamp: 0x506956b8
    Faulting module name: Microsoft.Exchange.Net.ni.dll, version: 15.0.516.27, time stamp: 0x5064072e
    Exception code: 0xc00000fd
    Fault offset: 0x0000000000639d07
    Faulting process id: 0x1cc8
    Faulting application start time: 0x01ce2d83cbb5568e
    Faulting application path: D:\Program Files\Microsoft Exchange\v15\Bin\MSExchangeSubmission.exe
    Faulting module path: C:\Windows\assembly\NativeImages_v4.0.30319_64\Microsoft.E91f4adf5#\6f9b1d97c1f0dcb9b1006260c405a5da\Microsoft.Exchange.Net.ni.dll
    Report Id: 0a1e3a42-9977-11e2-93f1-00155d0a4b05
    Faulting package full name:
    Faulting package-relative application ID:
    Event Xml:
    <Event xmlns="http://schemas.microsoft.com/win/2004/08/events/event">
      <System>
        <Provider Name="Application Error" />
        <EventID Qualifiers="0">1000</EventID>
        <Level>2</Level>
        <Task>100</Task>
        <Keywords>0x80000000000000</Keywords>
        <TimeCreated SystemTime="2013-03-30T20:18:53.000000000Z" />
        <EventRecordID>112812</EventRecordID>
        <Channel>Application</Channel>
        <Computer>HV-E2K13</Computer>
        <Security />
      </System>
      <EventData>
        <Data>MSExchangeSubmission.exe</Data>
        <Data>15.0.516.29</Data>
        <Data>506956b8</Data>
        <Data>Microsoft.Exchange.Net.ni.dll</Data>
        <Data>15.0.516.27</Data>
        <Data>5064072e</Data>
        <Data>c00000fd</Data>
        <Data>0000000000639d07</Data>
        <Data>1cc8</Data>
        <Data>01ce2d83cbb5568e</Data>
        <Data>D:\Program Files\Microsoft Exchange\v15\Bin\MSExchangeSubmission.exe</Data>
        <Data>C:\Windows\assembly\NativeImages_v4.0.30319_64\Microsoft.E91f4adf5#\6f9b1d97c1f0dcb9b1006260c405a5da\Microsoft.Exchange.Net.ni.dll</Data>
        <Data>0a1e3a42-9977-11e2-93f1-00155d0a4b05</Data>
        <Data>
        </Data>
        <Data>
        </Data>
      </EventData>
    </Event>
    Any thoughts?
    Paul

