IPS event log size

Hi everyone,
I have a very "interesting" que from my customer.
He is asking me how much disk space is needed for an event log. Just one event log. Because I told him that IPS itself has limited space for logs and to archive it, please use IME installed on a server.
Does anyone know how much disk space is taken up for a single event log? LOL
Regards

There is no fixed size. Different types of events will contain more or less data. If you turn on packet captures, the size will be much larger as well.
- Bob

Similar Messages

  • Correlating Cisco ASA-SSM-IPS Events/Logs

    I have just configured a Cisco ASA-SSM-IPS10. An exciting feature of this decice is the ability to monitor, analyse, and correlate security events. Can anybody help with a documentation to simplify daily (or periodic) analysis, and correlation of the IPS Logs? As I am not yet to up to speed with this task yet, a "How-to" document would be just fine.  Thank you.

    Hi Chris,
    Good to have you get on the case. I am yet to setup and ips manager software. Presently, I use an ASDM 6 interface, with this interface, I am able to view events and alerts, and perform other adminsitrative cores... The IPS manager express does it comes bundle with our device purchase? Does it contain necesary templates/docs for correlating events/Logs?

  • Manage size of DHCP-Clinet Event log SIZE

    While troubleshooting DHCP –NAC problem i had to enable and increase  the size of the Microsoft-Windows-Dhcp-Client/Admin , Microsoft-Windows-Dhcp-Client/Operational, Microsoft-Windows-DNS-Client/Operational
    Because when NAC event course default size of 1MB of the log is to short, and it fills up in a seconds, and it  overwrite  first event.
    Is there any why, how to increase log size, from GPO.

    Hi,
    Where are these events logged? If these events are logged in Event Viewer, we can utilize Group Policy to change the maximum size of the log.
    The path for this policy setting is:
    GPO_name\Computer Configuration\Windows Settings\Security Settings\Event Log\
    Regarding this point, the following article and blog can be referred to for more information.
    Event Log Policy Settings
    http://technet.microsoft.com/en-us/library/cc778402(v=ws.10).aspx
    Group Policy Settings - Security Settings - Event Log
    http://vanstechelman.eu/windows/group_policy_settings/security_settings/event_log
    Please Note: Since the second website is not hosted by Microsoft, the link may change without notice. Microsoft does not guarantee the accuracy of
    this information.
    Best regards,
    Frank Shen

  • How to monitoring IPS event logs !

    Hi ,
    We have Some Cisco IPS and also juniper IDP sensors in our networks ,with juniper i use NSM for analyzing network logs,attacks,generating different kind of graphs and stuff like that,its so easy to work with and also its informative, but with cisco IPS devices i dont know what tools are available for online monitoring network logs, attacks and also generating graphs for my boss .I see IDM but it doesn't have the features that we need ,does any one know anything else for analyzing and monitoring logs ?
    Warm regards,
    Omid

    IME (IPS Manager Express) provides more information and reporting tool than IDM, and it can support up to 10 IPS devices/modules.
    Here is the URL for IME for your reference:
    http://www.cisco.com/en/US/products/ps9610/index.html
    Please check the system requirement for IME on the following release notes:
    http://www.cisco.com/en/US/prod/collateral/vpndevc/ps5729/ps5715/ps9610/data_sheet_c78-459033.html
    Hope that helps.

  • Event Log missing

    Hello,
    The event log seems to be overwritten after a certain period of time... I have no vent in the event log > System before the 10/13/2014 even I have 4/7/2014 for the Application event log
    1. How to have automatic backups?
    2. anyway to retrieve the old logs?
    3. How to expand the event log size?
    Thanks,
    Dom
    System Center Operations Manager 2007 / System Center Configuration Manager 2007 R2 / Forefront Client Security / Forefront Identity Manager

    Hi,
    In addition, you can check the policy settings for Application event log in Group Policy Management Editor in the path below:
    Computer Configuration\Administrative Templates\Windows Components\Event Log Service\Application
    Best regards,
    Susie

  • Windows Server 2008 R2 Security Event Log Maximum Size

    I have a customer with logging requirements on domain controllers that are exceeding the maximum log size they have configured for the security log.  When they attempted to increase the maximum size of the security event log via Group Policy, the settings
    did not take effect.  When an attempt was made to increase the security event log manually on the domain controller via the properties of the log, an error is generated whenever the value was changed.
    The Maximum Log Size specified is not valid.  It is too large or too small. The Maximum Log Size will be set to the following: 196608 KB
    The 196608 KB value is the value that it is currently set at.  Testing on other logs, application, system, has lead to the same result.  
    wevtutil.exe sl security /ms:<n> produces similar results.  There is no error message given but the value doesn't change when you run wevtutil.exe gl security
    When viewing the registry value MaxSize under HKLM\Current Control Set\Services\EventLog\Security the change is reflected, but the log does not seem to get any larger.  
    What one would expect to be a two minute change in a group policy object has turned into something much more difficult.  Any idea what could be causing this?
    Joseph M. Durnal MCM: Exchange 2010 MCITP: Enterprise Messaging Administrator, Exchange 2010 MCITP: Enterprise Messaging Administrator, MCITP: Enterprise Administrator

    I verified that it was not another policy - the domain is pretty simple without many policies, only policies applied are:
    Default Domain Policy (no event log settings)
    Company Domain Policy (no event log settings)
    Default Domain Controller Policy (no event logs settings)
    Company Domain Controller Policy (...\Event Log\Maximum security log size 4194240 kilobytes)
    The value was 196608 before, the plan was to change the group policy setting to 4194240 and I expected it to be that easy.  However, the values didn't change.
    4194240 is divisible by 64
    Used multiple tools to try and change
    Group Policy
    Event Viewer
    wevtutil.exe
    registry editor
    While some of the methods display a larger event log, the actual size of the event log still seems to be limited to 196608 kb.  
    Thanks,
    Joe
    Joseph M. Durnal MCM: Exchange 2010 MCITP: Enterprise Messaging Administrator, Exchange 2010 MCITP: Enterprise Messaging Administrator, MCITP: Enterprise Administrator

  • How to create an rule with action to subtract from the event log of Ips manager express console?

    how to create an rule with action to subtract from the event log of Ips manager express console?, some knows of has an guide?.
    Thank you.
    Sent from Cisco Technical Support iPad App

    Hi,
    http://www.cisco.com/en/US/products/sw/secursw/ps2113/products_tech_note09186a0080bc7910.shtml
    HTH
    Luis Silva
    "If you need PDI (Planning, Design, Implement) assistance feel free to reach us"
    http://www.cisco.com/web/partners/tools/pdihd.html

  • System Events Log growing in size

    My Imac is 4 months old & the Syatem Events Log is already 10 meg. in size. I have this feeling that because of it Imac starting time slightly increased (I switch off at nights).
    I tried utilities like maintenance & Onyx to delete the file without success. Is there a way to delete it? What will happen if I trash it manually?
    Appreciate any suggestion.

