Mysterious repeat log entries in System events log

I tried unsuccessfully to share internet connection with 2 iMacs without router(That doesn't matter). But after this, my iMac (24" 2.8 GHz) not networked or on internet now shows this repeated log entries every minute:
com.apple.launchd[1] (com.apple.InternetSharing): Throttling respawn: Will start in 10 seconds
This message gets repeated every minute on System events log. Daily, Monthly maintenance was not done automatically earlier today on this iMac (usually it did without any problem) which was on all-night.
I checked with Disk Utility, repaired permissions. Although no problems in working, this continuous log writings disturbs me.
Thanks for any help & Happy New Year!
Best.

Thanks, V.K. Did that (was asked password). System log showed after restart:
com.apple.launchd[1] (com.apple.InternetSharing[152]): Exited with exit code: 1
com.apple.launchd[1] (com.apple.InternetSharing): Throttling respawn: Will start in 10 seconds
com.apple.launchd[1] (com.apple.InternetSharing153): Exited with exit code: 1
com.apple.launchd[1] (com.apple.InternetSharing): Throttling respawn: Will start in 10 seconds
Then it started again the same way as above - with each aditional line each time as shown above. Thanks for sticking with me on this. Hope you will offer other suggestions.
Best.

Similar Messages

  • ZLM Event Log and System Event Log

    I just created my base ZLM server using version 7.3 and updated a test SLES 10 server to use the 7.3 agent. The SLES server was running sp1 and running the 64-bit OS. I was able to successfully upgrade the server to sp2 but I noticed I don't get any entries in the event or system event log areas. This is under the Devices > Servers > Server name I could tell if the bundles installed successfully or the device was refreshed. I don't get anything now. Any thoughts or suggestions on how to fix this?

    Oops. Sorry. Here is the output from rug ping
    ZMD 7.3.0, Copyright (C) 2009 Novell, Inc.
    Started at 4/15/2009 2:13:14 PM (uptime: 1 days, 23 hours, 33 minutes)
    RSS size: 141440
    Network Connected: Yes
    Running on Mono 1.2.6
    OS Target: SUSE Linux Enterprise Server 10.2 (x86_64)
    Module Name | Description
    -------------------+-------------------------------------------------
    Image Agent Module | Novell ZENWorks Imaging Agent
    Policy Manager | Manages policy enforcement on the device
    Settings | Handles Settings refresh events.
    TessModule | Tess Module
    Inventory | Software and Hardware inventory module for Linux
    NetworkManager | NetworkManager support
    Package Management | Package Management module for Linux
    RMModule | Remote Management module
    ZENworks Server | SOAP methods used by a ZENworks server
    Scheduled Actions | Scheduled Actions module for ZMD
    XML-RPC interface | Export ZMD public interfaces over XML-RPC
    log level is set to info
    log-level | info | Logging level (off, fatal, error, warn, info, debug)

  • Windows 8 system doesn't get internet, says system event log on service has some problem of STOP 0xC000021A error which system restarts very slowly

    Hi, my system runs on windows 8 on hp laptop envy series. All of a sudden, system event log on service stopped, errors which prevented the system to log on services. It displayed error of STOP 0xC000021A when i use system restore to roll back to previous
    configuration. Also when I tried to refresh my pc, it says i can't do changes as log in was switched to prevent the changes by notification.I don't know what to do next, I tried to put recovery dvds which I made when system was bought, now not at all working.
    Internet is not active, not able to resolve by trouble shooting and system taking lot of time to get dsktop. Previously I used to get my desktop in 10 seconds. Now its 10 min. May be I m infected with virus. My files, they are there. I tried to transfer some
    files by pendrive to another system, now the new system(where i put my files in another system) crashed, windows 7 system which does not display desktop, icons etc and not at all workable. 
    Also in my hp system, i m unable to open control panel. if its opened, it will not go off, when i use task manager, it says explorer and shuts down. I had to force restart the system. Please resolve something to get my hp laptop workable. I m waiting for
    my MS thesis to be working on that. My files are locked and no way to transfer, I fear of infected by virus to another computer also. 
    Pls give instructions to hw to set my hp laptop at the earliest without losing any of the files. Idon't want to reinstall and lose all the data for timebeing. Else, inform me the option for copying data safely. I tried to change the adv startup and recovery
    by changing the boot sequence by DVD but this also shows error 0xC000021A and asks us to see the details. I didn't understand all this. Pls help asap.
    Thanks
    venkata
    STOP 0xC000021A