    Hi,
    Im dealing with the same errors when i'm trying to restore our productive mailbox from a disaster.
    I've tried everything listed here but last Milind Naphade commentary.
    I'm in that right now, i ll tell if it's working soon.
    Ty!
    Hi Again. It Failed to start MSExchangeSubmission.exe
    Here is the event on eventvwr (Some details on spanish wich is the language of my server)
    Nombre de la aplicación con errores: MSExchangeSubmission.exe, versión: 15.0.516.29, marca de tiempo: 0x506956b8
    Nombre del módulo con errores: Microsoft.Exchange.Net.ni.dll, versión: 15.0.516.27, marca de tiempo: 0x5064072e
    Código de excepción: 0xc00000fd
    Desplazamiento de errores: 0x000000000062f697
    Identificador del proceso con errores: 0x7d0
    Hora de inicio de la aplicación con errores: 0x01cfac0a0bb16a68
    Ruta de acceso de la aplicación con errores: C:\Program Files\Microsoft\Exchange Server\V15\Bin\MSExchangeSubmission.exe
    Ruta de acceso del módulo con errores: C:\Windows\assembly\NativeImages_v4.0.30319_64\Microsoft.E91f4adf5#\b028905d8fd3faa99c9801b69b1500da\Microsoft.Exchange.Net.ni.dll
    Identificador del informe: 4a9638fc-17fd-11e4-9404-000c29f101d8
    Nombre completo del paquete con errores: 
    Identificador de aplicación relativa del paquete con errores: 
    ExchangeSetup.log   ends with:
    [07/30/2014 15:19:10.0220] [1] The following 1 error(s) occurred during task execution:
    [07/30/2014 15:19:10.0220] [1] 0.  ErrorRecord: El servicio 'MSExchangeSubmission' no puede alcanzar el estado 'Running' en este servidor.
    [07/30/2014 15:19:10.0220] [1] 0.  ErrorRecord: Microsoft.Exchange.Configuration.Tasks.ServiceDidNotReachStatusException: El servicio 'MSExchangeSubmission' no puede alcanzar el estado 'Running' en este servidor.
       en Microsoft.Exchange.Configuration.Tasks.Task.ThrowError(Exception exception, ErrorCategory errorCategory, Object target, String helpUrl)
       en Microsoft.Exchange.Configuration.Tasks.Task.WriteError(Exception exception, ErrorCategory category, Object target)
       en Microsoft.Exchange.Management.Tasks.ManageSetupService.WaitForServiceStatus(ServiceController serviceController, ServiceControllerStatus status, Unlimited`1 maximumWaitTime, Boolean ignoreFailures, Boolean sendWatsonReportForHungService)
       en Microsoft.Exchange.Management.Tasks.ManageSetupService.StartService(ServiceController serviceController, Boolean ignoreServiceStartTimeout, Boolean failIfServiceNotInstalled, Unlimited`1 maximumWaitTime, String[] serviceParameters)
       en Microsoft.Exchange.Management.Tasks.ManageSetupService.StartService(String serviceName, Boolean ignoreServiceStartTimeout, Boolean failIfServiceNotInstalled, Unlimited`1 maximumWaitTime, String[] serviceParameters)
       en Microsoft.Exchange.Management.Tasks.StartSetupService.InternalProcessRecord()
       en Microsoft.Exchange.Configuration.Tasks.Task.ProcessRecord()
    [07/30/2014 15:19:10.0236] [1] [ERROR] The following error was generated when "$error.Clear(); 
    start-SetupService -ServiceName MSExchangeSubmission
    " was run: "El servicio 'MSExchangeSubmission' no puede alcanzar el estado 'Running' en este servidor.".
    [07/30/2014 15:19:10.0236] [1] [ERROR] Service 'MSExchangeSubmission' failed to reach status 'Running' on this server.
    [07/30/2014 15:19:10.0236] [1] [ERROR-REFERENCE] Id=MailboxServiceControlLast___23a36fed7b6947e0906f388b5a90135c Component=EXCHANGE14:\Current\Release\Shared\Datacenter\Setup
    [07/30/2014 15:19:10.0251] [1] Setup is stopping now because of one or more critical errors.
    [07/30/2014 15:19:10.0251] [1] Finished executing component tasks.
    [07/30/2014 15:19:10.0267] [1] Ending processing DisasterRecovery-MailboxRole
    [07/30/2014 15:19:10.0282] [0] No se completó la operación de instalación de Exchange Server. Puede encontrar más detalles en ExchangeSetup.log ubicado en la <SystemDrive>: carpeta \ExchangeSetupLogs.
    [07/30/2014 15:19:10.0282] [0] End of Setup
    [07/30/2014 15:19:10.0282] [0] **********************************************
    Any suggestion please??? idk what else can i do!