    OS X will automatically compress and discard old logs, IF you let it run during the night, or if you put it to sleep during the night. If you do a cold restart every morning, OS X won't automatically run the cleanup scripts.
    If you like to power it off when not in use, do the following:
    - on an admin account, open Terminal
    - enter 'sudo periodic daily weekly monthly', without the quotes, then press return. You will be asked for your admin password.
    - wait a few minutes until the command completes
    This will force the OS X maintenance scripts to run. It's not critical how often you do this, but once per month will be OK.
    Alternatively, there is a way to reschedule the daily, weekly and monthly scripts to run during the day.

  • NetBT 4321 Errors in Member Server's System Event Logs

    Hi,
    I've searched high and low and can't find a resolution to this issue.  We have approximately 30 windows server 2003 servers, most R2, all SP2.  We have 2 domain controllers - 10.0.0.10 & 10.0.0.11 (the first one holds the PDC role).
    In the System event log of nearly all the member servers is the NetBT 4321 error, with the following text:
    "The name "OURDOMAIN :1d" could not be registered on the Interface with IP address 10.0.0.43. The machine with the IP address 10.0.0.10 did not allow the name to be claimed by this machine."
    On each machine the first IP mentioned is always that machine's IP (10.0.0.43 in this case), with the second one (the one not allowing 1d to be registered) being the PDC emulator's IP (10.0.0.10).  Now I can understand why this is failing - these machines are all on the same subnet and I would guess that the domain (1d) should only be registered by the PDC emulator anyway.  What I can't work out is why these errors started appearing about 3 months ago - we can't work out what, if any, change occured at that time.
    We run a DNS-only environment (no WINS), 2k3 Native domain.  We're looking to upgrade to a 2k8 Native domain (ie upgrading our DCs) but are wanting to get this niggling issue sorted first.
    Any help would be much appreciated.
    Regards,
    Ben N.

    Hi,
    At some stage I've not been clear - no we most certainly don't have two IPs per server - the two IPs together above are the two domain controllers.
    Here's the IPconfig:
    DOMAIN CONTROLLER:
    Windows IP Configuration
    Host Name . . . . . . . . . . . . : svrdomain1
    Primary Dns Suffix . . . . . . . : us.local
    Node Type . . . . . . . . . . . . : Unknown
    IP Routing Enabled. . . . . . . . : No
    WINS Proxy Enabled. . . . . . . . : No
    DNS Suffix Search List. . . . . . : us.local
    Ethernet adapter Local Area Connection 3:
    Connection-specific DNS Suffix . :
    Description . . . . . . . . . . . : HP Network Team #1
    Physical Address. . . . . . . . . : 00-0B-CD-23-12-F9
    DHCP Enabled. . . . . . . . . . . : No
    IP Address. . . . . . . . . . . . : 10.0.0.10
    Subnet Mask . . . . . . . . . . . : 255.255.255.0
    Default Gateway . . . . . . . . . : 10.0.0.1
    DNS Servers . . . . . . . . . . . : 10.0.0.10
    10.0.0.11
    PROBLEMATIC SERVER:
    Windows IP Configuration
    Host Name . . . . . . . . . . . . : svrfile1
    Primary Dns Suffix . . . . . . . : us.local
    Node Type . . . . . . . . . . . . : Broadcast
    IP Routing Enabled. . . . . . . . : No
    WINS Proxy Enabled. . . . . . . . : No
    DNS Suffix Search List. . . . . . : us.local
    Ethernet adapter Local Area Connection:
    Connection-specific DNS Suffix . :
    Description . . . . . . . . . . . : VMware Accelerated AMD PCNet Adapter
    Physical Address. . . . . . . . . : 00-50-56-89-14-79
    DHCP Enabled. . . . . . . . . . . : No
    IP Address. . . . . . . . . . . . : 10.0.0.43
    Subnet Mask . . . . . . . . . . . : 255.255.255.0
    Default Gateway . . . . . . . . . : 10.0.0.1
    DNS Servers . . . . . . . . . . . : 10.0.0.10
    10.0.0.11
    Thanks,
    Ben.

  • VSS snapshot of 1.1TB is ending after few hours with timeout. No errors in event log

    Hello,
    does someone have experienced issue where starting making snapshot (forum GUI or command line) is taking a lot of time and then it just ends with timeout?
    I have scenario on virtualised Windows Web Server 2008 R2 where backup is being made by Idera Backup Software but since it relies on VSS Snapshots then we can just skip this point because making snapshots from directly Windows command line or drive preferences/GUI
    is ending with timeout for this single drive after few hours. Affected system has 3 drives: C - 95GB, D-1.06TB and E-120GB. C and E can be backuped correctly and only drive D has problems. System is updated with latest drivers vssadmin for writers returns
    list without any errors and snapshot for drive D which ends with timeout is not generating any error in event log. I wanted to configure VSS trace like it is being instructed on this site:
    http://publib.boulder.ibm.com/infocenter/tsminfo/v6/index.jsp?topic=%2Fcom.ibm.itsm.tshoot.doc%2Ft_pdg_traceprfrm.html
    but I don't see any trace.txt file on given location. If I remove drive D from backup process it ends without errors. System was restarted many times. Only thing which is visible in windows Event log (application part) is that "The VSS service is shutting
    down due to idle timeout." about 4 hours after snapshot making proces is starting.
    I've contacted Idera backup about this but they can't help too much if Windows snapshot process is failing. They suggested that something can be wrong with this drive but since this is virtualised machine and all of my VM are being stored on RAID10 disk
    array connected to my server using fiber connections then I don't think that this is hardware issue (especially when other two drives are located on the same LUN on disk array).
    Any suggestions?
    Regards