    MV
    If you can boot either from the win 8 dvd or in safe mode we need the DMP files
    We do need the actual DMP file as it contains the only record of the sequence of events leading up to the crash, what drivers were loaded, and what was responsible.  
    WE NEED AT LEAST TWO DMP FILES TO SPOT TRENDS AND CONFIRM THE DIAGNOSIS.
    Please follow our instructions for finding and uploading the files we need to help you fix your computer. They can be found here
    If you have any questions about the procedure please ask
    Wanikiya and Dyami--Team Zigzag

  • Reporting Services not automatically starting. System event log 7009, Application event: 18456

    For the past month (since Oct 11,2012)  reporting services (SSRS 2008R2) is not starting after the server is rebooted. The service is set to automatically start and starts manually without a problem.  The system event log contains the following error:
    Event ID 7009: A timeout was reached (30000 milliseconds) while waiting for the SQL Server Reporting Services (MSSQLSERVER) service to connect.
    SQL logs :
    The SQL logs has many "Event 18456 Login Failed, State 38" errors when the database engine starts. I assume clients conections are failing because the databases  aren't online yet. None of these 18456 errors coorespond to the account reporting services
    runs under.
    The SQL logs indication Event 7009 occures before the "ReportingServer" database is online so im assuming there is a dependancy but I don't know how to avoid this.
    This problem is occuring on a number of our servers running SSRS (if not all)
    Any ideas?
    Paul

    Hi A141695,
    For Event ID 7009, you can try to do the steps below to resolve it.
        1. Click Start, click Run, type regedit, and then click OK.
        2. Locate and then click the following registry subkey:
            HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control
        3. Right-click Control, point to New, and then click DWORD Value.
        4. In the New Value #1 box, type ServicesPipeTimeout, and then press ENTER.
        5. Right-click ServicesPipeTimeout, and then click Modify.
        6. Click Decimal, type the number of milliseconds that you want to wait until the service times out, and then click OK.
    For example, to wait 60 seconds before the service times out, type 60000.
    Quit Registry Editor, and then restart the computer. For more information about it, please see:
    http://www.sqlservercentral.com/Forums/Topic850540-1550-1.aspx#bm851211
    http://myitforum.com/myitforumwp/2012/08/22/configmgr-2012-sms_srs_reporting_point-component-failure/
    If you have any questions, please feel free to ask.
    Regards,
    Charlie Liao
    TechNet Subscriber Support
    If you are TechNet Subscription user and have any feedback on our support quality, please send your feedback
    here.

  • Continuous "36888 Schannel Errors" in System Event Log when NOT connected to Internet

    We are hoping someone will be able to assist with us this very strange issue please ?
    We are using Windows 8.1 x64 Enterprise with Office 2013 and the latest Symantec Endpoint Proctecion v12.1.5 installed. They are managed using SCCM2012 in a large AD domain environment
    When our workstations are NOT connected to the internet (only local intranet) the following errors appear in SYSTEM event log almost continuously (several times a minute).
    Event ID:36888  User: SYSTEM  OpCode:Info  Level:Error  Source:SChannel 
    "A fatal alert was generated and sent to the remote endpoint. This may result in termination of the connection. The TLS protocol defined fatal error code is 70. The Windows Schannel error state is 11."
    The process associated with these events is "Local Security Authority Process"
    When an internet connection is enabled for these machines these 36888 errors will suddenly stop !.
    An event "Error 36887 "A fatal alert was received from the remote endpoint. The TLS protocol defined fatal alert code is 40." Is also occurring on these machines but only occasionally.
    As a result, We suspect there must be a process continuously attempting to connect to an internet service and failing ?.
    Some of the things we have tried so far;
    - We have disabled all non-essential services (e.g. Windows Store Service) one by one but this didn't fix.
    - We have tried disabling Tile updates on Start 
    - We have tried a bunch of different Group Policy settings to disable different combinations of TLS/SSL in IE config.
    - We have searched the internet forums and tried some suggested fixes but this combination of error state and error code seems unique ?.
    It doesn't happen on our Windows 7 x64 workstations that have much same apps & configuration.
    Any advice or suggestions would be greatly appreciated !
    Thanks.