  • Event ID 2142, 2077, 2069 MSExchangeADTopology Exchange 2013

    Hello,
    I have just inherited a slightly abused new server as part of my job and it looks like the previous admin was using a live single domain as a test bed.
    From what I have been able to determine this windows 2008R2 server started life as a single name domain (no FQDN) that had exchange 2013 running on it (sin I know).  A domain rename was performed and from what I can tell it did change the domain name to
    a FQDN environment.  (it went for COMPANY to COMPANY.COM)
    I have been able to clean up most of the other ghosts in the machine except when it comes to exchange.  I get event ID 2142(error), 2077 (info), and 2069 (info) repeatedly it cycles every 2 minutes:
    Log Name:      Application
    Source:        MSExchangeADTopology
    Date:          4/18/2013 11:42:39 AM
    Event ID:      2142
    Task Category: Topology
    Level:         Error
    Keywords:      Classic
    User:          N/A
    Computer:      SERVER2013.COMPANY
    Description:
    Process Microsoft.Exchange.Directory.TopologyService.exe (PID=13460) Forest COMPANY.com. Topology discovery failed, error details
    No Suitable Directory Servers Found in Forest COMPANY.com Site Default-First-Site-Name..
    Event Xml:
    <Event xmlns="http://schemas.microsoft.com/win/2004/08/events/event">
      <System>
        <Provider Name="MSExchangeADTopology" />
        <EventID Qualifiers="49156">2142</EventID>
        <Level>2</Level>
        <Task>3</Task>
        <Keywords>0x80000000000000</Keywords>
        <TimeCreated SystemTime="2013-04-18T16:42:39.000000000Z" />
        <EventRecordID>4918254</EventRecordID>
        <Channel>Application</Channel>
        <Computer>SERVER2013.COMPANY</Computer>
        <Security />
      </System>
      <EventData>
        <Data>Microsoft.Exchange.Directory.TopologyService.exe</Data>
        <Data>13460</Data>
        <Data>COMPANY.com</Data>
        <Data>No Suitable Directory Servers Found in Forest COMPANY.com Site Default-First-Site-Name.</Data>
      </EventData>
    </Event>
    Log Name:      Application
    Source:        MSExchangeADTopology
    Date:          4/18/2013 11:42:39 AM
    Event ID:      2077
    Task Category: Topology
    Level:         Information
    Keywords:      Classic
    User:          N/A
    Computer:      SERVER2013.COMPANY
    Description:
    Process Microsoft.Exchange.Directory.TopologyService.exe (PID=13460) Forest COMPANY.com. Exchange Active Directory Provider could not find any suitable domain controller servers in either the local site 'Default-First-Site-Name' or the following sites:
    Event Xml:
    <Event xmlns="http://schemas.microsoft.com/win/2004/08/events/event">
      <System>
        <Provider Name="MSExchangeADTopology" />
        <EventID Qualifiers="16388">2077</EventID>
        <Level>4</Level>
        <Task>3</Task>
        <Keywords>0x80000000000000</Keywords>
        <TimeCreated SystemTime="2013-04-18T16:42:39.000000000Z" />
        <EventRecordID>4938976</EventRecordID>
        <Channel>Application</Channel>
        <Computer>SERVER2013.COMPANY</Computer>
        <Security />
      </System>
      <EventData>
        <Data>Microsoft.Exchange.Directory.TopologyService.exe</Data>
        <Data>13460</Data>
        <Data>COMPANY.com</Data>
        <Data>Default-First-Site-Name</Data>
        <Data>
        </Data>
      </EventData>
    </Event>
    Log Name:      Application
    Source:        MSExchangeADTopology
    Date:          4/18/2013 11:42:39 AM
    Event ID:      2069
    Task Category: Topology
    Level:         Information
    Keywords:      Classic
    User:          N/A
    Computer:      SERVER2013.COMPANY
    Description:
    Process Microsoft.Exchange.Directory.TopologyService.exe (PID=13460) Forest COMPANY.com. Exchange Active Directory Provider couldn't find any suitable Global Catalog servers in either the local site 'Default-First-Site-Name' or the following sites:
    Event Xml:
    <Event xmlns="http://schemas.microsoft.com/win/2004/08/events/event">
      <System>
        <Provider Name="MSExchangeADTopology" />
        <EventID Qualifiers="16388">2069</EventID>
        <Level>4</Level>
        <Task>3</Task>
        <Keywords>0x80000000000000</Keywords>
        <TimeCreated SystemTime="2013-04-18T16:42:39.000000000Z" />
        <EventRecordID>4938977</EventRecordID>
        <Channel>Application</Channel>
        <Computer>SERVER2013.COMPANY</Computer>
        <Security />
      </System>
      <EventData>
        <Data>Microsoft.Exchange.Directory.TopologyService.exe</Data>
        <Data>13460</Data>
        <Data>COMPANY.com</Data>
        <Data>Default-First-Site-Name</Data>
        <Data>
        </Data>
      </EventData>
    </Event>
    It looks to me that exchange is still looking for the old domain name.  Does anyone know how to point it to the correct domain name?
    Exchange is currently down and I am unable to log into EAC, OWA or Exchange Management Powershell.  I am also unable to un-install exchange as it is reporting active mailboxes and I can't delete them because I am unable to log in.
    My overall goal is to remove exchange from this server and put it on a separate server but until I can get exchange working to a point where I can remove the mailboxes, I am stuck.
    Any and all help appreciated.
    Hummedan