    Hi,
    Do you create VMs on Hyper-V or VMWare? Based on research, possible causes could be:
    1. Files changes in the volume is very huge. So the shadow size may be big and the current shadow storage my not able to hold it. And that’s cause the shadow copy creation failure. 
    2. The I/O in D drive is heavy and make the shadow copy I/O failed. 
    3. Server is too busy to handle the request.
    4. The disk is heavily defragment.
    Please refer to the articles to troubleshoot the issue:
    Time-out errors occur in Volume Shadow Copy service writers, and shadow copies are lost during backup and during times when there are high levels of input/output
    http://support.microsoft.com/kb/826936/en-us
    VSS timeouts during backup? What could contribute to that?
    https://blogs.technet.com/b/askpfeplat/archive/2012/09/12/vss-timeouts-during-backup-check-fragmentation.aspx
    Regards,
    Mandy
    We
    are trying to better understand customer views on social support experience, so your participation in this
    interview project would be greatly appreciated if you have time.
    Thanks for helping make community forums a great place.

  • Microsoft sql server extended event log file

    Dears
    Sorry for my below questions if it is very beginner level.
    In my implementation I have cluster SQL 2012 on Windows 2012; I am using MountPoints since I have many Clustered Disks.
    My MountPoint Size is only 3 GB; My Extended event log are growing fast and it is storing in the MountPoint Drive directly (Path: F:\MSSQL11.MSSQLSERVER\MSSQL\Log).
    What is the best practice to work with it? (is it to keep all Extended events? or recirculate? or to shrink? or to store in DB?)
    Is there any relation between SQL truncate and limiting the size of Extended event logs?
    How can I recirculate this Extended Events?
    How can I change the default path?
    How can I stop it?
    and in case I stop it, does this means to stop storing SQL event in Windows event Viewer?
    Thank you

    After a lot of checking, I have found below:
    My Case:
    I am having SQL Failover Cluster Instances "FCI" and I am using Mount-Points to store my Instances.
    I am having 2 Passive Copies for each FCI.
    In my configuration I choose to store the Root Instance which include the logs on Mount-Point.
    My Mount Point is 2 GB Only, which became full after few days of deployment.
    Light Technical Information:
    The Extended Event Logs files are generated Coz I have FCI, in single SQL Installation you will not find this files.
    The File Maximum size will be 100 MB.
    The Files start circulating after it become 10 Full Files.
    If you have the FCI installed as 1 Active 2 Passive, and you are doing failover between the nodes, then you will expect to see around 14 - 30 copy of this file.
    Based on above information you will need to have around 100 MB * 10 Files Per Instance copy * 3 Since in my case I have 1 Active and 2 passive instances which will = 3000 MB
    So in my case My Mount-Point was 2 GB, which become full coz of this SQLDIAG Logs.
    Solution:
    I extended my mount point by 3 GB coz I am storing this logs on it.
    In case you will need to change SQLDIAG Extended Logs Size to 50 MB for example and place to F:\Logs, then you will need below commands:
    ALTER SERVER CONFIGURATION SET DIAGNOSTICS LOG OFF;
    ALTER SERVER CONFIGURATION
    SET DIAGNOSTICS LOG MAX_SIZE = 50 MB;
    ALTER SERVER CONFIGURATION
    SET DIAGNOSTICS LOG PATH = 'F:\logs';
    ALTER SERVER CONFIGURATION SET DIAGNOSTICS LOG ON;
    After that you will need to restart the FCI from SQL Server Configuration Manager or Failover Cluster Manager.
    I wish you will find this information helpful if it is your case.
    Regards

  • Web Cache Acess.log Size

    Hi all,
    Windows 2000 Server
    Oracle Application Server 10G
    Web Cache 9.0.4.0.0
    access.log of web cache is big (500MB).
    is there any way to keep this file smaller ? kind of rotate logs ?
    if i want to analyze this file i have to load 500MB into notepad :(
    is there anything like UNIX "tail" in windows world ???

    Please check the event log settings namely 'flush interval'. Set this to be very small or diable buffering. Now check it. One possibility is that the event log's size is too small (say it has only 1 or 2 lines in it) to rollover. Also, try restarting Web cache and admin servers and try again.
    Regards,
    Priyanka GES
    Oracle Web Cache Team

  • Crystal Reports XI Crashes When Reporting on Event Log

    I have successfully connected to the event log on my local Windows 7 pc, as well as two different Windows 2003 server event logs. The report runs fine unless I include the field "DESCRIPTION" on the report. If I include that field, CR crashes with the following error in my event log:
    Faulting application name: crw32.exe, version: 11.0.0.1282, time stamp: 0x422d5c77
    Faulting module name: crheapalloc.dll, version: 9.2.0.4, time stamp: 0x422d5ade
    Exception code: 0xc0000005
    Fault offset: 0x00002454
    Faulting process id: 0x17e0
    Faulting application start time: 0x01ca58e2b9115606
    Faulting application path: C:\Program Files (x86)\Business Objects\Crystal Reports 11\crw32.exe
    Faulting module path: C:\Program Files (x86)\Common Files\Business Objects\3.0\bin\crheapalloc.dll
    Report Id: fe7f7599-c4d5-11de-a50a-001e4fe037ce
    I've found a few sites online that others have had the same problem, but I've not found a solution. Any suggestions from anyone here??

    Hi Carla, I moved this post to the database connectivity forum.
    It may be due to the size or of the text included int he description or MS is reporting the wrong size of the field.
    Other issue is XI is not supported on Windows 7 due to the age of CR and newness of Windows 7. CR XI is no longer patchable nor will any new OS platforms be added.
    What you can do though is download CR XI R2 for free and use your XI keycode to install it, then go to the Keycode Request site and get one for R2:
    Go to this link: http://www.sdn.sap.com/irj/boc and download the trial version of CR XI R2 and use your XI keycode, then apply the patches which you can get to by clicking on the BusinessObjects tab above, then Downloads.
    Test again and if it still fails you may have to wait for Service Pack 6 to come out, I believe we are adding Windows 7 to the supported OS's.
    Thank you
    Don

