Monitoring EPS of an event source?
Hi,
We have a requirement to generate proper alerts whenever the EPS value
of an event source is over a predefined threshold fro a given period.
After some search on API documents I saw there is no-data alert
mechanism and also configuration for limiting dta rate from the event
source, but I could not find any mechanism for generating alert when the
event source's data rate is over some threshold value.
Is there a way to monitor eps values of event sources and generate
alerts properly?
Alternatively, limiting data-rates for database and file connectors may
be acceptable, but what about syslog event sources?
How can we catch event-drop situations so that some admin may be
informed via e-mail/sms.
Thanks,
Hakan
hkalyoncu
hkalyoncu's Profile: https://forums.netiq.com/member.php?userid=3117
View this thread: https://forums.netiq.com/showthread.php?t=46187
Well, you could easily set up a correlation rule to detect this
condition. Something as simple as:
trigger(60000, 60, discriminator(e.rv24)
would generate an alert if the number of events from a single source was
over 1000 for 60s.
This is likely to be an expensive rule, however, and may not be
necessary - you should investigate whether ESM already will complain if
the rate is exceeded.
But really I think your use case is whether events are dropped, and
that's kind of a different use case. How this works depends on the type
of source:
- For the Syslog Connector, the Syslog Event Source Server will simply
cache events that can't be processed fast enough until the system
recovers. It can cache a largish number of events, so although things
may be processed a bit late, it's unlikely to drop event data. Plus, it
will generate a nasty alert message if the entire cache overflow.
- For File/Database/WMI/etc, these are offset based so if they get
behind they will just keep working until they catch up. There's really
not much risk of losing events entirely unless the source "ages out" old
events aggressively.
In general, if a given source just keeps generating events faster than
Sentinel can process them for a really long period of time, eventually
the Collector will get so far behind that the caching or aging
mechanisms will overflow. This would be a pretty bad condition,
actually, but should also be pretty obvious - this would be something
like a single source sending > 1000 EPS for many minutes. In this case
what will really tell you if the processing is getting behind is if new
events coming into the system look "old", meaning that you start seeing
events that are from 2 minutes ago arriving at Sentinel now, and this
gets worse and worse.
Overall I guess what I'd tell your customer is something like "Look,
Sentinel makes aggressive use of caching and offset mechanisms to
prevent loss of event data under any conditions. In the very bad case
where some out-of-control source generates huge volumes of data for a
long time, you'll get some high-priority alerts from components like the
Syslog Connector. Otherwise what you'll see is that the processing just
gets a little bit behind, and then eventually catches up."
DCorlette
DCorlette's Profile: https://forums.netiq.com/member.php?userid=323
View this thread: https://forums.netiq.com/showthread.php?t=46187
Similar Messages
-
Problem with printing Event ID 811 Event Source PrintService
Hi, We are having lot of errors on our server this is not printer servers its our sql box which have 20 printers install. This server process prints.
We are using Windows 2008 R2 for printer server and The server which these errors are happening is also server 2008 R2
Log Name: Microsoft-Windows-PrintService/Operational
Source: Microsoft-Windows-PrintService
Date: 08/08/2014 07:41:43
Event ID: 811
Task Category: Executing a file operation
Level: Error
Keywords: Print Spooler
User: SYSTEM
Computer: server.Domain.com
Description:
The print spooler failed to move the file C:\Windows\system32\spool\PRTPROCS\x64\hpcpp155.dll to C:\Windows\system32\spool\PRTPROCS\x64\3_hpcpp155.dll, error code 0xb7. See the event user data for context information.
Event Xml:
<Event xmlns="http://schemas.microsoft.com/win/2004/08/events/event">
<System>
<Provider Name="Microsoft-Windows-PrintService" Guid="{747EF6FD-E535-4D16-B510-42C90F6873A1}" />
<EventID>811</EventID>
<Version>0</Version>
<Level>2</Level>
<Task>46</Task>
<Opcode>12</Opcode>
<Keywords>0x4000000000020000</Keywords>
<TimeCreated SystemTime="2014-08-08T06:41:43.723732000Z" />
<EventRecordID>20345165</EventRecordID>
<Correlation />
<Execution ProcessID="1324" ThreadID="7756" />
<Channel>Microsoft-Windows-PrintService/Operational</Channel>
<Computer>server.Domain.com</Computer>
<Security UserID="S-1-5-18" />
</System>
<UserData>
<FileOpFailed xmlns:auto-ns3="http://schemas.microsoft.com/win/2004/08/events" xmlns="http://manifests.microsoft.com/win/2005/08/windows/printing/spooler/core/events">
<Source>C:\Windows\system32\spool\PRTPROCS\x64\hpcpp155.dll</Source>
<Destination>C:\Windows\system32\spool\PRTPROCS\x64\3_hpcpp155.dll</Destination>
<Flags>0x0</Flags>
<ErrorCode>0xb7</ErrorCode>
<Context>103</Context>
</FileOpFailed>
</UserData>
</Event>Hi LalaJee,
Sorry for my delay.