    Hi Makes006,
    This Event ID 36888 occurs if a user tries to access a web site using HTTP but specifies an SSL port in the URL.
    We can try clean boot to troubleshoot whether this issue is caused by a third party program .
    How to perform a clean boot in Windows
    http://support.microsoft.com/kb/929135
    If there is no sensible impacts on operating the machines ,we can try to disable this log by modify the following registry key value to 0.
    HKEY_LOCAL_MACHINE\System\CurrentControlSet\Control\SecurityProviders\SCHANNEL\EventLogging
    For more information, please refer to the following link:
    How to enable Schannel event logging in IIS
    http://support.microsoft.com/kb/260729
    Regards,
    Please remember to mark the replies as answers if they help, and unmark the answers if they provide no help. If you have feedback for TechNet Support, contact [email protected]

  • NetBT 4321 Errors in Member Server's System Event Logs

    Hi,
    I've searched high and low and can't find a resolution to this issue.  We have approximately 30 windows server 2003 servers, most R2, all SP2.  We have 2 domain controllers - 10.0.0.10 & 10.0.0.11 (the first one holds the PDC role).
    In the System event log of nearly all the member servers is the NetBT 4321 error, with the following text:
    "The name "OURDOMAIN :1d" could not be registered on the Interface with IP address 10.0.0.43. The machine with the IP address 10.0.0.10 did not allow the name to be claimed by this machine."
    On each machine the first IP mentioned is always that machine's IP (10.0.0.43 in this case), with the second one (the one not allowing 1d to be registered) being the PDC emulator's IP (10.0.0.10).  Now I can understand why this is failing - these machines are all on the same subnet and I would guess that the domain (1d) should only be registered by the PDC emulator anyway.  What I can't work out is why these errors started appearing about 3 months ago - we can't work out what, if any, change occured at that time.
    We run a DNS-only environment (no WINS), 2k3 Native domain.  We're looking to upgrade to a 2k8 Native domain (ie upgrading our DCs) but are wanting to get this niggling issue sorted first.
    Any help would be much appreciated.
    Regards,
    Ben N.

    Hi,
    At some stage I've not been clear - no we most certainly don't have two IPs per server - the two IPs together above are the two domain controllers.
    Here's the IPconfig:
    DOMAIN CONTROLLER:
    Windows IP Configuration
    Host Name . . . . . . . . . . . . : svrdomain1
    Primary Dns Suffix . . . . . . . : us.local
    Node Type . . . . . . . . . . . . : Unknown
    IP Routing Enabled. . . . . . . . : No
    WINS Proxy Enabled. . . . . . . . : No
    DNS Suffix Search List. . . . . . : us.local
    Ethernet adapter Local Area Connection 3:
    Connection-specific DNS Suffix . :
    Description . . . . . . . . . . . : HP Network Team #1
    Physical Address. . . . . . . . . : 00-0B-CD-23-12-F9
    DHCP Enabled. . . . . . . . . . . : No
    IP Address. . . . . . . . . . . . : 10.0.0.10
    Subnet Mask . . . . . . . . . . . : 255.255.255.0
    Default Gateway . . . . . . . . . : 10.0.0.1
    DNS Servers . . . . . . . . . . . : 10.0.0.10
    10.0.0.11
    PROBLEMATIC SERVER:
    Windows IP Configuration
    Host Name . . . . . . . . . . . . : svrfile1
    Primary Dns Suffix . . . . . . . : us.local
    Node Type . . . . . . . . . . . . : Broadcast
    IP Routing Enabled. . . . . . . . : No
    WINS Proxy Enabled. . . . . . . . : No
    DNS Suffix Search List. . . . . . : us.local
    Ethernet adapter Local Area Connection:
    Connection-specific DNS Suffix . :
    Description . . . . . . . . . . . : VMware Accelerated AMD PCNet Adapter
    Physical Address. . . . . . . . . : 00-50-56-89-14-79
    DHCP Enabled. . . . . . . . . . . : No
    IP Address. . . . . . . . . . . . : 10.0.0.43
    Subnet Mask . . . . . . . . . . . : 255.255.255.0
    Default Gateway . . . . . . . . . : 10.0.0.1
    DNS Servers . . . . . . . . . . . : 10.0.0.10
    10.0.0.11
    Thanks,
    Ben.