  • Worrying items in event log

    HI,
    I was looking at the GUI section of the Event Log of HH3, and I came across some items which are a bit worrying.
    Most of the entries in my event log look like this:
    15:40:30,31 Aug. HTTP User admin login from 192.168.1.64 successfully.
    15:40:15,31 Aug. HTTP User Basic login from 192.168.1.64 successfully.
    The IP I recognise as my own.
    But i also noticed these entries too.  in particular, the one in bold worries as it seems to suggest that someone has been able to log in to my HomeHub.
    23:17:16,29 Aug. HTTP authentication Fail from 115.47.18.xxx
    17:12:51,26 Aug. HTTP authentication success from 64.186.182.xxx
    17:12:51,26 Aug. HTTP authentication Fail from 64.186.182.xxx
    17:18:01,23 Aug. HTTP authentication Fail from 124.161.95.xxx
    I have a decent password for my HH and a decent password for my wireless.  There's no other evidence of anyone using my wireless.  Can anyone shed some light on this?  I'd be very grateful.
    Solved!
    Go to Solution.

    xpsuser wrote:
    Thank you for your reply.
    I input the other IPs into the website you linked to.  They seem to be from China.  Can anyone shed any light on this?
    Probably hackers attempting to access your home hub, the same way as Motive do. Its very unlikely they would succeed as there are a number of measures in place to stop them.
    There are some useful help pages here, for BT Broadband customers only, on my personal website.
    BT Broadband customers - help with broadband, WiFi, networking, e-mail and phones.

  • Could not add bundle to session / event log full

    Hi!
    ZCM 10.3.3 on SLES 11 SP1, Windows XP SP3.
    So far ZCM 10.3.3 was very stable, must admit, very pleased! But, I start to see some problems on - so far - few clients which I can't solve, seems to.
    Yesterday (and day before) on WXP device in computer room didn't remove DLU volatile client after logoff, yesterday same device additionally did show NAL window empty. I took a look into logs and see there may errors a'la
    [ERROR] [11/24/2011 10:11:43.824] [208] [ZenworksWindowsService] [66] [] [BundleManager] [BUNDLE.CouldNotAddBundle] [Could not add bundle 33d121df8527419ab00096c1a3b9049d to session] [] []
    [DEBUG] [11/24/2011 10:11:43.824] [208] [ZenworksWindowsService] [66] [] [MessageLogger] [] [Unable to write to event log (Application) using source (Novell.Zenworks.Logger) Exception: System.ComponentModel.Win32Exception: The event log file is full
    at System.Diagnostics.EventLog.InternalWriteEvent(UIn t32 eventID, UInt16 category, EventLogEntryType type, String() strings, Byte() rawData, String currentMachineName)
    at System.Diagnostics.EventLog.WriteEntry(String message, EventLogEntryType type, Int32 eventID, Int16 category, Byte() rawData)
    at System.Diagnostics.EventLog.WriteEntry(String source, String message, EventLogEntryType type, Int32 eventID, Int16 category, Byte() rawData)
    at System.Diagnostics.EventLog.WriteEntry(String source, String message, EventLogEntryType type, Int32 eventID)
    at log4net.Appender.EventLogAppender.Append(LoggingEv ent loggingEvent)] [] []
    Also I noticed that device-attached bundles is not working anymore, not set to start at device boot nor after user logoff.
    On another device with same symptoms I see in log many entries a'la
    [ERROR] [11/24/2011 10:26:37.038] [580] [ZenworksWindowsService] [16] [] [BundleManager] [BUNDLE.CouldNotAddBundle] [Could not add bundle 5aed9420cf9a9277fffbdcee2744981b to session] [] []
    On this device client wasn't able to login today.
    Tried zac.exe cc and also on computer room deleted zcm dir in cache folder, nothing, same result. Via ZCC I see both devices in green, I mean, ZCC show device is ok. When I try to refresh device it does it very quickly, usually it takes a little longer. ZCM server (SLES 11 SP1) seems to work ok.
    Any ideas?
    More thanks, Alar.

