Version 6.84 produces many Event Logs

I have just updated from 6.83 to 6.84 and, although the software appears to be working fine, I am getting several events logged in the Application Event Log when my 6131 synchronises.
Event 1004
User NT AUTHORITY\NETWORK SERVICE
Detection of product '{A982E6CC-9F0D-4948-9B18-BDFD55DE4A72}', feature 'PCSuite', component '{9B373FD2-8E0A-4A76-80C7-63B6521FD237}' failed. The resource 'HKEY_CURRENT_USER\Software\Nokia\' does not exist.
Event 1001
User NT AUTHORITY\NETWORK SERVICE
Detection of product '{A982E6CC-9F0D-4948-9B18-BDFD55DE4A72}', feature 'Platform' failed during request for component '{7BA39C00-ED40-417C-8C5C-3804B2DDD646}'
Event 1004
User JSSOLUTIONS\John Smith
Detection of product '{A982E6CC-9F0D-4948-9B18-BDFD55DE4A72}', feature 'PCSuite', component '{9B373FD2-8E0A-4A76-80C7-63B6521FD237}' failed. The resource 'HKEY_CURRENT_USER\Software\Nokia\' does not exist.
Event 1001
User JSSOLUTIONS\John Smith
Detection of product '{A982E6CC-9F0D-4948-9B18-BDFD55DE4A72}', feature 'Platform' failed during request for component '{7BA39C00-ED40-417C-8C5C-3804B2DDD646}'
These 4 Event Log entries are repeated 3 more times.
I have tried uninstalling and reinstalling but to no avail.
I have checked the Registry and HKEY_CURRENT_USER\Software\Nokia\ does exist.
I have tried adding premissions to this key for NETWORK SERVICE (John Smith already has full premissions) again to no avail.
I am running version 6.84.10.3 of PC Suite and Windows XP Professional SP2.
Whilst this is not a big issue as the software appears to be working fine, I do like to keep clear Event Logs so would appreciate any help in getting rid of these annoying entries.
Many thanks.

Hi,
I tried to follow the post of miksu and patched with 6.84.10.4 but still the same problems...
/discussions/board/message?board.id=pcsuite&message.id=19801
So, like Jssolutions I reinstalled a previous version of Nokia PC Suite (v6.83.14.1). It works fine now... no more Event Logs
This former version can be downloaded on http://nds1.nokia.com/files/support/global/phones/software/Nokia_PC_Suite_683_rel_14_1_eng_web.exeMessage Edited by rabbyn on 23-Sep-200706:44 PM

Similar Messages

  • Spiceworks Inventory service account many failed log on attempts

    I am having a problem with the inventory feature for spiceworks 7.3. We originally had version 6.2 hosted on our internal network (Which is not connected to the internet) and besides some random issues everything worked fine. We upgraded the client to 7.3 after some discussion. After we were still able to log in and see all of our information like before. We set a new password for the service account in spiceworks and in active directory. In 24 hours our auditing software showed that there were over 120,000 failed log on attempts from spiceworks and the account was locked out. After turning off many of the new features that check the network and setting up a new password it is still producing many failed log on attempts. Does anyone have a clue what could be causing this issue? And this network cannot connect to the internet to...
    This topic first appeared in the Spiceworks Community

    http://support.apple.com/kb/TS1643
    LOL
    Only 4 years. This issue has been there since iChat 2 and was first spotted with Zyxel routers/modems.
    It has become more of an Issue when using Port Forwarding on devices that now offer Protocol selection on Port Forwarding (port 5190 on the TCP for Login and UDP fro File Sharing and pics in chats) as one port can not be forwarded to two devices (it seems to cross over to just port forwarding twice in these devices).
    I have never known it happen on a Netgear.
    It is not limited to specific devices. There is some speculation that the AIM servers get too busy on port 5190 with several dozen clients as well as iChat and AIM on a PC using the same port.
    The AIM servers will in fact allow almost any port.
    443 has been suggested here by the regular posters as port used by Mail and Web browsers fro secure connections and therefore open in Tiger and earlier Firewalls and most modems and routers because it is below the 1024 threshold where ports need to be specifically opened.
    8:03 PM Friday; June 13, 2008