On current situation, please check if new printer drivers need to be updated. Meanwhile, please refer to following
HotFix and check if can help you.
FIX: A legacy HP printer driver may crash when you run
a 32-bit application on a computer that is running a 64-bit version of Windows 7 or of Windows Server 2008 R2
If this issue still exists, please temporarily disable Print Spooler service, clear Pinter Spooler files and
re-enable the Print Spooler service. Then monitor the result.
Click Start, type
Services.msc in Run. In Services, navigate to Print Spooler service and temporarily disable it.
Then please locate to: C:\Windows\System32\spool\PRINTERS folder, clear all files in the folder.
Please enable the Print Spooler service again.
If any update, please feel free to let me know.
Hope this helps.
Best regards,
Justin Gu -
Listing possible events from event source (or DLL)
Does anyone know of a replacement for MOM 2005 resource kit tool mpwizard, which could dig out what sort of events COULD be written to event viewer logs. Not interested about a tool that could parse the existing event logs, but specifically one that is capable
of listing what could be created by DLL's that write into event viewer.
http://technet.microsoft.com/en-us/library/cc180050.aspx
http://blogs.technet.com/b/kevinholman/archive/2009/02/16/how-to-find-all-possible-event-id-s-for-a-given-event-source.aspx
If there's no replacement, how about someone digging it from their secret stash of nice tools, I didn't find it anymore
from my stash.
Thanks for thoughts and ideas!
MCT | MCSE | MCITP | MCTS SCOM, SCCM, SCVMM, SCDPM | Open CITSHi,
Based on my research, MP Event Analyzer tool is designed to help a user with functional and exploratory testing and debugging of event based management pack workflows like rules and monitors.
The tool is in System Center Operation Manager 2007 Administration Resource Kit.
Please go through the below link for more details:
http://blogs.technet.com/b/momteam/archive/2011/06/03/system-center-operations-manager-2007-r2-admin-reskit-released.aspx
Management Pack Wizard is used to create a custom Management Pack for your MOM environment. If we have SCOM 2007 R2 installed then with the operational manager console, we can use Authoring workspace to custom managed packs, and we can also export MP to
xml and then modify it by editing the xml file.
Regards,
Yan Li
Regards, Yan Li -
Event Structure with Event source: This VI and Event: Mouse Up
I downloaded an old example from 2008 on this forum and would like to duplicate it. It uses an event structure with an event case of just Mouse Up. Under Event Specifiers: the Event Source is <This VI> and Event: Mouse Up. This works like I want in LV 2009.
In LV 2009 if I choose for Event Source <This VI> under Events Mouse Up is not an option! I tried Event Source: Pane, and then Event Mouse Up is an option, but this does not trigger the event if you drag the mouse off the pane before you lift the mouse button.
I can copy the Event Structure over to my VI and rewire every case but that does not seem to be a good solution cuz I want this in several VIs.
I have attached the original VI with the Event Specifier I want. How do I get this Event Specifier in LV 2009?
Attachments:
Slider event control.vi 19 KBphillman wrote:
I downloaded an old example from 2008 on this forum and would like to duplicate it. It uses an event structure with an event case of just Mouse Up. Under Event Specifiers: the Event Source is <This VI> and Event: Mouse Up. This works like I want in LV 2009.
In LV 2009 if I choose for Event Source <This VI> under Events Mouse Up is not an option! I tried Event Source: Pane, and then Event Mouse Up is an option, but this does not trigger the event if you drag the mouse off the pane before you lift the mouse button.
So what you can do is monitor the 'Mouse Leave' event for th pane, and then start polling the mouse state.
Technically it is correct that there is no Mouse Up event detected since the Mouse Up is not happening on th epane.
Ton
Free Code Capture Tool! Version 2.1.3 with comments, web-upload, back-save and snippets!
Nederlandse LabVIEW user groep www.lvug.nl
My LabVIEW Ideas
LabVIEW, programming like it should be! -
Allow Non-Administrator accounts to create event sources and write to event logs
We are setting up BizTalk 2013 in Windows Server 2012 and one of the requirements is to allow the service account to create sources and write in event logs (Application) of the BizTalk servers. We have found what it seems to be a simple solution for this
without giving service accounts local admin rights.
Give Full control for the following registry keys to the service accounts or groups to allow creating of event sources and write to event logs:
HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\EventLog
HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\EventLog\Security
HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\EventLog\Application
HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\EventLog\Security
Note: when changing permissions for EventLog key, the child keys will inherit the permissions by default except Security key which must be done manually.
Initial tests using a .net test app seems to work as expected. New event sources are being created in the event logs and writing to the event logs after that works perfectly.
The above method has been deployed in production and this is the most suitable solution for us.Hi Keong6806,
Thanks a lot for posting and sharing here.
Do you have any other questions regarding this topic? If not I would change the type as 'Discussion' then.