    I'll add here piece of logs where - I think - problem is described. Server info is changed -- server and ip pointing to the same device.
    [DEBUG] [11/25/2011 09:06:45.692] [660] [ZenworksWindowsService] [23] [] [ConnectMan] [] [ Found host server status: Good] [] []
    [DEBUG] [11/25/2011 09:06:45.692] [660] [ZenworksWindowsService] [47] [] [Remote Management Module] [] [<RMSettingsData><RemoteManagementService><RemoteCo ntrolService Enable="true"><Port>5950</Port></RemoteControlService><RemoteLoginService Enable="false"><Port>5951</Port></RemoteLoginService></RemoteManagementService><Session><ViewerDNSLookup> true</ViewerDNSLookup><AllowSessionInUserAbsence>true</AllowSessionInUserAbsence></Session><Performance><AutoBandwidthDetection>true</AutoBandwidthDetection><WallpaperSuppression>true</WallpaperSuppression><EightBitColor>false</EightBitColor><Caching>true</Caching><MirrorDriver>true</MirrorDriver></Performance><RemoteDiagnosticApps><App ID="1"><Name>SystemInformation</Name><Path>C:\Program Files\Common Files\Microsoft Shared\MSInfo\msinfo32.exe</Path></App><App ID="2"><Name>ComputerManagement</Name><Path>C:\WINDOWS\System32\compmgmt.msc</Path></App><App ID="3"><Name>Services</Name><Path>C:\WINDOWS\System32\services.msc</Path></App><App ID="4"><Name>RegistryEditor</Name><Path>C:\WINDOWS\regedit.exe</Path></App></RemoteDiagnosticApps></RMSettingsData>] [] []
    [DEBUG] [11/25/2011 09:06:45.692] [660] [ZenworksWindowsService] [23] [] [ConnectMan] [] [ Found host 199.0.8.11 status: Unknown] [] []
    [DEBUG] [11/25/2011 09:06:45.692] [660] [ZenworksWindowsService] [23] [] [ConnectMan] [] [Trying to locate source location: https://server/zenworks-bundleservice/] [] []
    [DEBUG] [11/25/2011 09:06:45.692] [660] [ZenworksWindowsService] [23] [] [ConnectMan] [] [ Host name to resolve: server] [] []
    [DEBUG] [11/25/2011 09:06:45.692] [660] [ZenworksWindowsService] [23] [] [ConnectMan] [] [ Found host: server, status: Good] [] []
    [DEBUG] [11/25/2011 09:06:45.692] [660] [ZenworksWindowsService] [23] [] [ConnectMan] [] [Marking location https://199.0.8.11/zenworks-bundleservice/ Good at the request of module bundleservice] [] []
    [DEBUG] [11/25/2011 09:06:45.692] [660] [ZenworksWindowsService] [23] [] [ConnectMan] [] [ Setting location name https://199.0.8.11/zenworks-bundleservice/ to status Good] [] []
    [DEBUG] [11/25/2011 09:06:45.692] [660] [ZenworksWindowsService] [23] [] [ConnectMan] [] [ Adding location: https://199.0.8.11/zenworks-bundleservice/, status: Good] [] []
    [DEBUG] [11/25/2011 09:06:45.692] [660] [ZenworksWindowsService] [23] [] [ConnectMan] [] [ Host: server, IP address: 199.0.8.11] [] []
    [DEBUG] [11/25/2011 09:06:45.692] [660] [ZenworksWindowsService] [23] [] [ConnectMan] [] [ Using IP address: 199.0.8.11, status: Good] [] []
    [DEBUG] [11/25/2011 09:06:45.692] [660] [ZenworksWindowsService] [23] [] [ConnectMan] [] [ Built location: https://199.0.8.11/zenworks-bundleservice/ using IP address 199.0.8.11] [] []
    [DEBUG] [11/25/2011 09:06:45.692] [660] [ZenworksWindowsService] [23] [] [ConnectMan] [] [FindFirstContent() returning https://199.0.8.11/zenworks-bundleservice/] [] []
    [DEBUG] [11/25/2011 09:06:45.692] [660] [ZenworksWindowsService] [27] [] [MessageLogger] [] [Settings passed to logger:<ZENSettings Version="1.0"><SettingConfiguration Name="LocalLog" Enabled="True" Revision="0"><Parameter Name="RollingType" Type="String" Value="Size" /><Parameter Name="BackupFiles" Type="Integer" Value="1" /><Parameter Name="FileSize" Type="Integer" Value="10" /><Parameter Name="FileSizeUnit" Type="String" Value="MB" /><Parameter Name="Severity" Type="Integer" Value="8" /></SettingConfiguration></ZENSettings>] [] []
    [DEBUG] [11/25/2011 09:06:45.692] [660] [ZenworksWindowsService] [27] [] [MessageLogger] [] [Ignoring the Settings as the revision number is same] [] []
    [DEBUG] [11/25/2011 09:06:45.692] [660] [ZenworksWindowsService] [27] [] [LOGGERCONFIGURATOR] [] [A new settings has been provided to Logger to change its configuration for localLogging] [] []
    [DEBUG] [11/25/2011 09:06:45.692] [660] [ZenworksWindowsService] [27] [] [MessageLogger] [] [Settings passed to logger:<ZENSettings Version="1.0"><SettingConfiguration Name="SystemLog" Enabled="True" Revision="0"><Parameter Name="Severity" Type="Integer" Value="12" /></SettingConfiguration></ZENSettings>] [] []
    [DEBUG] [11/25/2011 09:06:45.692] [660] [ZenworksWindowsService] [27] [] [MessageLogger] [] [Ignoring the Settings as the revision number is same] [] []
    [DEBUG] [11/25/2011 09:06:45.692] [660] [ZenworksWindowsService] [27] [] [MessageLogger] [] [Ignoring the Settings as the revision number is same] [] []
    [DEBUG] [11/25/2011 09:06:45.692] [660] [ZenworksWindowsService] [27] [] [LOGGERCONFIGURATOR] [] [A new settings has been provided to Logger to change its configuration for sysLogging] [] []
    [DEBUG] [11/25/2011 09:06:45.770] [660] [ZenworksWindowsService] [47] [] [Remote Management Module] [] [Updated the RM Configuration file.] [] []
    [DEBUG] [11/25/2011 09:06:45.848] [660] [ZenworksWindowsService] [47] [] [Remote Management Module] [] [Info: Sent ZRMConfigurationChangeEvent event to WinVNC server.] [] []
    [DEBUG] [11/25/2011 09:06:45.864] [660] [ZenworksWindowsService] [23] [] [ZenCache] [] [(Thread 23) GetObject(PROXY_OVERRIDE, UserContext{_LocalId=none; _RemoteId=(Public)}) called] [] []
    [DEBUG] [11/25/2011 09:06:45.880] [660] [ZenworksWindowsService] [23] [] [ZenCache] [] [(Thread 23) GetObject returning <not cached> in 0 ms] [] []