  • Seemingly successful install of Exchange 2013 SP1 turns into many errors in event logs after upgrade to CU7

    I have a new Exchange 2013 server with plans to migrate from my current Exchange 2007 Server. 
    I installed Exchange 2013 SP1 and the only errors I saw in the event log seemed to be long standing known issues that did not indicate an actual problem (based on what I read online). 
    I updated to CU7 and now lots of errors have appeared (although the old ones seem to have been fixed so I have that going for me). 
    Currently the Exchange 2013 server is not in use and clients are still hitting the 2007 server.
    Issue 1)
    After each reboot I get a Kernel-EventTracing 2 error.  I cannot find anything on this on the internet so I have no idea what it is.
    Session "FastDocTracingSession" failed to start with the following error: 0xC0000035
    I did read other accounts of this error with a different name in the quotes but still can’t tell what this is or where it is coming from.
    Issue 2)
    I am still getting 5 MSExchange Common 106 errors even after reregistering all of the perf counters per this page:
    https://support.microsoft.com/kb/2870416?wa=wsignin1.0
    One of the perf counters fails to register using the script from the link above.
    66 C:\Program Files\Microsoft\Exchange Server\V15\Setup\Perf\InfoWorkerMultiMailboxSearchPerformanceCounters.xml
    New-PerfCounters : The performance counter definition file is invalid.
    At C:\Users\administrator.<my domain>\Downloads\script\ReloadPerfCounters.ps1:19 char:4
    +    New-PerfCounters -DefinitionFileName $f
    +    ~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~
        + CategoryInfo         
    : InvalidData: (:) [New-PerfCounters], TaskException
        + FullyQualifiedErrorId : [Server=VALIS,RequestId=71b6bcde-d73e-4c14-9a32-03f06e3b2607,TimeStamp=12/18/2014 10:09:
       12 PM] [FailureCategory=Cmdlet-TaskException] 33EBD286,Microsoft.Exchange.Management.Tasks.NewPerfCounters
    But that one seems unrelated to the ones that still throw errors. 
    Three of the remaining five errors are (the forum is removing my spacing between the error text so it looks like a wall of text - sorry):
    Performance counter updating error. Counter name is Count Matched LowFidelity FingerPrint, but missed HighFidelity FingerPrint, category name is MSExchange Anti-Malware Datacenter Perfcounters. Optional code: 3. Exception: The
    exception thrown is : System.InvalidOperationException: The requested Performance Counter is not a custom counter, it has to be initialized as ReadOnly.
       at System.Diagnostics.PerformanceCounter.InitializeImpl()
       at System.Diagnostics.PerformanceCounter.set_RawValue(Int64 value)
       at Microsoft.Exchange.Diagnostics.ExPerformanceCounter.set_RawValue(Int64 value)
    Last worker process info : System.ArgumentException: Process with an Id of 7384 is not running.
       at System.Diagnostics.Process.GetProcessById(Int32 processId)
       at Microsoft.Exchange.Diagnostics.ExPerformanceCounter.GetLastWorkerProcessInfo()
    Performance counter updating error. Counter name is Number of items, item is matched with finger printing cache, category name is MSExchange Anti-Malware Datacenter Perfcounters. Optional code: 3. Exception: The exception thrown
    is : System.InvalidOperationException: The requested Performance Counter is not a custom counter, it has to be initialized as ReadOnly.
       at System.Diagnostics.PerformanceCounter.InitializeImpl()
       at System.Diagnostics.PerformanceCounter.set_RawValue(Int64 value)
       at Microsoft.Exchange.Diagnostics.ExPerformanceCounter.set_RawValue(Int64 value)
    Last worker process info : System.ArgumentException: Process with an Id of 7384 is not running.
       at System.Diagnostics.Process.GetProcessById(Int32 processId)
       at Microsoft.Exchange.Diagnostics.ExPerformanceCounter.GetLastWorkerProcessInfo()
    Performance counter updating error. Counter name is Number of items in Malware Fingerprint cache, category name is MSExchange Anti-Malware Datacenter Perfcounters. Optional code: 3. Exception: The exception thrown is : System.InvalidOperationException:
    The requested Performance Counter is not a custom counter, it has to be initialized as ReadOnly.
       at System.Diagnostics.PerformanceCounter.InitializeImpl()
       at System.Diagnostics.PerformanceCounter.set_RawValue(Int64 value)
       at Microsoft.Exchange.Diagnostics.ExPerformanceCounter.set_RawValue(Int64 value)
    Last worker process info : System.ArgumentException: Process with an Id of 7384 is not running.
       at System.Diagnostics.Process.GetProcessById(Int32 processId)
       at Microsoft.Exchange.Diagnostics.ExPerformanceCounter.GetLastWorkerProcessInfo()
    Issue 3)
    I appear to have some issues related to the healthmailboxes. 
    I get MSExchangeTransport 1025 errors for multiple healthmailboxes.
    SMTP rejected a (P1) mail from 'HealthMailbox23b10b91745648819139ee691dc97eb6@<my domain>.local' with 'Client Proxy <my server>' connector and the user authenticated as 'HealthMailbox23b10b91745648819139ee691dc97eb6'. The Active Directory
    lookup for the sender address returned validation errors. Microsoft.Exchange.Data.ProviderError
    I reran setup /prepareAD to try and remedy this but I am still getting some.
    Issue 4)
    I am getting an MSExchange RBAC 74 error. 
    (Process w3wp.exe, PID 984) Connection leak detected for key <my domain>.local/Admins/Administrator in Microsoft.Exchange.Configuration.Authorization.WSManBudgetManager class. Leaked Value 1.
    Issue 5)
    I am getting MSExchange Assistants 9042 warnings on both databases.
    Service MSExchangeMailboxAssistants. Probe Time Based Assistant for database Database02 (c83dbd91-7cc4-4412-912e-1b87ca6eb0ab) is exiting a work cycle. No mailboxes were successfully processed. 2 mailboxes were skipped due to errors. 0 mailboxes were
    skipped due to failure to open a store session. 0 mailboxes were retried. There are 0 mailboxes in this database remaining to be processed.
    Some research suggested this may be related to deleted mailboxes however I have never had any actual user mailboxes on this server. 
    If they are healthmailboxes or arbitration mailboxes that might make sense but I am unsure of what to do on this.
    Issue 6)
    At boot I am getting an MSExchange ActiveSync warning 1033
    The setting SupportedIPMTypes in the Web.Config file was missing. 
    Using default value of System.Collections.Generic.List`1[System.String].
    I don't know why but this forum is removing some of my spacing that would make parts of this easier to read.