Best Regards,
Elaine
Please remember to mark the replies as answers if they help and unmark them if they provide no help. If you have feedback for TechNet Subscriber Support, contact [email protected] -
Event Source: Application Error Event ID: 1000 (F1Server.exe)
Hi.
We regulary have an Application Error with "faulting module ntdll.dll" (see below).
And we can't find what is the problem.
Can you help us?
Windows Server 2003 R2 Eneterprise Edition Service Pack 2
[boot loader]
timeout=30
default=multi(0)disk(0)rdisk(0)partition(1)\WINDOWS
[operating systems]
multi(0)disk(0)rdisk(0)partition(1)\WINDOWS="Windows Server 2003, Enterprise" /noexecute=AlwaysOff /fastdetect /PAE /3Gb
Event Type: Error
Event Source: Application Error
Event Category: (100)
Event ID: 1000
Date: 1/11/2014
Time: 10:33:47 PM
User: N/A
Computer: MS-GARANT001
Description:
Faulting application F1Server.exe, version 7.9.0.0, faulting module ntdll.dll, version 5.2.3790.4937, fault address 0x00060c17.
Data:
0000: 41 70 70 6c 69 63 61 74 Applicat
0008: 69 6f 6e 20 46 61 69 6c ion Fail
0010: 75 72 65 20 20 46 31 53 ure F1S
0018: 65 72 76 65 72 2e 65 78 erver.ex
0020: 65 20 37 2e 39 2e 30 2e e 7.9.0.
0028: 30 20 69 6e 20 6e 74 64 0 in ntd
0030: 6c 6c 2e 64 6c 6c 20 35 ll.dll 5
0038: 2e 32 2e 33 37 39 30 2e .2.3790.
0040: 34 39 33 37 20 61 74 20 4937 at
0048: 6f 66 66 73 65 74 20 30 offset 0
0050: 30 30 36 30 63 31 37 0060c17Hi,
This issue may be caused by corrupted files or application conflicts. I recommend you to run "sfc /scannow" at the command prompt to check the system files. In addition, you can perform a clean boot to see if any service is causing the issue.
If the above cannot solve it, maybe you can find if there is any hotfix for the application or uninstall the application.
Best regards,
Susie -
How to get event source in phaselistener
Hello:
Is there a way to get the event source in the phaselistener ? I need to get the acion / action listener method name that will be executed for the current request in the phaselistener. Any pointers will be really helpful.
thanks and regards,
-- KannanTry:
JSF<h:commandButton action="#{myBean.actionMethodName}" value="submit" />PhaseListenerpublic void beforePhase(PhaseEvent event) {
if (event.getPhaseId() == PhaseId.INVOKE_APPLICATION) {
FacesContext context = event.getFacesContext();
Set componentIds = context.getExternalContext().getRequestParameterMap().keySet();
String action = null;
for (Iterator componentId = componentIds.iterator(); componentId.hasNext();) {
UIComponent component = context.getViewRoot().findComponent((String) componentId.next());
if (component instanceof UICommand) {
action = ((UICommand) component).getAction().getExpressionString();
break;
// action = #{myBean.actionMethodName}
}or:
JSF<h:commandButton action="#{myBean.actionMethodName}" value="submit">
<f:attribute name="method" value="actionMethodName" />
</h:commandButton>PhaseListenerpublic void beforePhase(PhaseEvent event) {
if (event.getPhaseId() == PhaseId.INVOKE_APPLICATION) {
FacesContext context = event.getFacesContext();
Set componentIds = context.getExternalContext().getRequestParameterMap().keySet();
String method = null;
for (Iterator componentId = componentIds.iterator(); componentId.hasNext();) {
UIComponent component = context.getViewRoot().findComponent((String) componentId.next());
if (component instanceof UICommand) {
method = (String) component.getAttributes().get("method");
break;
// method = actionMethodName
} -
Every morning receive Event Source MSExchange Common ID 4999
Every morning at 2/2/2012 2:06:02 AM
for weeks now we receive Event Source MSExchange Common ID
SBS 2011
Standard – Exchange 2010 => build 14.01.0355.002 (Update Rollup 6 for Exchange Server 2010 SP1)
Event Details:
Watson report about to be sent for process id: 12000, with parameters: E12, c-buddy-RTL-AMD64, 14.01.0355.001, BPA, M.E.Data.Directory, M.E.D.D.DSAccessTopologyProvider..ctor, S.IO.FileLoadException, 72f, 14.01.0355.001. ErrorReportingEnabled:
False
This is an Intel machine so we are not sure why there is “AMD64” in the details - This Event does not seem to cause any problem that we can detect.
Anyone tried
- Exchange Server 2010 SP2 December 4, 2011 Build 14.2.247.6 on a SBS2011 Standard yet? -
Since one of the KB articles – I found says -
Maybe -
http://support.microsoft.com/kb/2447629 (Rollup 3 but we have 6)Hi,
It seems that the issue is related to the special characters in the database name cause an
IndexOutOfRangeException exception. This exception crashes the
MSExchangeServicesAppPool application pool.