  • Windows could not start the Cluster Service on Local computer. For more information, review the System Event Log. If this is a non-Microsoft service, contact the service vendor, and refer to service-specific error code 2.

    Dear Technet,
    Windows could not start the Cluster Service on Local computer. For more information, review the System Event Log. If this is a non-Microsoft service, contact the service vendor, and refer to service-specific error code 2.
    My cluster suddenly went disappear. and tried to restart the cluster service. When trying to restart service this above mention error comes up.
    even i tried to remove the cluster through power-shell still couldn't happen because of cluster service not running.
    Help me please.. thank you.
    Regards
    Shamil

    Hi,
    Could you confirm which account when you start the cluster service? The Cluster service is a service that requires a domain user account.
    The server cluster Setup program changes the local security policy for this account by granting a set of user rights to the account. Additionally, this account is made a member
    of the local Administrators group.
    If one or more of these user rights are missing, the Cluster service may stop immediately during startup or later, depending on when the Cluster service requires the particular
    user right.
    Hope this helps.
    We
    are trying to better understand customer views on social support experience, so your participation in this
    interview project would be greatly appreciated if you have time.
    Thanks for helping make community forums a great place.

  • Error dbconsole 11g (system event log) , and emca ?

    Hi to all
    i work on database 11g r1 on windows 7 64 bit ultimate , and i am new on dba , when i want to start dbconsole service it appear this error :
    Windows could not start the OracleDBConsoleOracl on Local Computer. For more information, review the System Event Log. If this is a non-Microsoft service, contact the system vendor, and refer to service-specific error code 1 . wha is the problem ?
    another question plz
    If I have written this command (emca -config dbcontrol db -repos recreate) .. What exactly will happen? and what is (emca log) ?
    thank you very much

    I am not clear about your 1st question but in last queation you are going to Drops the current Database Control management repository and then recreates a new one.
    http://docs.oracle.com/cd/B28359_01/server.111/b28319/emca.htm

  • System events log issue

    This appears after every startup in the system log (on my new early 2009 mac mini):
    May 19 00:41:12 my names-Computer-2 com.apple.SystemStarter[18]: Break on _THE_PROCESS_HAS_FORKED_AND_YOU_CANNOT_USE_THIS_COREFOUNDATION_FUNCTIONALITY___Y OU_MUST_EXEC_() to debug.
    May 19 00:41:12 my names-Computer-2 com.apple.SystemStarter[18]: The process has forked and you cannot use this CoreFoundation functionality safely. You MUST exec().
    Should I be concerned about this? I'd sure like to fix whatever is causing it - *it repeats more than 100 times then lists some other normal system log info - then repeats again and more system log info...* It doesn't seem to be causing any trouble but *it sure looks like it shouldn't be happening.* I'd be very grateful for any help with this issue. Thanks!

    error in last post: *MAC OS X (10.5.6)* +not 10.5.7+

  • System events log !?

    This appears after every startup in the system log (on my brand new mac mini):
    Break on _THE_PROCESS_HAS_FORKED_AND_YOU_CANNOT_USE_THIS_COREFOUNDATION_FUNCTIONALITY___Y OU_MUST_EXEC_() to debug.
    Apr 2 10:12:49 my name-Computer-2 com.apple.SystemStarter[21]: The process has forked and you cannot use this CoreFoundation functionality safely. You MUST exec().
    Should I be concerned about this? I'd sure like to fix whatever is causing it - it repeats more than 100 times then lists some other normal system log info - then repeats again and more system log info... It doesn't seem to be causing any trouble but it sure looks like it shouldn't be happening. I'd be very grateful for any help with this issue. Thanks!

    Should I be concerned about this?
    Not if the system is working as intended; that's generally the case for Console logs.
    (42229)