    Thank you for your advise on correcting my issue.  I created the subnet and assigned it to the Default-First-Site-Name as there weren't any subnets listed.
    Upon reboot I checked the event log and I am still receiving the event log entries as above; however, I am now receiving a few new errors along with them and they are repeating (4027 error and 3176 action).  Here are the additional errors:
    Log Name:      Application
    Source:        MSExchange ADAccess
    Date:          4/22/2013 9:52:48 AM
    Event ID:      4027
    Task Category: General
    Level:         Error
    Keywords:      Classic
    User:          N/A
    Computer:      SERVER2013.COMPANY
    Description:
    Process msexchangerepl.exe (PID=8016). WCF request (Get Servers for COMPANY.com) to the Microsoft Exchange Active Directory Topology service on server (TopologyClientTcpEndpoint (localhost)) failed. Make sure that the service is running. In addition, make sure
    that the network ports that are used by Microsoft Exchange Active Directory Topology service are not blocked by a firewall. The WCF call was retried 3 time(s). Error Details
     An error occurred during forest discovery (COMPANY.com). ----> No Suitable Directory Servers Found in Forest COMPANY.com Site Default-First-Site-Name.
       at Microsoft.Exchange.Directory.TopologyService.ADTopologyDiscovery.Discover()
       at Microsoft.Exchange.Directory.TopologyService.ADTopologyDiscovery.DoWork(CancellationToken cancellationToken)
       at Microsoft.Exchange.Directory.TopologyService.Common.WorkItem`1.Execute(CancellationToken joinedToken)
       at Microsoft.Exchange.Directory.TopologyService.Common.WorkItem`1.<>c__DisplayClass6.<StartExecuting>b__4()
       at System.Threading.Tasks.Task.Execute()
       at Microsoft.Exchange.Directory.TopologyService.Common.Extensions.WrapAndRethrowException(Exception exception, LocalizedString errorMessage)
       at Microsoft.Exchange.Directory.TopologyService.TopologyDiscoveryManager.EndGetTopology(IAsyncResult ar)
       at Microsoft.Exchange.Directory.TopologyService.TopologyService.InternalEndGetServersForRole(IAsyncResult result)
       at Microsoft.Exchange.Directory.TopologyService.TopologyService.<>c__DisplayClassa.<EndGetServersForRole>b__9()
       at Microsoft.Exchange.Directory.TopologyService.TopologyService.ExecuteServiceCall(Action action)
    Log Name:      Application
    Source:        MSExchangeRepl
    Date:          4/22/2013 9:52:48 AM
    Event ID:      3176
    Task Category: Action
    Level:         Error
    Keywords:      Classic
    User:          N/A
    Computer:      SERVER2013.COMPANY
    Description:
    The Microsoft Exchange Replication service attempted to start the Active Manager RPC server but failed because an error occurred when attempting to read the Exchange Servers universal security group SID from Active Directory. Error:
    The call to Microsoft Exchange Active Directory Topology service on server 'TopologyClientTcpEndpoint (localhost)' returned an error. Error details An error occurred during forest discovery (COMPANY.com)..
    Log Name:      Application
    Source:        MSExchange ADAccess
    Date:          4/22/2013 9:52:48 AM
    Event ID:      4027
    Task Category: General
    Level:         Error
    Keywords:      Classic
    User:          N/A
    Computer:      SERVER2013.COMPANY
    Description:
    Process MSExchangeSubmission.exe (PID=10708). WCF request (Get Servers for COMPANY.com) to the Microsoft Exchange Active Directory Topology service on server (TopologyClientTcpEndpoint (localhost)) failed. Make sure that the service is running. In addition,
    make sure that the network ports that are used by Microsoft Exchange Active Directory Topology service are not blocked by a firewall. The WCF call was retried 3 time(s). Error Details
     An error occurred during forest discovery (COMPANY.com). ----> No Suitable Directory Servers Found in Forest COMPANY.com Site Default-First-Site-Name.
       at Microsoft.Exchange.Directory.TopologyService.ADTopologyDiscovery.Discover()
       at Microsoft.Exchange.Directory.TopologyService.ADTopologyDiscovery.DoWork(CancellationToken cancellationToken)
       at Microsoft.Exchange.Directory.TopologyService.Common.WorkItem`1.Execute(CancellationToken joinedToken)
       at Microsoft.Exchange.Directory.TopologyService.Common.WorkItem`1.<>c__DisplayClass6.<StartExecuting>b__4()
       at System.Threading.Tasks.Task.Execute()
       at Microsoft.Exchange.Directory.TopologyService.Common.Extensions.WrapAndRethrowException(Exception exception, LocalizedString errorMessage)
       at Microsoft.Exchange.Directory.TopologyService.TopologyDiscoveryManager.EndGetTopology(IAsyncResult ar)
       at Microsoft.Exchange.Directory.TopologyService.TopologyService.InternalEndGetServersForRole(IAsyncResult result)
       at Microsoft.Exchange.Directory.TopologyService.TopologyService.<>c__DisplayClassa.<EndGetServersForRole>b__9()
       at Microsoft.Exchange.Directory.TopologyService.TopologyService.ExecuteServiceCall(Action action)

  • Seemingly successful install of Exchange 2013 SP1 turns into many errors in event logs after upgrade to CU7