For more detailed information, you could refer to the article below:
Title: Event ID 4999 is logged on an Exchange Server 2010 Client Access server (CAS)
URL:
http://support.microsoft.com/kb/2665115
From the KB article resolution, you need to obtain Interim Update (IU) by contacting Microsoft Customer Service and Support.
Regards,
James
James Xiong
TechNet Community Support -
Event Source: Involflt , Event Id:68
Hello
I have done Windows updates few days ago on Server 2008 R2 and it crashed/reboot yesterday. Upon reviewing Crash Dump it point to the following.
I did extensive search and can't find any information on the following error, please if some one point me to right direction in order to avoid server crash issues.
Event Type: Error
Event Source: involflt
Event Category: None
Event ID: 68
Date: 2/20/2014
Time: 9:59:32 AM
User: N/A
Computer: PK-LA-REMOTE
Description:
Previous Change node Last Time stamp ffffffffffffffff is greater than Current Change node First Time stamp 1cf2d266eee5dda (1:1).
Data:
0000: 00 00 00 00 05 00 52 00 ......R.
0008: 00 00 00 00 44 00 12 e1 ....D..á
0010: 38 14 00 00 00 00 00 00 8.......
0018: 00 00 00 00 00 00 00 00 ........
0020: 00 00 00 00 00 00 00 00 ........
SyedHi,
Since the server crashes, you may collect and post dump file for further troubleshooting.
But forum is not the best place for analyzing dump. It’s suggested to contact Microsoft Customer Support Services (CSS) so that a dedicated Support
Professional can help you on this issue.
To obtain the phone numbers for specific technology request, please refer to the website listed below:
http://support.microsoft.com/default.aspx?scid=fh;EN-US;PHONENUMBERS’
If you are outside the US, please refer to http://support.microsoft.com for regional
support phone numbers.
Thanks for your understanding.
Regards,
Andy Qi
Andy Qi
TechNet Community Support -
How to set "VISA Read" as a event source?
I want to made the VISA Read as one of the event source.
For instance, whenever the "VISA Read" read one byte, it can creat a event, so the event can process it.
How to realize it? Thank you.hi there
please try the attached vi (not testet cause i don't have any serial device at hand).
it uses a string indicator as the data buffer. if there is new data the vi sets the "Val(Sgnl)" - property of the control which itself raises the "value changed" - event. i don't see a possibility to connect user events and VISA. there are the VISA - events (see the VISA advanced palette, but they also can't be connected to a event structure)
Best regards
chris
CL(A)Dly bending G-Force with LabVIEW
famous last words: "oh my god, it is full of stars!"
Attachments:
event_ValSignaling_7.1.vi 53 KB -
Experiencing weird issues with getting UCS working in one environment (including OWA/IM and UM). Event Source: LS Storage Service - Event ID: 32043
I've had no issues with UCS in other environments with multiple 2013 Mailbox servers and multiple 2013 CAS servers. This particular environment is having issues. I do have Exchange split with MBX and CAS.
I Followed all procedures from TechNet, NextHop, etc. I am Running same oAuth cert on all exchange and lync boxes.
I still have Lync 2010 and Exchange 2010 in the environment, since I'm in the middle of a coexistence migration but don't really want to cut over to new servers until the Lync 2013 to Exchange 2013 integration is complete and tested.
Test-CsExStorageConnectivity -SipUri [email protected]
Test-CsExStorageConnectivity : ExCreateItem exchange operation failed,
code=574, reason=StoreContext{traceId=[2048369003],
activityId=[53f4e8c5-e7e3-491a-adf4-cef37c517cb4]}StoreException:
code=ErrorUnhandledException, reason=Wrapped callback failed --->
System.InvalidOperationException: Client found response content type of '',
but expected 'text/xml'.