    [DEBUG] [11/25/2011 09:06:45.880] [660] [ZenworksWindowsService] [23] [] [ZenCache] [] [(Thread 23) GetObject(PROXY_DEFAULT, UserContext{_LocalId=none; _RemoteId=(Public)}) called] [] []
    [DEBUG] [11/25/2011 09:06:45.880] [660] [ZenworksWindowsService] [23] [] [ZenCache] [] [(Thread 23) GetObject returning <not cached> in 0 ms] [] []
    [DEBUG] [11/25/2011 09:06:45.880] [660] [ZenworksWindowsService] [23] [] [BundleManager] [] [ApplicationService GetAppService appContext.GetWebServiceURI() = https://199.0.8.11/zenworks-bundleservice/] [] []
    [DEBUG] [11/25/2011 09:06:45.880] [660] [ZenworksWindowsService] [23] [] [ZMD] [] [Soap Utility: KeepAlive is read from registry. KeepAlive = True] [] []
    [DEBUG] [11/25/2011 09:07:03.230] [660] [ZenworksWindowsService] [23] [] [BundleManager] [] [BUNDLE.CouldNotGetBundleDetailsException] [] []
    [DEBUG] [11/25/2011 09:07:03.230] [660] [ZenworksWindowsService] [23] [] [ZMD] [] [GetCurrentURIFromConnectMan - URI is bad https://199.0.8.11/zenworks-bundleservice/ trying to find another one] [] []
    [DEBUG] [11/25/2011 09:07:03.230] [660] [ZenworksWindowsService] [23] [] [ConnectMan] [] [FindNextContent()] [] []
    [DEBUG] [11/25/2011 09:07:03.230] [660] [ZenworksWindowsService] [23] [] [ConnectMan] [] [ badUri: https://199.0.8.11/zenworks-bundleservice/] [] []
    [DEBUG] [11/25/2011 09:07:03.230] [660] [ZenworksWindowsService] [23] [] [ConnectMan] [] [ Exception: There is an error in XML document (92, 393489).] [] []
    [DEBUG] [11/25/2011 09:07:03.230] [660] [ZenworksWindowsService] [23] [] [ConnectMan] [] [ ] [] []
    [DEBUG] [11/25/2011 09:07:03.230] [660] [ZenworksWindowsService] [23] [] [ConnectMan] [] [https://server/zenworks-bundleservice/ ] [] []
    [DEBUG] [11/25/2011 09:07:03.230] [660] [ZenworksWindowsService] [23] [] [ConnectMan] [] [https://199.0.8.11/zenworks-bundleservice/ ] [] []
    [DEBUG] [11/25/2011 09:07:03.230] [660] [ZenworksWindowsService] [23] [] [ConnectMan] [] [ ] [] []
    [DEBUG] [11/25/2011 09:07:03.230] [660] [ZenworksWindowsService] [23] [] [ConnectMan] [] [Marking IP Location https://server/zenworks-bundleservice/: Bad] [] []
    [DEBUG] [11/25/2011 09:07:03.230] [660] [ZenworksWindowsService] [23] [] [ConnectMan] [] [Unknown Exception] [] []
    [DEBUG] [11/25/2011 09:07:03.230] [660] [ZenworksWindowsService] [23] [] [ConnectMan] [] [There is an error in XML document (92, 393489).] [] []
    [DEBUG] [11/25/2011 09:07:03.230] [660] [ZenworksWindowsService] [23] [] [ConnectMan] [] [ at System.Xml.Serialization.XmlSerializer.Deserialize (XmlReader xmlReader, String encodingStyle, XmlDeserializationEvents events)
    at System.Xml.Serialization.XmlSerializer.Deserialize (XmlReader xmlReader, String encodingStyle)
    at System.Web.Services.Protocols.SoapHttpClientProtoc ol.ReadResponse(SoapClientMessage message, WebResponse response, Stream responseStream, Boolean asyncCall)
    at System.Web.Services.Protocols.SoapHttpClientProtoc ol.Invoke(String methodName, Object() parameters)
    at Novell.Zenworks.AppModule.Schema.ApplicationServic e.getAppDetails(GetAppDetailsRequest GetAppDetailsRequest)
    at Novell.Zenworks.AppModule.WebAppService.GetAppDeta ils(GetAppDetailsRequest request)] [] []
    [DEBUG] [11/25/2011 09:07:03.246] [660] [ZenworksWindowsService] [23] [] [ConnectMan] [] [Marking location https://199.0.8.11/zenworks-bundleservice/ Bad at the request of module bundleservice] [] []
    [DEBUG] [11/25/2011 09:07:03.246] [660] [ZenworksWindowsService] [23] [] [ConnectMan] [] [ Setting location name https://199.0.8.11/zenworks-bundleservice/ to status Bad] [] []
    [DEBUG] [11/25/2011 09:07:03.246] [660] [ZenworksWindowsService] [23] [] [ConnectMan] [] [ Exception causing location name https://199.0.8.11/zenworks-bundleservice/ to be marked Bad: System.InvalidOperationException: There is an error in XML document (92, 393489). ---> System.Xml.XmlException: The 'null' start tag on line 92 does not match the end tag of 'DestDir'. Line 92, position 393489.
    at System.Xml.XmlTextReaderImpl.Throw(Exception e)
    at System.Xml.XmlTextReaderImpl.Throw(String res, String() args)
    at System.Xml.XmlTextReaderImpl.ThrowTagMismatch(Node Data startTag)
    at System.Xml.XmlTextReaderImpl.ParseEndElement()
    at System.Xml.XmlTextReaderImpl.ParseElementContent()
    at System.Xml.XmlTextReaderImpl.Read()
    at System.Xml.XmlTextReader.Read()
    at System.Xml.XmlLoader.LoadNode(Boolean skipOverWhitespace)
    at System.Xml.XmlLoader.ReadCurrentNode(XmlDocument doc, XmlReader reader)
    at System.Xml.XmlDocument.ReadNode(XmlReader reader)
    at System.Xml.Serialization.XmlSerializationReader.Re adXmlNode(Boolean wrapped)
    at Microsoft.Xml.Serialization.GeneratedAssembly.XmlS erializationReaderApplicationService.Read14_AppDat aActionSetsInstall(Boolean isNullable, Boolean checkType)
    at Microsoft.Xml.Serialization.GeneratedAssembly.XmlS erializationReaderApplicationService.Read21_AppDat aActionSets(Boolean isNullable, Boolean checkType)
    at Microsoft.Xml.Serialization.GeneratedAssembly.XmlS erializationReaderApplicationService.Read24_AppDat a(Boolean isNullable, Boolean checkType)
    at Microsoft.Xml.Serialization.GeneratedAssembly.XmlS erializationReaderApplicationService.Read25_GetApp DetailsResponseAppResult(Boolean isNullable, Boolean checkType)
    at Microsoft.Xml.Serialization.GeneratedAssembly.XmlS erializationReaderApplicationService.Read26_GetApp DetailsResponse(Boolean isNullable, Boolean checkType)
    at Microsoft.Xml.Serialization.GeneratedAssembly.XmlS erializationReaderApplicationService.Read32_getApp DetailsResponse()