  • Seeing multiple DCOM errors generating event ID 10016 in System Event log

    Hi there. Our current SharePoint server running Windows Server 2003, Standard Edition SP1 and not on the domain is getting it's event logs filled up every 15 minutes to an hour with the following DCOM error:
    Event Type: Error
    Event Source: DCOM
    Event Category: None
    Event ID: 10016
    Date:  26/11/2014
    Time:  4:31:30 AM
    User:  NT AUTHORITY\NETWORK SERVICE
    Computer: xxx-xxx
    Description:
    The application-specific permission settings do not grant Local Activation permission for the COM Server application with CLSID
    {61738644-F196-11D0-9953-00C04FD919C1}
     to the user NT AUTHORITY\NETWORK SERVICE SID (S-1-5-20).  This security permission can be modified using the Component Services administrative tool.
    For more information, see Help and Support Center at
    http://go.microsoft.com/fwlink/events.asp
    I have attempted the following fix to add the local admin account to the security permissions under the following service: 61738644-F196-11D0-9953-00C04FD919C1 which was what Microsoft recommended from looking at a few random google results which had no
    effect and caused the same error to continue to happen.
    We run Windows SharePoint Services WSS 3.0 on this server which is our primary intranet server.
    Has this happened to anyone else and what would you suggest we do to fix it?

    Hi Steven,
    The results of trying this generated the same DCOM error again at the early hours of this morning as it's always done.
    The exact error generated from the server is listed below:
    Event Type: Error
    Event Source: DCOM
    Event Category: None
    Event ID: 10016
    Date:  3/12/2014
    Time:  4:31:30 AM
    User:  NT AUTHORITY\NETWORK SERVICE
    Computer: HAL-SPS
    Description:
    The application-specific permission settings do not grant Local Activation permission for the COM Server application with CLSID
    {61738644-F196-11D0-9953-00C04FD919C1}
     to the user NT AUTHORITY\NETWORK SERVICE SID (S-1-5-20).  This security permission can be modified using the Component Services administrative tool.
    For more information, see Help and Support Center at
    http://go.microsoft.com/fwlink/events.asp.
    Given this machine isn't on the domain and we have to log into it as local administrator, the local administrator account has been granted local launch and local activation permissions under IIS WAMREG admin on the server.
    Was this the correct account, or should I have granted permissions to another account?
    SB.

  • System Events Log growing in size

    My Imac is 4 months old & the Syatem Events Log is already 10 meg. in size. I have this feeling that because of it Imac starting time slightly increased (I switch off at nights).
    I tried utilities like maintenance & Onyx to delete the file without success. Is there a way to delete it? What will happen if I trash it manually?
    Appreciate any suggestion.

    OS X will automatically compress and discard old logs, IF you let it run during the night, or if you put it to sleep during the night. If you do a cold restart every morning, OS X won't automatically run the cleanup scripts.
    If you like to power it off when not in use, do the following:
    - on an admin account, open Terminal
    - enter 'sudo periodic daily weekly monthly', without the quotes, then press return. You will be asked for your admin password.
    - wait a few minutes until the command completes
    This will force the OS X maintenance scripts to run. It's not critical how often you do this, but once per month will be OK.
    Alternatively, there is a way to reschedule the daily, weekly and monthly scripts to run during the day.

  • Many events for ID 14554 appearing in System event log

    I have two 2008 R2 domain controllers and one new 2012 R2 server I just promoted to DC a few days ago. One of the 2K8R2 servers holds all the FSMO roles.   The new 2K12R2 DC is also an additional namespace server for domain-based namespace. 
    The DFS seems to be working fine, but about every 20 minutes the following 14554 event for 'DfsSvr' is logged:
    The DFS Namespaces service has successfully initialized the shared folder that hosts the namespace root. Shared folder: ourDFSnamespace
    This event does not appear on either of the two 2K8R2 DCs.

    Hi,
    My personal opinion is that there are 2 possible cause of this event: It is newly added in Windows 2012 R2 (which means it is not an issue) or the DFS namespace added on your server do have trouble in recognizing.
    Currently I did not find enough information about this event log. For a test could you try to remove Windows 2012 R2 as a referral target of this DFS namespace, force an AD replication and re-create it? If the settings is not complex you can have a try with
    creating.
    In the meantime I'll continue search to see if it is actually just a new event log in Windows 2012 R2.
    If you have any feedback on our support, please send to [email protected]

  • LocalDrive, remoteDrive error being logged to Windows Application event log

    Post Author: yday
    CA Forum: Data Integration
    Hi all,We are finding the following error messages being constantly logged to the Windows application event log:Event ID: 4096Source: Data Integrator"The error: localDrive: LocalDrive1; localDriveValue:  "andEvent ID: 4096
    Source: Data Integrator
    "The error: remoteDrive: RemoteDrive1; remoteDriveValue: "Another user noted as having the same problem in the old BO Support Forum:http://support.businessobjects.com/forums/message.asp?fid=568&mid=171195  We are also running Data Quality XI R2 (11.5.1.0) on the same server.  This problem has been happening for as long as I can remember.  It does not appear to cause any jobs to fail, but we would like to resolve this to prevent error messages being logged to computer management. Can anyone suggest a solution?  Product: Data Integrator XI R2
    Version: 11.7.0.0
    Patches Applied: None
    Operating System(s): Windows Server 2003 w SP1
    Database(s): Oracle 10gR2
    Error Messages: remoteDrive, localDrive error (as above)Steps to Reproduce: Restart the job server and the error appearsThanks and regards,York DAY