I have had a case opened with MS for weeks now and have torn down and rebuilt the config several times - the certificates should solid all around including using servers' FQDNs in the SN instead of just somewhere in the SAN list and using just the domain as
the SN for the oAuth certs (using the exact same cert on both Lync and Exchange for oAuth)
Any comments would be greatly appreciated
Here are the steps i did on the integration (certificates not included however they are verified)
****************** ON LYNC
Get-CsCertificate -Type OAuthTokenIssuer
Issuer : CN=dc02, DC=domain, DC=com
NotAfter : 11/12/2015 5:38:22 PM
NotBefore : 11/12/2013 5:38:22 PM
SerialNumber : 360000000901D6BF9542A0E971000100000009
Subject : CN=domain.com, OU=IT Department, O="Customer Name",
L=Santa Clarita, S=California, C=US
AlternativeNames : {}
Thumbprint : A42D2481AB68473EB25B78DAB8964ADDFF9F8245
EffectiveDate : 11/12/2013 5:48:30 PM
PreviousThumbprint :
UpdateTime :
Use : OAuthTokenIssuer
SourceScope : Global
Set-CsOAuthConfiguration -Identity Global -ExchangeAutoDiscoverURL 'https://excas02.domain.com/autodiscover/autodiscover.svc'
New-CsPartnerApplication -Identity Exchange -ApplicationTrustLevel Full -MetadataUrl "https://excas02.domain.com/autodiscover/metadata/json/1"
Identity : Exchange
AuthToken : Value=https://excas02.domain.com/au
todiscover/metadata/json/1
Name : Exchange
ApplicationIdentifier : 00000002-0000-0ff1-ce00-000000000000
Realm : domain.com
ApplicationTrustLevel : Full
AcceptSecurityIdentifierInformation : False
Enabled : True
Get-CsOAuthConfiguration
Identity : Global
PartnerApplications : {Name=Exchange;ApplicationIdentifier=00000
002-0000-0ff1-ce00-000000000000;Realm=ushw
orks.com;ApplicationTrustLevel=Full;Accept
SecurityIdentifierInformation=False;Enable
d=True}
OAuthServers : {}
Realm : domain.com
ServiceName : 00000004-0000-0ff1-ce00-000000000000
ExchangeAutodiscoverUrl : https://excas02.domain.com/autodisco
ver/autodiscover.svc
ExchangeAutodiscoverAllowedDomains :
****************** ON Exchange
[Get-AuthConfig
RunspaceId : 2b3c00ee-adbf-45a0-81d1-dc87d1e8aa6f
CurrentCertificateThumbprint : A42D2481AB68473EB25B78DAB8964ADDFF9F8245
PreviousCertificateThumbprint :
NextCertificateThumbprint :
NextCertificateEffectiveDate :
ServiceName : 00000002-0000-0ff1-ce00-000000000000
Realm :
Name : Auth Configuration
AdminDisplayName :
ExchangeVersion : 0.20 (15.0.0.0)
DistinguishedName : CN=Auth Configuration,CN=Customer,CN=Microsoft
Exchange,CN=Services,CN=Configuration,DC=domain,DC=com
Identity : Auth Configuration
Guid : db55e975-4986-49b7-a799-15ecb8c40e8f
ObjectCategory : domain.com/Configuration/Schema/ms-Exch-Auth-Auth-Config
ObjectClass : {top, container, msExchContainer, msExchAuthAuthConfig}
WhenChanged : 1/28/2014 5:37:30 PM
WhenCreated : 10/8/2013 6:35:32 PM
WhenChangedUTC : 1/29/2014 1:37:30 AM
WhenCreatedUTC : 10/9/2013 1:35:32 AM
OrganizationId :
OriginatingServer : DC04.domain.com
IsValid : True
ObjectState : Unchanged
Set-ClientAccessServer -identity excas02 -AutodiscoverServiceInternalUri 'https://excas02.domain.com/autodiscover/autodiscover.xml'
Get-ClientAccesSserver excas02 | fl
RunspaceId : 568a785b-b51f-459a-abf2-d7283744a84a
Name : EXCAS02
Fqdn : EXCAS02.domain.com
OutlookAnywhereEnabled : True
AutoDiscoverServiceCN : EXCAS02
AutoDiscoverServiceClassName : ms-Exchange-AutoDiscover-Service
AutoDiscoverServiceInternalUri : https://excas02.domain.com/autodiscover/autodiscover.xml
AutoDiscoverServiceGuid : 77378f46-2c66-4aa9-a6a6-3e7a48b19596
AutoDiscoverSiteScope : {West}
AlternateServiceAccountConfiguration :
IsOutOfService : False
WorkloadManagementPolicy : DefaultWorkloadManagementPolicy_15.0.505.0
Identity : EXCAS02
IsValid : True
ExchangeVersion : 0.1 (8.0.535.0)
DistinguishedName : CN=EXCAS02,CN=Servers,CN=Exchange Administrative Group
(FYDIBOHF23SPDLT),CN=Administrative Groups,CN=Customer,CN=Microsoft
Exchange,CN=Services,CN=Configuration,DC=domain,DC=com
Guid : 2d3b4138-a933-46e1-b5da-3f7115cb5d00
ObjectCategory : domain.com/Configuration/Schema/ms-Exch-Exchange-Server
ObjectClass : {top, server, msExchExchangeServer}
WhenChanged : 1/30/2014 11:35:25 AM
WhenCreated : 10/8/2013 7:06:35 PM
WhenChangedUTC : 1/30/2014 7:35:25 PM
WhenCreatedUTC : 10/9/2013 2:06:35 AM
OrganizationId :
OriginatingServer : DC04.domain.com
ObjectState : Unchanged
cd "C:\Program Files\Microsoft\Exchange Server\V15\Scripts\"
.\Configure-EnterPrisePartnerApplication.ps1 -AuthMetadataUrl "https://lyfe02.domain.com/metadata/json/1" -ApplicationType Lync
Creating User <LyncEnterprise-ApplicationAccount> for Partner Application.
Created User <domain.com/Users/LyncEnterprise-ApplicationAccount> for Partner Application.