    at Microsoft.Xml.Serialization.GeneratedAssembly.Arra yOfObjectSerializer5.Deserialize(XmlSerializationR eader reader)
    at System.Xml.Serialization.XmlSerializer.Deserialize (XmlReader xmlReader, String encodingStyle, XmlDeserializationEvents events)
    --- End of inner exception stack trace ---
    at System.Xml.Serialization.XmlSerializer.Deserialize (XmlReader xmlReader, String encodingStyle, XmlDeserializationEvents events)
    at System.Xml.Serialization.XmlSerializer.Deserialize (XmlReader xmlReader, String encodingStyle)
    at System.Web.Services.Protocols.SoapHttpClientProtoc ol.ReadResponse(SoapClientMessage message, WebResponse response, Stream responseStream, Boolean asyncCall)
    at System.Web.Services.Protocols.SoapHttpClientProtoc ol.Invoke(String methodName, Object() parameters)
    at Novell.Zenworks.AppModule.Schema.ApplicationServic e.getAppDetails(GetAppDetailsRequest GetAppDetailsRequest)
    at Novell.Zenworks.AppModule.WebAppService.GetAppDeta ils(GetAppDetailsRequest request)] [] []
    [DEBUG] [11/25/2011 09:07:03.246] [660] [ZenworksWindowsService] [23] [] [ConnectMan] [] [Exiting MarkLocationBad] [] []
    [DEBUG] [11/25/2011 09:07:03.246] [660] [ZenworksWindowsService] [23] [] [ConnectMan] [] [FindFirstContent()] [] []
    [DEBUG] [11/25/2011 09:07:03.246] [660] [ZenworksWindowsService] [23] [] [ConnectMan] [] [ ] [] []
    [DEBUG] [11/25/2011 09:07:03.246] [660] [ZenworksWindowsService] [23] [] [ConnectMan] [] [ ] [] []
    [DEBUG] [11/25/2011 09:07:03.246] [660] [ZenworksWindowsService] [23] [] [ConnectMan] [] [ Found host server status: Good] [] []
    [DEBUG] [11/25/2011 09:07:03.246] [660] [ZenworksWindowsService] [23] [] [ConnectMan] [] [ Found location https://199.0.8.11/zenworks-bundleservice/ status: Bad] [] []
    [DEBUG] [11/25/2011 09:07:03.246] [660] [ZenworksWindowsService] [23] [] [ConnectMan] [] [ Skipping IP location: https://199.0.8.11/zenworks-bundleservice/, status: Bad] [] []
    [DEBUG] [11/25/2011 09:07:03.246] [660] [ZenworksWindowsService] [23] [] [ConnectMan] [] [ Found host 199.0.8.11 status: Unknown] [] []
    [DEBUG] [11/25/2011 09:07:03.246] [660] [ZenworksWindowsService] [23] [] [ConnectMan] [] [ Found location https://199.0.8.11/zenworks-bundleservice/ status: Bad] [] []
    [DEBUG] [11/25/2011 09:07:03.246] [660] [ZenworksWindowsService] [23] [] [ConnectMan] [] [ Skipping IP location: https://199.0.8.11/zenworks-bundleservice/, status: Bad] [] []
    [DEBUG] [11/25/2011 09:07:03.246] [660] [ZenworksWindowsService] [23] [] [ConnectMan] [] [Trying to locate source location: https://server/zenworks-bundleservice/] [] []
    [DEBUG] [11/25/2011 09:07:03.246] [660] [ZenworksWindowsService] [23] [] [ConnectMan] [] [ Host name to resolve: server] [] []
    [DEBUG] [11/25/2011 09:07:03.246] [660] [ZenworksWindowsService] [23] [] [ConnectMan] [] [ Found host: server, status: Good] [] []
    [DEBUG] [11/25/2011 09:07:03.246] [660] [ZenworksWindowsService] [23] [] [ConnectMan] [] [ Skipping location: https://199.0.8.11/zenworks-bundleservice/, status: Bad] [] []
    [DEBUG] [11/25/2011 09:07:03.246] [660] [ZenworksWindowsService] [23] [] [ConnectMan] [] [Trying to locate source location: https://199.0.8.11/zenworks-bundleservice/] [] []
    [DEBUG] [11/25/2011 09:07:03.246] [660] [ZenworksWindowsService] [23] [] [ConnectMan] [] [ Host name to resolve: 199.0.8.11] [] []
    [DEBUG] [11/25/2011 09:07:03.246] [660] [ZenworksWindowsService] [23] [] [ConnectMan] [] [ Found host: 199.0.8.11, status: Unknown] [] []
    [DEBUG] [11/25/2011 09:07:03.246] [660] [ZenworksWindowsService] [23] [] [ConnectMan] [] [ Host: 199.0.8.11, IP address: 199.0.8.11] [] []
    [DEBUG] [11/25/2011 09:07:03.246] [660] [ZenworksWindowsService] [23] [] [ConnectMan] [] [ Using IP address: 199.0.8.11, status: Good] [] []
    [DEBUG] [11/25/2011 09:07:03.246] [660] [ZenworksWindowsService] [23] [] [ConnectMan] [] [Entered FindServerFromBusyList] [] []
    [DEBUG] [11/25/2011 09:07:03.246] [660] [ZenworksWindowsService] [23] [] [ConnectMan] [] [ FindServerFromBusyList() Found host: server, status: Good] [] []
    [DEBUG] [11/25/2011 09:07:03.246] [660] [ZenworksWindowsService] [23] [] [ConnectMan] [] [ IP address 199.0.8.11 marked Good] [] []
    [DEBUG] [11/25/2011 09:07:03.246] [660] [ZenworksWindowsService] [23] [] [ConnectMan] [] [GetGoodOrBusyIp() returning 199.0.8.11] [] []
    [DEBUG] [11/25/2011 09:07:03.246] [660] [ZenworksWindowsService] [23] [] [ConnectMan] [] [ FindServerFromBusyList() Skipping location: https://199.0.8.11/zenworks-bundleservice/, status: Bad] [] []
    [DEBUG] [11/25/2011 09:07:03.246] [660] [ZenworksWindowsService] [23] [] [ConnectMan] [] [ FindServerFromBusyList() Found host: 199.0.8.11, status: Unknown] [] []
    [DEBUG] [11/25/2011 09:07:03.246] [660] [ZenworksWindowsService] [23] [] [ConnectMan] [] [ IP address 199.0.8.11 marked Good] [] []
    [DEBUG] [11/25/2011 09:07:03.246] [660] [ZenworksWindowsService] [23] [] [ConnectMan] [] [GetGoodOrBusyIp() returning 199.0.8.11] [] []
    [DEBUG] [11/25/2011 09:07:03.246] [660] [ZenworksWindowsService] [23] [] [ConnectMan] [] [ FindServerFromBusyList() Skipping location: https://199.0.8.11/zenworks-bundleservice/, status: Bad] [] []
    [DEBUG] [11/25/2011 09:07:03.246] [660] [ZenworksWindowsService] [23] [] [ConnectMan] [] [Exited FindServerFromBusyList with Server = to null] [] []
    [DEBUG] [11/25/2011 09:07:03.246] [660] [ZenworksWindowsService] [23] [] [ConnectMan] [] [FindFirstContent() returning ] [] []