    Post Author: yday
    CA Forum: Data Integration
    Ben,
    I have just installed DI 11.7.2.0 and it is still an issue!  The bug has not been listed in the release notes in either the resolved issues section, or the known issues section.
    Australia support told me it would be fixed in the next service release.  This was well before 11.7.2.0 was released.
    I've opened another support case as I closed the last one, believing it was resolved.  From our perspective, it is not even being shown as a known issue with the product at this stage - so I will be keeping my support issue open this time until I see it is fixed.
    My support case number is 302810798 FYI.
    Rgds,York

  • RMAN ALert Log Message: ALTER SYSTEM ARCHIVE LOG

    Created a new Database on Oracle 10.2.0.4 and now seeing "ALTER SYSTEM ARCHIVE LOG" in the Alert Log only when the online RMAN backup runs:
    Wed Aug 26 21:52:03 2009
    ALTER SYSTEM ARCHIVE LOG
    Wed Aug 26 21:52:03 2009
    Thread 1 advanced to log sequence 35 (LGWR switch)
    Current log# 2 seq# 35 mem# 0: /u01/app/oracle/oradata/aatest/redo02.log
    Current log# 2 seq# 35 mem# 1: /u03/oradata/aatest/redo02a.log
    Wed Aug 26 21:53:37 2009
    ALTER SYSTEM ARCHIVE LOG
    Wed Aug 26 21:53:37 2009
    Thread 1 advanced to log sequence 36 (LGWR switch)
    Current log# 3 seq# 36 mem# 0: /u01/app/oracle/oradata/aatest/redo03.log
    Current log# 3 seq# 36 mem# 1: /u03/oradata/aatest/redo03a.log
    Wed Aug 26 21:53:40 2009
    Starting control autobackup
    Control autobackup written to DISK device
         handle '/u03/exports/backups/aatest/c-2538018370-20090826-00'
    I am not issuing a log swiitch command. The RMAN commands I am running are:
    CONFIGURE RETENTION POLICY TO REDUNDANCY 2;
    CONFIGURE CONTROLFILE AUTOBACKUP ON;
    CONFIGURE CONTROLFILE AUTOBACKUP FORMAT FOR DEVICE TYPE DISK TO '/u03/exports/backups/aatest/%F';
    CONFIGURE DEVICE TYPE DISK BACKUP TYPE TO COMPRESSED BACKUPSET;
    CONFIGURE CHANNEL DEVICE TYPE DISK FORMAT '/u03/exports/backups/aatest/%d_%U';
    BACKUP DATABASE PLUS ARCHIVELOG;
    DELETE NOPROMPT OBSOLETE;
    DELETE NOPROMPT ARCHIVELOG UNTIL TIME 'SYSDATE-2';
    I do not see this message on any other 10.2.0.4 instances. Has anyone seen this and if so why is this showing in the log?
    Thank you,
    Curt Swartzlander

    There's no problem with log switch. Please refer to documentation for more information on syntax "PLUS ARCHIVELOG"
    http://download.oracle.com/docs/cd/B19306_01/backup.102/b14192/bkup003.htm#sthref377
    Adding BACKUP ... PLUS ARCHIVELOG causes RMAN to do the following:
    *1. Runs the ALTER SYSTEM ARCHIVE LOG CURRENT command.*
    *2. Runs BACKUP ARCHIVELOG ALL. Note that if backup optimization is enabled, then RMAN skips logs that it has already backed up to the specified device.*
    *3. Backs up the rest of the files specified in BACKUP command.*
    *4. Runs the ALTER SYSTEM ARCHIVE LOG CURRENT command.*
    *5. Backs up any remaining archived logs generated during the backup.*
    This guarantees that datafile backups taken during the command are recoverable to a consistent state.

Maybe you are looking for