    Hi Eric
    Yes I have uninstalled and reinstalled Exchange 2013 CU7 for the 3<sup>rd</sup> time. 
    I realize you said one issue per forum thread but since I already started this thread with many issues I will at least post what I have discovered on them in case someone finds their way here from a web search.
    I have an existing Exchange 2007 server in the environment so I am unable to create email address policies that are defined by “recipient container”. 
    If I try and do so I get “You can't specify the recipient container because legacy servers are detected.”
     So I cannot create a normal email address policy and restrict it to an OU without resorting to some fancy filtering. 
    Instead what I have done is use PS to modify extensionAttribute1 (otherwise known as Custom Attribute 1 to exchange) for all of my users. 
    I then applied an address policy to them and gave it the highest priority. 
    Then I set a default email address policy for the entire organization. 
    After reinstalling Exchange all of my system mailboxes were created with the internal domain name. 
    So issue number 3 above has not come up. 
    For issue number one above I have created a new thread:
    https://social.technet.microsoft.com/Forums/office/en-US/7eb12b89-ae9b-46b2-bd34-e50cd52a4c15/microsoftwindowskerneleventtracing-error-2-happens-twice-at-boot-ex2013cu7?forum=exchangesvrdeploy
    For issue number four I have posted to this existing thread where there is so far no resolution:
    https://social.technet.microsoft.com/Forums/exchange/en-US/2343730c-7303-4067-ae1a-b106cffc3583/exchange-error-id-74-connection-leak-detected-for-key?forum=exchangesvradmin
    Issue number Five I have managed to recreate and get rid of in more than one way. 
    If I create a new database in ECP and set the database and log paths where I want, then this error will appear. 
    If I create the database in the default location and then use EMS to move it and set the log path, then the error will not appear. 
    The error will also appear (along with other errors) if I delete the health mailboxes and let them get recreated by restarting the server or the Health Manager service. 
    If I then go and set the retention period for deleted mailboxes to 0 days and wait a little while, these will all go away. 
    So my off hand guess is that these are caused by orphaned system mailboxes.
    For issue number six I have posted to this existing thread where there is so far no resolution:
    https://social.technet.microsoft.com/Forums/exchange/en-US/dff62411-fad8-4d0c-9bdb-037374644845/event-1033-msexchangeactivesync-warning?forum=exchangesvrmobility
    So for the remainder of this thread we can try and tackle issue number two which is the perf counters. 
    The exact same 5 perf counter were coming up and this had been true each time I have uninstalled and reinstalled Exchange 2013CU7. 
    Actually to be more accurate a LOT of perf counter errors come up after the initial install, but reloading the perf counters using the script I posted above reduces it to the same five. 
    Using all of your suggestions so far has not removed these 5 remaining errors either.  Since there is no discernible impact other than these errors at boot I am not seriously bothered by them but as will all event log errors, I would prefer
    to make them go away if possible.