    [DEBUG] [11/25/2011 09:07:03.246] [660] [ZenworksWindowsService] [23] [] [ConnectMan] [] [FindNextContent: Exiting with content null] [] []
    [DEBUG] [11/25/2011 09:07:03.246] [660] [ZenworksWindowsService] [23] [] [ZMD] [] [GetCurrentURIFromConnectMan - New uri is: ] [] []
    [DEBUG] [11/25/2011 09:07:03.246] [660] [ZenworksWindowsService] [23] [] [BundleManager] [] [!!!!!!!!!!! No Bundle Data Retrieved !!!!!!!!!!!!!!!!!] [] []
    [DEBUG] [11/25/2011 09:07:03.246] [660] [ZenworksWindowsService] [23] [] [BundleManager] [] [Exiting GetBundle details] [] []
    [DEBUG] [11/25/2011 09:07:03.246] [660] [ZenworksWindowsService] [23] [] [BundleManager] [] [Time for GeneralRefresh: 553] [] []
    [DEBUG] [11/25/2011 09:07:03.246] [660] [ZenworksWindowsService] [23] [] [BundleManager] [] [Found details for 3 bundles] [] []
    [DEBUG] [11/25/2011 09:07:03.246] [660] [ZenworksWindowsService] [23] [] [BundleManager] [] [ Found bundle Infutik auth; GUID: 5f49e281737695163d4c929d98844c25; Version: 0] [] []
    [DEBUG] [11/25/2011 09:07:03.246] [660] [ZenworksWindowsService] [23] [] [BundleManager] [] [ Found bundle Windows XP default ekraani-asetused; GUID: 3b78a17437ec0c9c9be7b8bb5cf484c5; Version: 2] [] []
    [DEBUG] [11/25/2011 09:07:03.246] [660] [ZenworksWindowsService] [23] [] [BundleManager] [] [ Found bundle Log-kataloog; GUID: 7b78a1535264a515dcb72a8d87485101; Version: 0] [] []
    [ERROR] [11/25/2011 09:07:03.246] [660] [ZenworksWindowsService] [23] [] [BundleManager] [BUNDLE.CouldNotAddBundle] [Could not add bundle 34ddcd7a97507d05b754a1b05be8c19a to session] [] []
    [ERROR] [11/25/2011 09:07:03.261] [660] [ZenworksWindowsService] [23] [] [BundleManager] [BUNDLE.CouldNotAddBundle] [Could not add bundle b1f973c7db610170c53eb630a381236c to session] [] []
    [ERROR] [11/25/2011 09:07:03.261] [660] [ZenworksWindowsService] [23] [] [BundleManager] [BUNDLE.CouldNotAddBundle] [Could not add bundle 0e265efd29dee160013d4030b90ebab3 to session] [] []
    [ERROR] [11/25/2011 09:07:03.261] [660] [ZenworksWindowsService] [23] [] [BundleManager] [BUNDLE.CouldNotAddBundle] [Could not add bundle 53880f0e33e70a863c6acf218814a498 to session] [] []
    [DEBUG] [11/25/2011 09:07:03.261] [660] [ZenworksWindowsService] [23] [] [MessageLogger] [] [Unable to write to event log (Application) using source (Novell.Zenworks.Logger) Exception: System.ComponentModel.Win32Exception: The event log file is full
    at System.Diagnostics.EventLog.InternalWriteEvent(UIn t32 eventID, UInt16 category, EventLogEntryType type, String() strings, Byte() rawData, String currentMachineName)
    at System.Diagnostics.EventLog.WriteEntry(String message, EventLogEntryType type, Int32 eventID, Int16 category, Byte() rawData)
    at System.Diagnostics.EventLog.WriteEntry(String source, String message, EventLogEntryType type, Int32 eventID, Int16 category, Byte() rawData)
    at System.Diagnostics.EventLog.WriteEntry(String source, String message, EventLogEntryType type, Int32 eventID)
    at log4net.Appender.EventLogAppender.Append(LoggingEv ent loggingEvent)] [] []
    [ERROR] [11/25/2011 09:07:03.261] [660] [ZenworksWindowsService] [23] [] [BundleManager] [BUNDLE.CouldNotAddBundle] [Could not add bundle e0b738c3966a354de7cd84e3e76ef366 to session] [] []
    [DEBUG] [11/25/2011 09:07:03.261] [660] [ZenworksWindowsService] [23] [] [MessageLogger] [] [Unable to write to event log (Application) using source (Novell.Zenworks.Logger) Exception: System.ComponentModel.Win32Exception: The event log file is full
    at System.Diagnostics.EventLog.InternalWriteEvent(UIn t32 eventID, UInt16 category, EventLogEntryType type, String() strings, Byte() rawData, String currentMachineName)
    at System.Diagnostics.EventLog.WriteEntry(String message, EventLogEntryType type, Int32 eventID, Int16 category, Byte() rawData)
    at System.Diagnostics.EventLog.WriteEntry(String source, String message, EventLogEntryType type, Int32 eventID, Int16 category, Byte() rawData)
    at System.Diagnostics.EventLog.WriteEntry(String source, String message, EventLogEntryType type, Int32 eventID)
    at log4net.Appender.EventLogAppender.Append(LoggingEv ent loggingEvent)] [] []
    More thanks, Alar.

Maybe you are looking for

  • How can i import my old website into iweb

    hi, my harddrive crashed and I lost all my data. When I set up OSX for new I downloaded my website (www.et-voila.net) from my ftp and I wanted to import to i-web. But I found no possibility do this. How can I work on my old (i-web made) Website with

  • Web.show_document using javascript in Forms6i

    Dear all, I wnat to know in forms6i , is it workable calling web.show_document with javascript? As I face a problem that calling a url by web.show_document, but the requirement should not display the menu bar ... how can I do? Thanks in advance. JY

  • Drag and Drop into E-Mail

    Hi, is there any way to Drag&Drop a document FROM SharePoint Doc Library IN an E-Mail (as attachment)?

  • After syncing my ipad 2 to itunes, i have no music in ipod app

    initial syncing of ipad 2 transferred all my music to the ipod app.  After syncing today, there is no music content in the ipod app.  I have tried several times to sync, but no music appears in the ipod app.  How do I fix this?

  • Problem connecting 6230 to Vista PC with Toshiba B...

    Hello, I recently got a new laptop with Vista installed. My 6230 used to connect well with my former PC (Win XP). Initially I managed to have PC Suite (6.83) work once and downloaded my contacts to the PC. Then sync stopped working for contacts but o