Assigning role <UserApplication> to Application User <domain.com/Users/LyncEnterprise-ApplicationAccount>.
Assigning role <ArchiveApplication> to Application User <domain.com/Users/LyncEnterprise-ApplicationAccount>.
Creating Partner Application <LyncEnterprise-dd9f8b8f52fd4b4fb5f928a0d4a02b9c> using metadata <https://lyfe02.ushwor
ks.com/metadata/json/1> with linked account <domain.com/Users/LyncEnterprise-ApplicationAccount>.
Created Partner Application <LyncEnterprise-dd9f8b8f52fd4b4fb5f928a0d4a02b9c>.
THE CONFIGURATION HAS SUCCEEDED.
****************** On Lync
****************** ERROR
Test-CsExStorageConnectivity -SipUri [email protected]
Test-CsExStorageConnectivity : ExCreateItem exchange operation failed,
code=574, reason=StoreContext{traceId=[2109175579],
activityId=[cf8138ff-9436-4f56-937e-26ab8c712ab2]}StoreException:
code=ErrorUnhandledException, reason=Wrapped callback failed --->
System.InvalidOperationException: Client found response content type of '',
but expected 'text/xml'.
The request failed with an empty response.
at System.Web.Services.Protocols.SoapHttpClientProtocol.ReadResponse(SoapCli
entMessage message, WebResponse response, Stream responseStream, Boolean
asyncCall)
at
System.Web.Services.Protocols.SoapHttpClientProtocol.EndInvoke(IAsyncResult
asyncResult)
at Microsoft.Rtc.Internal.Storage.Exchange.Ews.ExchangeServiceBinding.EndInv
oke(IAsyncResult asyncResult)
at Microsoft.Rtc.Internal.Storage.Exchange.Ews.ExchangeServiceBinding.EndCre
ateItem(IAsyncResult asyncResult)
at Microsoft.Rtc.Internal.Storage.Adaptor.ExStoreAdaptor.OnCreateItemComplet
e(IAsyncResult result)
at
Microsoft.Rtc.Internal.Storage.StoreAsyncResult`1.CallbackWrapper(IAsyncResult
result)
--- End of inner exception stack trace ---
at Microsoft.Rtc.Internal.Storage.Api.StorageService.EndExecuteCommand(IAsyn
cResult asyncResult)
, exception=System.ServiceModel.FaultException:
StoreContext{traceId=[2109175579],
activityId=[cf8138ff-9436-4f56-937e-26ab8c712ab2]}StoreException:
code=ErrorUnhandledException, reason=Wrapped callback failed --->
System.InvalidOperationException: Client found response content type of '',
but expected 'text/xml'.
The request failed with an empty response.
at System.Web.Services.Protocols.SoapHttpClientProtocol.ReadResponse(SoapCli
entMessage message, WebResponse response, Stream responseStream, Boolean
asyncCall)
at
System.Web.Services.Protocols.SoapHttpClientProtocol.EndInvoke(IAsyncResult
asyncResult)
at Microsoft.Rtc.Internal.Storage.Exchange.Ews.ExchangeServiceBinding.EndInv
oke(IAsyncResult asyncResult)
at Microsoft.Rtc.Internal.Storage.Exchange.Ews.ExchangeServiceBinding.EndCre
ateItem(IAsyncResult asyncResult)
at Microsoft.Rtc.Internal.Storage.Adaptor.ExStoreAdaptor.OnCreateItemComplet
e(IAsyncResult result)
at
Microsoft.Rtc.Internal.Storage.StoreAsyncResult`1.CallbackWrapper(IAsyncResult
result)
--- End of inner exception stack trace ---
at Microsoft.Rtc.Internal.Storage.Api.StorageService.EndExecuteCommand(IAsyn
cResult asyncResult)
Server stack trace:
at
System.ServiceModel.Channels.ServiceChannel.HandleReply(ProxyOperationRuntime
operation, ProxyRpc& rpc)
at System.ServiceModel.Channels.ServiceChannel.EndCall(String action,
Object[] outs, IAsyncResult result)
at System.ServiceModel.Channels.ServiceChannelProxy.InvokeEndService(IMethod
CallMessage methodCall, ProxyOperationRuntime operation)
at System.ServiceModel.Channels.ServiceChannelProxy.Invoke(IMessage message)
Exception rethrown at [0]:
at System.Runtime.Remoting.Proxies.RealProxy.HandleReturnMessage(IMessage
reqMsg, IMessage retMsg)
at System.Runtime.Remoting.Proxies.RealProxy.PrivateInvoke(MessageData&
msgData, Int32 type)
at
Microsoft.Rtc.Internal.Storage.IStorageService.EndExecuteCommand(IAsyncResult
asyncResult)
at Microsoft.Rtc.Management.Lyss.Cmdlets.LyssCmdletCommon.ExecuteExCommand(S
toreOperation operation, String sipUri, BaseRequestType ewsRequest, Nullable`1
autoCreateParentFolder, IStorageService& client, Boolean reAuthorize), inner
exception=. Please check event log and trace for relevant information.