    I have a new Exchange 2013 server with plans to migrate from my current Exchange 2007 Server. 
    I installed Exchange 2013 SP1 and the only errors I saw in the event log seemed to be long standing known issues that did not indicate an actual problem (based on what I read online). 
    I updated to CU7 and now lots of errors have appeared (although the old ones seem to have been fixed so I have that going for me). 
    Currently the Exchange 2013 server is not in use and clients are still hitting the 2007 server.
    Issue 1)
    After each reboot I get a Kernel-EventTracing 2 error.  I cannot find anything on this on the internet so I have no idea what it is.
    Session "FastDocTracingSession" failed to start with the following error: 0xC0000035
    I did read other accounts of this error with a different name in the quotes but still can’t tell what this is or where it is coming from.
    Issue 2)
    I am still getting 5 MSExchange Common 106 errors even after reregistering all of the perf counters per this page:
    https://support.microsoft.com/kb/2870416?wa=wsignin1.0
    One of the perf counters fails to register using the script from the link above.
    66 C:\Program Files\Microsoft\Exchange Server\V15\Setup\Perf\InfoWorkerMultiMailboxSearchPerformanceCounters.xml
    New-PerfCounters : The performance counter definition file is invalid.
    At C:\Users\administrator.<my domain>\Downloads\script\ReloadPerfCounters.ps1:19 char:4
    +    New-PerfCounters -DefinitionFileName $f
    +    ~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~
        + CategoryInfo         
    : InvalidData: (:) [New-PerfCounters], TaskException
        + FullyQualifiedErrorId : [Server=VALIS,RequestId=71b6bcde-d73e-4c14-9a32-03f06e3b2607,TimeStamp=12/18/2014 10:09:
       12 PM] [FailureCategory=Cmdlet-TaskException] 33EBD286,Microsoft.Exchange.Management.Tasks.NewPerfCounters
    But that one seems unrelated to the ones that still throw errors. 
    Three of the remaining five errors are (the forum is removing my spacing between the error text so it looks like a wall of text - sorry):
    Performance counter updating error. Counter name is Count Matched LowFidelity FingerPrint, but missed HighFidelity FingerPrint, category name is MSExchange Anti-Malware Datacenter Perfcounters. Optional code: 3. Exception: The
    exception thrown is : System.InvalidOperationException: The requested Performance Counter is not a custom counter, it has to be initialized as ReadOnly.
       at System.Diagnostics.PerformanceCounter.InitializeImpl()
       at System.Diagnostics.PerformanceCounter.set_RawValue(Int64 value)
       at Microsoft.Exchange.Diagnostics.ExPerformanceCounter.set_RawValue(Int64 value)
    Last worker process info : System.ArgumentException: Process with an Id of 7384 is not running.
       at System.Diagnostics.Process.GetProcessById(Int32 processId)
       at Microsoft.Exchange.Diagnostics.ExPerformanceCounter.GetLastWorkerProcessInfo()
    Performance counter updating error. Counter name is Number of items, item is matched with finger printing cache, category name is MSExchange Anti-Malware Datacenter Perfcounters. Optional code: 3. Exception: The exception thrown
    is : System.InvalidOperationException: The requested Performance Counter is not a custom counter, it has to be initialized as ReadOnly.
       at System.Diagnostics.PerformanceCounter.InitializeImpl()
       at System.Diagnostics.PerformanceCounter.set_RawValue(Int64 value)
       at Microsoft.Exchange.Diagnostics.ExPerformanceCounter.set_RawValue(Int64 value)
    Last worker process info : System.ArgumentException: Process with an Id of 7384 is not running.
       at System.Diagnostics.Process.GetProcessById(Int32 processId)
       at Microsoft.Exchange.Diagnostics.ExPerformanceCounter.GetLastWorkerProcessInfo()
    Performance counter updating error. Counter name is Number of items in Malware Fingerprint cache, category name is MSExchange Anti-Malware Datacenter Perfcounters. Optional code: 3. Exception: The exception thrown is : System.InvalidOperationException:
    The requested Performance Counter is not a custom counter, it has to be initialized as ReadOnly.
       at System.Diagnostics.PerformanceCounter.InitializeImpl()
       at System.Diagnostics.PerformanceCounter.set_RawValue(Int64 value)
       at Microsoft.Exchange.Diagnostics.ExPerformanceCounter.set_RawValue(Int64 value)
    Last worker process info : System.ArgumentException: Process with an Id of 7384 is not running.
       at System.Diagnostics.Process.GetProcessById(Int32 processId)
       at Microsoft.Exchange.Diagnostics.ExPerformanceCounter.GetLastWorkerProcessInfo()
    Issue 3)
    I appear to have some issues related to the healthmailboxes. 
    I get MSExchangeTransport 1025 errors for multiple healthmailboxes.
    SMTP rejected a (P1) mail from 'HealthMailbox23b10b91745648819139ee691dc97eb6@<my domain>.local' with 'Client Proxy <my server>' connector and the user authenticated as 'HealthMailbox23b10b91745648819139ee691dc97eb6'. The Active Directory
    lookup for the sender address returned validation errors. Microsoft.Exchange.Data.ProviderError
    I reran setup /prepareAD to try and remedy this but I am still getting some.
    Issue 4)
    I am getting an MSExchange RBAC 74 error. 
    (Process w3wp.exe, PID 984) Connection leak detected for key <my domain>.local/Admins/Administrator in Microsoft.Exchange.Configuration.Authorization.WSManBudgetManager class. Leaked Value 1.
    Issue 5)
    I am getting MSExchange Assistants 9042 warnings on both databases.
    Service MSExchangeMailboxAssistants. Probe Time Based Assistant for database Database02 (c83dbd91-7cc4-4412-912e-1b87ca6eb0ab) is exiting a work cycle. No mailboxes were successfully processed. 2 mailboxes were skipped due to errors. 0 mailboxes were
    skipped due to failure to open a store session. 0 mailboxes were retried. There are 0 mailboxes in this database remaining to be processed.
    Some research suggested this may be related to deleted mailboxes however I have never had any actual user mailboxes on this server. 
    If they are healthmailboxes or arbitration mailboxes that might make sense but I am unsure of what to do on this.
    Issue 6)
    At boot I am getting an MSExchange ActiveSync warning 1033
    The setting SupportedIPMTypes in the Web.Config file was missing. 
    Using default value of System.Collections.Generic.List`1[System.String].
    I don't know why but this forum is removing some of my spacing that would make parts of this easier to read.