  • Where can I find Event Log ID's, produced by Intel ICH9R RAID controller on Windows Server 2003?

    I need to monitor RAID errors and events by parsing Event Log, but I need a list of possible errors that I can find in event log. I'm using Intel ICH9R RAID controller. Server manufacturer (SuperMicro) said, that errors, produced by controller, are interpreted
    by Winows and than are put to Event Log, so I need to find this info somewhere else.

    Hi,
    As far as I know, there isn’t such as list present those Event Log ID’s for Intel ICH9R RAID controller, you may contact Intel to perform
    the further research, you may also wait for other customer's experience sharing on this.
    By the way, based on my experience, most of the IT guys will use the monitor application/toolkit comes with the RAID controller, so you may contact Intel
    also to get more information. Thanks for your understanding.
    Best Regards,
    Vincent Hu

  • Many events for ID 14554 appearing in System event log

    I have two 2008 R2 domain controllers and one new 2012 R2 server I just promoted to DC a few days ago. One of the 2K8R2 servers holds all the FSMO roles.   The new 2K12R2 DC is also an additional namespace server for domain-based namespace. 
    The DFS seems to be working fine, but about every 20 minutes the following 14554 event for 'DfsSvr' is logged:
    The DFS Namespaces service has successfully initialized the shared folder that hosts the namespace root. Shared folder: ourDFSnamespace
    This event does not appear on either of the two 2K8R2 DCs.

    Hi,
    My personal opinion is that there are 2 possible cause of this event: It is newly added in Windows 2012 R2 (which means it is not an issue) or the DFS namespace added on your server do have trouble in recognizing.
    Currently I did not find enough information about this event log. For a test could you try to remove Windows 2012 R2 as a referral target of this DFS namespace, force an AD replication and re-create it? If the settings is not complex you can have a try with
    creating.
    In the meantime I'll continue search to see if it is actually just a new event log in Windows 2012 R2.
    If you have any feedback on our support, please send to [email protected]

  • Unable to stop the event logs on access point console

    Hi team,
    I have an AIR-LAP1131AG-E-K9 access point having ios c1130-k9w8-mx.124-21a.JHB1.
    When I am trying to take the console of it there are many logs generated like LWAPP ...Go join the controller, Discover controller etc. and the ap is unable to register to the controller(2112 with ios version 6.0.199.4). I'm trying to enter the command but there are many event msg generated....How do i stop this event log. I tried entering the command no debug all. but still there are many logs...
    I want to enter the the following commands
    #lwapp ap  ip address <ip addr>.
    #lwapp a pip default-gateway <gateway ip addr>
    #lwapp ap controller ip addr <controller ip>
    #wr me
    Revert me back on urgent basis
    Thanks in advance..

    Thanks Rashika,
    Now the access point got registered to the controller..This happened becuse of country Code..
    I have changed the country code to UK, Belgium it started working fine.
    Initially when it was IN the access point was not getting register..
    But now the problem which arised is that the user is unable to get authenticated to the radius server.
    Radius server is reachable and we have done every changes required for radius server authentication.
    Users are getting rejected.
    Customer is saying that the radius server is in IN domain and the WLC/access point is in UK,BE and hence the users are unable to connect..
    Is it so??
    Rply
    Thanks in advance...