At line:1 char:1
+ Test-CsExStorageConnectivity -SipUri [email protected]
+ ~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~
+ CategoryInfo : InvalidOperation: (:) [Test-CsExStorageConnectiv
ity], FaultException
+ FullyQualifiedErrorId : ErrorExecuteExchangeCommandFailedWithFaultExcept
ion,Microsoft.Rtc.Management.Lyss.Cmdlets.TestExStorageConnectivityCmdlet
Test failed.
PS C:\Users\jmadsen>
JensI fixed the issue
It had to do with the Lync server still trying to access the old CAS server
For internal URLs on both CAS servers I am using the internal name, however the external url is https://webmail.domain.com
On both servers and internally that DNS record points to the old CAS server since we haven't cut over users yet
This was affecting the connection process some how Lync was using the external URL instead of the internal URL to connect to EWS
I was able to see with a packet sniffer that Lync frontend was trying to communicate with both the new CAS server and the old CAS server
When connecting to auto discovery it was connecting to the right CAS server, but after receiving the Autodiscover.xml it started connecting to webmail.ushworls.com (not EXCAS02)
I create an entry in the local HOST file on the Lync Front end server and pointed webmail.domain.com to the new CAS server
Issue Fixed – I can remove the entry from the host file after we make the DNS change internally and cut over users -
Re: Event Source Name in variable
-----BEGIN PGP SIGNED MESSAGE-----
Hash: SHA1
CollectorNodeName is a field I see populated on my Sentinel 7 system
with the name of the collector from ESM. I'm looking at SLES (vs.
database) events so the SourceHostName field is also relevant fo rseeing
the source of events and may be the same for JDBC-based events from your
database.
Good luck
-----BEGIN PGP SIGNATURE-----
Version: GnuPG v2.0.18 (GNU/Linux)
Comment: Using GnuPG with Mozilla - http://enigmail.mozdev.org/
iQIcBAEBAgAGBQJP9x3fAAoJEF+XTK08PnB58OQP/131J+Q8XJSnSUSiHtFWkku7
U+IHnHqhQrhwRYyjU0lFFzsZhn3wOcdQuS9y009+mZ9ecMNiLI C6XlO82vct4KlW
25SiJJLlzNqHH7xelv3WrnVW+CAPLg7zN1X6hPOBYjdNzFjBqd Q1ZsSn2E2seAa9
1Tz1WlZYILlhdpfNlzofReV9h2yShjwVaL/bGEhXAs4tR+HntvheZ5ghUQ+eWtho
bVwccQndGLw48oI3dmnIuFsClitV8P2hvVvfzuXMcXjNCP7Gao 1JEDARmrCKU09W
P9hmPqBB9fizRvlIPoVCwZar+afDbr/HopiX6X8JsfGi/t4MilMDMVCcol71/+R6
3UHaGH5fBlLVC9Uh5rDVKOVJXeY2tI5/q6vJAFKTNiCms9Lw/OYDhuYS0S51QUwD
I2HbEPxn8PPHJGLIPNtRU27fV4YSzCzcxfHE2nckgMTJ8gs3fA 0iHF0oF7kIixND
Pr6azrpdiuntsJgSynXXLGCstuobYyFEixCr7vaG9aqhZd6U2W Wx3mJEyMD+2Nnp
+6zixlXKDV11QZntk+HlqlHg8RwSUrw1/l9aXJ3UX1LL8LAY7lQlLFPEUWJxfy3y
NggOPvU+DsCS218UseptAH7wNYNsL4as5i5P7C0zZhRp1yXrDZ Iy+KkoaEORA/mL
4PeYVNY2aoq51YW6vnVG
=4FvU
-----END PGP SIGNATURE----------BEGIN PGP SIGNED MESSAGE-----
Hash: SHA1
Ah, well this helps a bit. A few things come to mind:
First, "legacy" (as in, non-ECMAscript) collectors will not work at all
in Sentinel 7+. If these were collectors shipped by Novell it is likely
there are newer ECMAscript versions at this point.
Regarding the ability to map values around, I'm not sure how that can be
done, though you should be able to create reports based on event sources
very easily in Sentinel 7. Not knowing how familiar you are with
Sentinel 7 I'll mention that creating reports now is significantly
easier than before. For starters, Crystal Reports is gone (unless you
have it on your own reporting against a data source populated via RDD as
it sounds like you may, which is fine of course) and instead reports can
be created, for many cases, from within the Sentinel Web UI. How
completely that UI meets your needs depends a lot on your needs, but
most customers I've talked to with either Sentinel 7 or Log Manager are
not doing a lot of customization via iReport. iReport does exist,
though, to create your own custom plugins for instances where more
customization is needed. Usually the case I have heard about most is
the need to do a query in a way that the Lucene language was not made to
query.
Good luck.