    Hi Eric
    Yes I have uninstalled and reinstalled Exchange 2013 CU7 for the 3<sup>rd</sup> time. 
    I realize you said one issue per forum thread but since I already started this thread with many issues I will at least post what I have discovered on them in case someone finds their way here from a web search.
    I have an existing Exchange 2007 server in the environment so I am unable to create email address policies that are defined by “recipient container”. 
    If I try and do so I get “You can't specify the recipient container because legacy servers are detected.”
     So I cannot create a normal email address policy and restrict it to an OU without resorting to some fancy filtering. 
    Instead what I have done is use PS to modify extensionAttribute1 (otherwise known as Custom Attribute 1 to exchange) for all of my users. 
    I then applied an address policy to them and gave it the highest priority. 
    Then I set a default email address policy for the entire organization. 
    After reinstalling Exchange all of my system mailboxes were created with the internal domain name. 
    So issue number 3 above has not come up. 
    For issue number one above I have created a new thread:
    https://social.technet.microsoft.com/Forums/office/en-US/7eb12b89-ae9b-46b2-bd34-e50cd52a4c15/microsoftwindowskerneleventtracing-error-2-happens-twice-at-boot-ex2013cu7?forum=exchangesvrdeploy
    For issue number four I have posted to this existing thread where there is so far no resolution:
    https://social.technet.microsoft.com/Forums/exchange/en-US/2343730c-7303-4067-ae1a-b106cffc3583/exchange-error-id-74-connection-leak-detected-for-key?forum=exchangesvradmin
    Issue number Five I have managed to recreate and get rid of in more than one way. 
    If I create a new database in ECP and set the database and log paths where I want, then this error will appear. 
    If I create the database in the default location and then use EMS to move it and set the log path, then the error will not appear. 
    The error will also appear (along with other errors) if I delete the health mailboxes and let them get recreated by restarting the server or the Health Manager service. 
    If I then go and set the retention period for deleted mailboxes to 0 days and wait a little while, these will all go away. 
    So my off hand guess is that these are caused by orphaned system mailboxes.
    For issue number six I have posted to this existing thread where there is so far no resolution:
    https://social.technet.microsoft.com/Forums/exchange/en-US/dff62411-fad8-4d0c-9bdb-037374644845/event-1033-msexchangeactivesync-warning?forum=exchangesvrmobility
    So for the remainder of this thread we can try and tackle issue number two which is the perf counters. 
    The exact same 5 perf counter were coming up and this had been true each time I have uninstalled and reinstalled Exchange 2013CU7. 
    Actually to be more accurate a LOT of perf counter errors come up after the initial install, but reloading the perf counters using the script I posted above reduces it to the same five. 
    Using all of your suggestions so far has not removed these 5 remaining errors either.  Since there is no discernible impact other than these errors at boot I am not seriously bothered by them but as will all event log errors, I would prefer
    to make them go away if possible.