  • Questions about BT Home Hub 4A event log - WIFI c...

    Hope someone can help please ?
    I had BT inifinity installed 2 weeks ago with the HH 4 (type A) and everything has worked - connection found, no problem.
    This week, my ipod touch was unable to join the network but the iphone 5, another ipod and a tablet could connect without a problem. The ipod touch managed to connect to another WIFI used at the property and my work wifi without a problem.
    I thought it maybe the ipod touch as it was quite old but that doesn't make sense since it connects fine to other networks.  I restored network settings and other options suggested by Apple but to no avail.
    I have turned my attention to the Hub. My laptop (older than the ipod touch) gets the connection no problem along with the other devices.  I went into the hub management page but I am not smart enough to decifer the event log so would like some help so I can fix this because I thought BT infinity was the better more reliable option?
    The ipod touch Wifi IP address is 00:25:00:b7:35:f6.
    On the event log, it shows STA before the address - but it shows STA before all the device IP addresses. Should I change this to DCHP ? or is this (Static ? alright)
    The Lease on all the devices on the event log is set to 1440 min. (1 day) is that alright too, what does it mean ?
    Do I have to keep renewing the lease ? How do I do that ? I read it can be set to 21 days ?
    Going back to the IP address on the ipod it shows the Hostname as 00:25:00:B7:35:f6-2 this is different to the IP address with the -2. Could that be a cause of the unable to join network or is it because I attempted to recreate the network on the ipod so its the second version of that host name ?
    Is there any setting I can change to fix this because I am concerned the same this will happen to the other devices and then the laptop....
    What do I need to do to be able to get my ipod touch to connect to the BT network setting ?
    I think its the hub 4A causing the 'block' on the ipod touch not the device and I think its maybe a matter of changing a setting - but then why was it all fine before when Infinity was first installed ?
    Lastly my laptop (7 Years old) seems to be attached to the 5GHZ Wireless channel - is that alright ? The other more recent devices are on the 2.4ghz channel (except the ipod touch which isn't on any !!)
    Is it alright to turn the hub on / off ? -I am resisting that because I don't want to make the situation worse. 
    Sorry but what does client disassociated mean and all the BLOCKS - do they relate to firewall ?
    Please can you review the event log and my questions ?
    Many thanks
    angie 2601 
    The time frame is 3.55am 8/8/2013 - 7.16 am 8/8/2013
    (Latest (7.16am) at the top
    Message
    07:16:39, 08AUG
    (1224785.050000) Admin login successful by 192.168.1.64 on HTTP (1224766.610000) Admin login FAILED by 192.168.1.64 on HTTP (1224648.050000) New GUIsession  from IP 192.168.1.64
    (1224466.770000) Device disconnected: Hostname: Unknown-d8:dl:cb:ec:a6:fe
    IP: 192.168.1.65 MAC: d8:d1:cb:ec:a6:fe
    wlan1: STA d8:d1:cb:ec:a6:fe IEEE 802.11: Client  disassociated
    (1224362.750000) lease for IP 192.168.1.65 renewed by host Unknown­ d8:d1:cb:ec:a6:fe (MAC d8:d1:cb:ec:a6:fe).lease duration:1440 min (1224362.750000) Device connected: Hostname:Unknown-d8:d1:cb:ec:a6:feiP:
    192.168.1.65 MAC:d8:dl:cb:ec:a6:fe lease time: 1440 min. link rate:90.0 Mbps
    (1224362.690000) Lease requested
    wlan1: STA d8:d1:cb:ec:a6:fe IEEE 802.11:Client associated
    (1224241.150000) lease for IP 192.168.1.64 renewed by host FAMILY (MAC
    00:13:02:de:6d:e6). Lease duration:1440 min
    (1224241.150000) Device connected: Hostname: FAMii.Y IP:192.168.1.64 MAC:
    00:13:02:de:6d:e6 Lease time: 1440 min. link rate: 54.0 Mbps
    (1224241.090Cl00) Lease requested
    wlan1TA  00:13:02:de:6d:e6 IEEE 802.11:Client associated
    OUT: BLOCK [9] Packet invalid in connection (TCP
    192.168.1.66:34905->31.13.72.38:443 on ppp1)
    (1223644.770000) Device disconnected: Hostname: Unknown-d8:dl:cb:ec:a6:fe
    IP: 192.168.1.65 MAC: d8:d1:cb:ec:a6:fe
    wlanl: STA d8:d1:cb:ec:a6:-fe IEEE 802.11:CHent diSassociated
    (1223489.390000) Lease for IP 192.168.1.65 renewed by host Unknown­ d8:d1:cb:ec:a6:fe (MAC d8:d1:cb:ec:a6:fe).lease duration:1440 min (1223489.380000) Device connected:Hostname:Unknown-d8:dl:cb:ec:a6:fe IP:
    192.168.1.65 MAC: d kd1:cb ec:-a6-:fe Lease time: 1440 min. Link  rare: 90.0 Mbps
    (1223489.330000) Lease requested
    wlan1: STA d8:d1:cb:ec:a6:fe IEEE 802.11: Client  associated wlan1TA d8:d1:cb:ec:a6:fe IEEE 802.11: Client disasSociated
    wlan1TA d8:d1:cb:ec:a6:fe IEEE 802.11:Client associated
    OUT;BLOCK [9] Packet i valid in connection (TCP
    192.168.1.66:34375->31.13.72.38:443 on pppl)
    l'N':BLOCK [16-} Remote administration {ICMP type 8 code 0
    117.1.42.94->86.182.228.205 on ppp1)
    IN: BLOCK [9] Packet invalid in connection (TCP
    31.13.72.33:443->86.182.228.205:44156 on ppp1) IN: BLOCK [9] Packet invalid in connection (TCP
    31.13.72.33:443->86.182.228.205:36615 on ppp1)
    OUT: BLOCK [9] Packet invalid  in connection (TCP
    192.1-68.1.68:49476->173.252.103.16:443 OR ppp1)
    BLOCKED 5 more  packets (because of Packet invalid in connection) OUT: BLOCK [9] Packet invalid  in connection (TCP
    192.168.1.68:49443->95.100.195.205:443 on ppp1)
    OUT:BLOCK {9] PaCket invalid in connection (TCP
    192.168.1.68:49438->95.100.194.217:443 on ppp1)
    IN:BLOCK [9] Packet invalid in connection (TCP
    95.100.194.217:443->86.182.228.205:49444 on ppp1)
    (1222111.810000) Lease for IP 192.168.1.68 renewed by host Unknown-
    70:56:81:46:bf:d9 (MAC 70:56:81:46:bf:d9).Lease duration:1440 min
    (1222111.810000) Device connected:Hostname:Unknown-70:56:81:46:bf:d9 IP:,
    192.168.1.68 MAC:70:56:8:t:46:bf:d9lease time:1440 min. Link rate:52.0 Mbps
    (1222111.750000) Lease requested  .-
    wlanO: STA 70:56:81:46:bf:d9 IEEE 802.11: Client  associated • (1222093.690000) Device dlsconn: Hostname:Unknown-
    00:25:00:b7:35:f6-2 IP: 192.168. MAC: 00:25:00:b7:35:f6 wlanoTA  00:25:00:b7:35:f6 IEEE 802.11:Client disassociated
    OUT:BLOCK [9] Packet invalid in connection (TCP
    192.168.1.66-:43272->31.13.72.33:443 on ppp1)
    221969.130000) lease for IP 192.168.1.67 renewed  by host Unknown-
    00:25:00:b7:35:f6-2 (MAC 00:25:00:b7:35:f6). lease duration:1440 min
    (1221969.130000} Devicconnected: Hostname·:Unknowwoo·:25:00:b7 35:f6-2
    IP: 192.168.1.67 MAC: 00:25:00:b7:35:f6 Lease time: 1440 min. Unk  rate: 54.0
    Mbps
    (1221969.070000) Lease requested