-----BEGIN PGP SIGNATURE-----
Version: GnuPG v2.0.18 (GNU/Linux)
Comment: Using GnuPG with Mozilla - http://enigmail.mozdev.org/
iQIcBAEBAgAGBQJQBB2eAAoJEF+XTK08PnB5ccEQAL4xA0ygii NIGMj2aw4+yEwO
EIPnIRhKbKGnkWlRTaiR18a5Z5HJUPM47IvGsZKo7bAlmj1cu7 IIIfK/Z9n/GqCA
JPeVr86ZWZUvBOOHNAnX264fUpOF31TEnTWVajqOnMQtpWRTyC z1bvKFjbFU5bij
820yfFYME1oT9vDgr15tZDkWr2bfpHcCxv6ZccvoRam8Jfuznq 1B+WShqHmEnEQq
xEj2ReRM70Ja6UODFs3cCUz4d6pG23K+zV558SsQvSngUsVFot p4aYKsWL6Up6EH
0oMQL7QOCcrQ59rse511B/VWlsJYGcLbksI2L1XrprIHheZbvTRjy/X60BsKhJvT
zBwHEguP7Q8A88R78+ZsKyyRgvSOfNwBQ9mxT7bFHpO+2jqI01 KgcDzLEwIf6Ejo
lN/OJyo+SO3v5NTqhL0osyDPIKDf7zCVACSxVGgrz2RmBBeaez875 qwRyDiAP2dw
Vy12NxuztkXbQQrVYlpBNyg5FNIkJuAQiq03wlQw1N3e5hBnp6 RQhAeaZWMNY6L/
qy5mYtFv1JHNhHRaWkAwlqh8rZ8WcgEzcTaYVLsGvhKRlZIZIZ dS8kV1FkfIbzQw
C2nP6wMidTjY79wMnZkTN3wlQ/XHpr6W0UwqmNsxUYQz9AHPc6Gsgne+Smt+tJTD
AxjWjC6zstZzQyBDFlVU
=JiL3
-----END PGP SIGNATURE----- -
The computer consistantly freezes for about one to two seconds over and over, making it difficult to navigate through web pages. I have looked at the Event log and this is the only consistent error that has taken place that falls in line with this
issue. I have tried changing the Security in Internet Explorer and tried every option for SSL and TLS and removed all history and cookies after each change, as well as restarting my computer, and still to no avail. Please help! Thank you.See the below:
http://social.technet.microsoft.com/Forums/en-US/67609e1a-ae35-48ef-a91a-a0b06992702f/windows-operating-system-version-61760117940-event-id-36888-event-source-schannel?forum=w7itproperf
http://social.technet.microsoft.com/Forums/en-US/eca5e2cb-28b2-4170-944b-c4c3ea7c8d72/event-id-36888-event-source-schannel?forum=winservergen
Rgds -
Problems with event source using event structure
Hello!
I'm using an event structure block. It works correctly when the event source is a control and the event is change value. But i want to use an indicator like event structure or a variable (like a matrix or a vector). I want that when the value changes, an event occurs, but it doen't work, I dont' know why?. What i have to do to work with indicators or variables in a event structure block?
Thank you in advance
Larsonof course!
regards timo
Attachments:
change_detection.vi 20 KB -
1 event listener, many events source
i have 3 different classes. 2 listens for read() from RS232, while 1 listens for read() from a socket
When any of the 3 registers a read, i will need to fire a thread with inputs from the event that processes my business logic
Most probably i will need a listener that reacts to any of the 3 events after which, spunning a thread to handle the inputs from the event and
then in a forever loop to continue to wait for new events
From what i've read, it seems that i will need a EventListener that listens to the 2 RS232 events and 1 Socket event
I am pretty new to the whole event listener concept, is there any reference code that i can take a peek at?
Many ThanksThere's no reason why the same EventListener can't be added to serveral event sources. (That's why there's a getSource() in the EventObject class).
Maybe you are looking for
-
I am sure that many of you experienced developers have read requests in the past concerning implmentation of Ward Christenen's XModem protocol over a TCP socket. If not, well... you are about to... This is a major hack... but it is starting to come t
-
Hostapd `EAPOL TX: no buffer space available' error
Hi guys, I have just configured hostapd with NAT to let my smart phone use wired network. At first, it worked normally. But recently I found that sometimes, the connection between the AP and my phone seemed to fail after some time, especially when th
-
Hi all I've on one of my machines a Sis900 Network Adapter, and with Ubuntu installed on that pc, i had to insert the line hwaddress ether 00:00:00:00:00:01 in the file /etc/network/interfaces for allowing the system to see the eth0 in the ifconfig l
-
TooManyObjectsException on Select with Where
i'm using ADF and JSF in Oracle JDeveloper Studio Edition (10.1.3.0.4) with SU5 the project I'm working on, we need to filter on week numbers and usernames, both represented as a string throughout the application. currently we are doing this by defin
-
Como instalo cert para configurar exchange en mail
buenas noches donde debo instalar un cert.cer para poder configurar el correo con mail con dicha cuenta de exchange.