  • Exchange 2013 DCOM Event ID 10028

    I am running two virtual Exchange 2013 Std servers (CAS and MBX on both) on Server 2012 Std in two different sites (no DAG...yet). When connecting from EX01 through ECP or EMS and I try to retrieve configuration for something from the other server (EX02)
    it will take up to 5 minutes before I get the information and the System Event viewer will have the following:
    Log Name:      System
    Source:        Microsoft-Windows-DistributedCOM
    Date:          8/21/2013 9:08:47 AM
    Event ID:      10028
    Task Category: None
    Level:         Error
    Keywords:      Classic
    User:          SYSTEM
    Computer:      EX02.domain.com
    Description:
    DCOM was unable to communicate with the computer EX02.domain.com using any of the configured protocols; requested by PID     26ec (c:\windows\system32\inetsrv\w3wp.exe).
    Event Xml:
    <Event xmlns="http :// schemas.microsoft.com/win/2004/08/events/event">
      <System>
        <Provider Name="Microsoft-Windows-DistributedCOM" Guid="{1B562E86-B7AA-4131-BADC-B6F3A001407E}" EventSourceName="DCOM" />
        <EventID Qualifiers="0">10028</EventID>
        <Version>0</Version>
        <Level>2</Level>
        <Task>0</Task>
        <Opcode>0</Opcode>
        <Keywords>0x8080000000000000</Keywords>
        <TimeCreated SystemTime="2013-08-21T14:08:47.915595500Z" />
        <EventRecordID>15029</EventRecordID>
        <Correlation />
        <Execution ProcessID="744" ThreadID="19976" />
        <Channel>System</Channel>
        <Computer>EX02.domain.com</Computer>
        <Security UserID="S-1-5-18" />
      </System>
      <EventData>
        <Data Name="param1">EX02.domain.com</Data>
        <Data Name="param2">    26ec</Data>
        <Data Name="param3">c:\windows\system32\inetsrv\w3wp.exe</Data>
        <Binary>3C5265636F726423313A20436F6D70757465723D286E756C6C293B5069643D3734343B382F32312F323031332031343A383A34373A3931353B5374617475733D313832353B47656E636F6D703D323B4465746C6F633D313436313B466C6167733D303B506172616D733D303B3E3C5265636F726423323A20436F6D70757465723D286E756C6C293B5069643D3734343B382F32312F323031332031343A383A34373A3931353B5374617475733D313832353B47656E636F6D703D323B4465746C6F633D3135333B466C6167733D303B506172616D733D343B7B506172616D23303A2D323134363839333030367D7B506172616D23313A347D7B506172616D23323A36383132367D7B506172616D23333A317D3E</Binary>
      </EventData>
    </Event>
    This error can be repeatedly triggered with no problem. If I'm on EX01 on EMS and run:
    Get-OWAVirtualDirectory -Server EX02
    it will take nearly 4 minutes before I get the details and the System Event ID 10028 DistributedCOM will appear on EX01. Same occurs if I reverse the process from EX02. I have turned off the Windows Firewall to see if that makes a difference - no change.
    I have remove AV from both servers - no change.
    Any ideas will be appreciated.
    ~Rick

    Having the same setup and running in the same problem. Remote-Powershell doesn't work properly. Any remote query needs minutes.
    Two Exchange Server 2013 STD on Windows Server 2012, both with MBX & CAS (no DAG), placed in two different sites. CU2 is installed, the system is fully patched. The sites are connected over a IPSec-Tunnel with a acceptable RTT of 50 to 150ms. The Firewall
    in between is open for the whole Servernetwork-Segments. The local Windows Firewall is deactivated by GPO. I can portping all needed ports (TCP/80,443,5985) on remote system with success. AutoDiscover is working properly, the Test-Outlook-Clients can connect
    automatically to the server, in each site localy. Im using on both servers SAN-Certificates, created on the internal MS-CA. The external part does not exist until now, but there will be a reverse proxy (netscaler) with the official SAN-Certificate, on both
    sites with separate internet access.
    Another issue is very strange and I don't understand what causes that behavior: The administrators mailbox is on SRV1. When I connect to ECP over "https://fqdnOfSRV1/ECP/" works perfect. But when I connect over "https://fqdnOfSRV2/ECP/" to the same mailbox,
    which is on SRV1, the IIS redirects me to the WebApp of administrator. I did test it inverse and using a administrator2 account, which is on a DB on SRV2. Same issue when I connect over SRV1.
    I have much more issues and hope some of them will be addressed with CU3.
    Did you have any update on this case?
    Regards
    Patrick

  • Exchange 2013 CU6 Event ID 4999

    After installing CU6 on the exchange 2013 mailbox server we keep getting the below event error message
    Log Name:      Application
    Source:        MSExchange Common
    Date:          10/2/2014 1:06:25 PM
    Event ID:      4999
    Task Category: General
    Level:         Error
    Keywords:      Classic
    User:          N/A
    Computer:     
    Description:
    Watson report about to be sent for process id: 30632, with parameters: E12, c-RTL-AMD64, 15.00.0995.029, M.E.RpcClientAccess.Service, M.E.Data.ApplicationLogic, M.E.D.A.U.HttpPhotoRequestBuilder.Build, System.NotSupportedException, 4e29, 15.00.0995.027.
    ErrorReportingEnabled: True
    Event Xml:
    <Event xmlns="">
      <System>
        <Provider Name="MSExchange Common" />
        <EventID Qualifiers="16388">4999</EventID>
        <Level>2</Level>
        <Task>1</Task>
        <Keywords>0x80000000000000</Keywords>
        <TimeCreated SystemTime="2014-10-02T20:06:25.000000000Z" />
        <EventRecordID>7826297</EventRecordID>
        <Channel>Application</Channel>
        <Computer></Computer>
        <Security />
      </System>
      <EventData>
        <Data>30632</Data>
        <Data>E12</Data>
        <Data>c-RTL-AMD64</Data>
        <Data>15.00.0995.029</Data>
        <Data>M.E.RpcClientAccess.Service</Data>
        <Data>M.E.Data.ApplicationLogic</Data>
        <Data>M.E.D.A.U.HttpPhotoRequestBuilder.Build</Data>
        <Data>System.NotSupportedException</Data>
        <Data>4e29</Data>
        <Data>15.00.0995.027</Data>
        <Data>True</Data>
        <Data>False</Data>
        <Data>Microsoft.Exchange.RpcClientAccess.Service</Data>
        <Data>
        </Data>
      </EventData>
    </Event>
    Services seem to be fine but i do have a group of users that complain that their outlook 2013 email clients will go non-responsive a few times a days. Wondering if this is related. Also this error is appearing every few minutes. Anyone else experiencing
    this?