    wlanO: STA 00:25:00:b7:35:f6 IEEE 802.11:Client associated
    (1220365.290000) Device disconnected: Hostname:Unknown-
    00:25:00:b7:35:f6-2 IP: 192.168.1.67 MAC: 00:25:00:b7:35:f6 wlanOTA 00:25:00:b7:35:f6 IEEE 802.11:Client disassociated
    (1220348.230000) Lease for IP 192.168.1.67 renewed by host Unlmown-
    00:25:00:b7:35:f6-2 (MAC 00:25:00:b7:35:f6).lease duration: 1440 min
    (1220348.230000) Device connected: Hostname:Unknown-00:25:00:b7:35:f6-2
    IP: 192.168.1.67 MAC: 00:25:00:b7:35:f6 Lease time: 1440 min. Unk rate: 54.0
    Mbps
    (1220348.170000) lease requested
    wlanOTA 00:25:00:b7:35:f6 IEEE 802.11:Client associated
    IN: BLOCK f16] Remote administration (TCP
    123.151.42.61:12233->86.182.228.205:8080 on ppp1) OUT: BLOCK [9] Packet invalid  in connection (TCP
    :t92.Hi8.1.66:53813->31.13.72.33:443 on ppp1)
    OUT:BLOCK [9] Packet invalid in connection (TCP
    192.168.1.66:43989->31.13.72.33:443 on ppp1)
    IN: BLOCK [16] Remote administration (ICMP type 8 rode 0
    2.7.251.109.227->86.182.228.205 on pppl)
    (1216770.650000) Device disconnected:Hostname:Unknown-
    00:25:00:b7:35:f6-2 IP: 192.168.1.67 MAC: 00:25:00:b7:35:f6
    OUT:BLOCK [9j Packet invalid in connection (TCF
    192.168.1.67:49180->74.125.136.109:993 on ppp1)
    wlanOTA 00:25:00:b7:35:f6 IEEE 802.11:Client disassociated
    (1216753.280000) Lease for IP 192.168.1.67 renewed  by host Unknown-
    00:25:00:b7:35:f6-2 (MAC 00:25:00:b7:35:f6). lease duration:1440 min
    (1216753.270000) Device connected: Hostname: Unknown-00:25:00:b7:35:f6-2
    IP: 192.168.1.67 MAC: 00:25.:00-:.b7.:35:f6 Lease time: 1440 min. Unk  rate: 54.0
    Mbps
    (1216753.220000) lease requested
    wlanO: STA 00:25:00:b7:35:f6 IEEE 802.11:Client assodat
    OUT: BLOCK [9] Packet invalid in connection (TCP
    192.168.1.66:55944->23.21.78.229:443 on ppp1)
    OUT: BLOCK [9J  Packet invafid in connection (TCP
    192.168.1.66:34794->31.13.72.33:443 on ppp1)
    OUT:BLOCK [9] Packet invalid in connection (TCP
    192.168.1.66:41441->31.13.72.33:443 on ppp1)
    {1213176.020000) Device disconnected:.Hostname:Unknown-
    00:25:00:b7:35:f6-2 IP: 192.168.1.67 MAC:00:25:00:b7:35:f6 wlanO: STA 00:25:00:b7:35:f6 IEEE 802.11: Client disassociated
    (1213158.410000) Lease for IP 192.168.1.67 renewed  by host Unknown-
    00:25:00:b7:35:f6-2 (MAC 00:25:00:b7:35:f6). lease duration:1440 min                           _./:\ (1213158.400000) Device connected:Hostname:Unknown-00:25:00:b7:35:ftt.Y IP: 192.168.1.67 MAC: 00:25:00:b7:35:f6 Lease time: 1440 min.Unk rate: 54.0
    Mbps
    (1213158.340000) Lease requested
    wlanO: STA 00:25:00:b7:35:f6 IEEE 802.11: Client associated
    OUT:BLOCK (9] Packet invalid in connection (TCP
    192.168.1.66:59767->176.34.180.243:443 on ppp1) OUT;BLOCK [9] P.acket invalid in connection {TCP
    192.168.1.66:56075->31.13.72.33:443 on ppp1) OUT: BLOCK [9] Packet invalid  in connection (TCP
    192.168.1.66 581:1:0->31.13.72.33:443 on ppp1)
    BL.OCKED 2 more packets (because of Packet invalid in connection) OUT:BLOCK [9] Packet invalid in connection (TCP
    192.168.1.66:56251->31.13.72.33:443 on ppp1)
    OUT:BLOCK [9] Packet invalid in connection (TCP
    192.168.1.66:36959->31.13.72.33:443 on ppp1)
    BlOCKED 1more packets (because of Packet invalid in connection)