    Hi,
    I would like to add some information to this, in case others are facing the same circumstance. I too received the same errors on my Exchange 2013 CU5 and CU6 servers mentioned above. I ended up calling Microsoft Premiere support because there was a very
    large impact in our environment as we had Outlook 2010 clients that were having Exchange 2013 connectivity issues. Long story short, since Outlook 2010 was trying to use RPC to connect to the Exchange 2013 servers and in the Event Viewer we were seeing the
    4999 Event ID multiple times per minute, RPC was crashing on the Exchange servers resulting in client connectivity issues.
    Microsoft ran a ProcDump on the PID for RPC crash and basically came back with nothing only saying that it was a result of someone uploading a picture via Lync that was either corrupt or too large cause the photo store to crash the RPC Service. They also
    were firm in saying that this should have no impact. I was not convinced because this happened after installing CU5 and the client connectivity issues also appeared in conjunction with these 4999 RPC errors. In my mind that is a bug and I asked that something
    be published to address this as it seems silly that one user uploading a Lync profile picture could cripple our environment.
    You would need to navigate to the following location to see this Photo Store. (D:\Program Files\Microsoft\Exchange Server\V15\ClientAccess\photos) Change the path to point to your local Exchange install instance. Most of the files in my location are 0K but
    there are a few that are 4K so it seems they are not large enough to affect anything. We have 4 CAS+MBX servers so I looked at all 4 servers.
    What I ended up doing to resolve the 4999 event ID which actually ended up fixing my client connectivity issues also was to edit the following file. "D:\Program Files\Microsoft\Exchange Server\V15\Bin\Microsoft.Exchange.RpcClientAccess.Service.exe.config"
    Back the above file up and when you open it scroll about 3/4 to 7/8 of the way down and find the following lines:
        <!-- Enables retrieval of the HD photo in DOMT. -->
        <add key="HDPhotoEnabled" value="true" />
    Set the line to "false" like so:
        <!-- Enables retrieval of the HD photo in DOMT. -->
        <add key="HDPhotoEnabled" value="false" />
    Then restart the Microsoft Exchange RPC Client Access service and refresh the Event Viewer and the 4999 errors should stop and client connectivity should be restored.
    I noticed this error with CU5 and then subsequently after I installed CU6, so I had to perform this change after I installed CU6 and probably do the same once CU7 comes out. I do not know the adverse effects of making this change as Microsoft really could
    not explain more than what I wrote above, but I had to get Outlook connectivity restored and this was my only option. It appears that Lync 2010 photos and Outlook 2010 photos stayed intact so no users were complaining that their self-uploaded profile pictures
    were gone. We never had this problem with Outlook 2013 SP1 as we have MAPI enabled and the crashing RPC service would not have effected those clients. OWA was also working just fine.
    Hopefully Microsoft can offer me more of an explanation as I ended up fixing my own issue but I raised concern with how this happened. I hope this helps someone else as it helped me.
    Thanks.
    Alan

Maybe you are looking for

  • Issue with Customizing Condition-Dependent Document Output

    Hello gurus! When we print a Bid Invitation on SRM menubar web "Output Control", Sap creates three new spool orders. The first contains the output format of our SmartForm ZBBP_BID INVITATION. The second contains the format of a external mail. And the

  • Air 3.5 front camera issue

    I am using the latest air 3.5 sdk to build an video application. But I find that the front camera can not render correctly in spark.VideoDisplay, while the back camera is ok. My deivce is galaxy nexus, android 4.1.2, the code is below: protected func

  • Using ALEKS with Mac (math class review for college)

    Hi. I'm taking a math review class for college, and it's online. They want me to do it through something called ALEKS. Has anyone used this before? I've paid for the class, and tried downloading what they wanted me to download, but I got this error m

  • NO AUDIO even though it's worked before!

    I just made a onestep dvd like ive done many times in the past but this time there is NO audio! I made 5 copies the same way i always do and the sound encoding went fine according to the computer but theres no audio. there was even audio playing when

  • Portege series, different battery life on R100 and M100?

    Hello everybody, I want to buy a new notebook with high battery life for mobile working. The R100 and M100 are shortlisted, but does anybody know if there are differences in battery life. I have tested the two NBs at my dealer, but I have no experien