    It could be that the Ipod touch is having problems with both the 2.4GHz and 5GHz frequencies being named the same. If you give them separate SSids it may help. ie add a 5 to the 5GHz SSid.
    If you do this you will need to re-connect all your devices that can see both frequencies to both SSids so that they will swap between the frequencies seamlessly when ever they need to
    See link how to change SSid.
    http://bt.custhelp.com/app/answers/detail/a_id/445​04/related/1/session/L2F2LzEvdGltZS8xMzc1OTY2ODIxL​...
    Once you have changed the SSid I would delete the network connection on the Ipod touch and start again.

  • Windows Server 2008 R2 Security Event Log Maximum Size

    I have a customer with logging requirements on domain controllers that are exceeding the maximum log size they have configured for the security log.  When they attempted to increase the maximum size of the security event log via Group Policy, the settings
    did not take effect.  When an attempt was made to increase the security event log manually on the domain controller via the properties of the log, an error is generated whenever the value was changed.
    The Maximum Log Size specified is not valid.  It is too large or too small. The Maximum Log Size will be set to the following: 196608 KB
    The 196608 KB value is the value that it is currently set at.  Testing on other logs, application, system, has lead to the same result.  
    wevtutil.exe sl security /ms:<n> produces similar results.  There is no error message given but the value doesn't change when you run wevtutil.exe gl security
    When viewing the registry value MaxSize under HKLM\Current Control Set\Services\EventLog\Security the change is reflected, but the log does not seem to get any larger.  
    What one would expect to be a two minute change in a group policy object has turned into something much more difficult.  Any idea what could be causing this?
    Joseph M. Durnal MCM: Exchange 2010 MCITP: Enterprise Messaging Administrator, Exchange 2010 MCITP: Enterprise Messaging Administrator, MCITP: Enterprise Administrator

    I verified that it was not another policy - the domain is pretty simple without many policies, only policies applied are:
    Default Domain Policy (no event log settings)
    Company Domain Policy (no event log settings)
    Default Domain Controller Policy (no event logs settings)
    Company Domain Controller Policy (...\Event Log\Maximum security log size 4194240 kilobytes)
    The value was 196608 before, the plan was to change the group policy setting to 4194240 and I expected it to be that easy.  However, the values didn't change.
    4194240 is divisible by 64
    Used multiple tools to try and change
    Group Policy
    Event Viewer
    wevtutil.exe
    registry editor
    While some of the methods display a larger event log, the actual size of the event log still seems to be limited to 196608 kb.  
    Thanks,
    Joe
    Joseph M. Durnal MCM: Exchange 2010 MCITP: Enterprise Messaging Administrator, Exchange 2010 MCITP: Enterprise Messaging Administrator, MCITP: Enterprise Administrator

  • SCOM 2012 R2 Exchange Correlation Service , we receive almost at every day in the Event log Application the Event720

    HI
    Since the SCOM was Upgrade to R2 
    Almost at every Day, we receive in the Event log application the Event 720 from the correlation service Source MSExchangeMonitoring Correlation
    This arrives always around 7:20AM, someday is at 7:19, other at 7:21. It is always approximately at the same hour, but we never have any problem during weekend
    The description of the Event
    Exceeded maximum time (15 minutes) to wait for completion of all CorrelateBatchTask threads.
    After that the correlation stop to work. At the Same time if we tried to open the SCOM Console on that server we was unable to open it. Also we was not able to open the SCOM PowerShell
    And also we cannot from that server to get which server is the RMS if we run get-SCOMRMSEmulator .  (This the RMS Server)
    When this arrive, the only thing we found, it to reboot the server or restart de SCOM service, after the Reboot the Correlation begin to work
    We got also many Event 714 Critical and after this Event 711 Warning
    Thank

    Have a look at: https://social.technet.microsoft.com/Forums/systemcenter/en-US/e75e84d9-0c9e-4d83-b3da-45a143757f85/exchange-2010-monitoring-with-scom-2012-correlation-service-issue
    One user reported an issue with the exchange correlation engine after upgrade and said that:
    I had issues with the corellation engine after upgrading scom 2012 to R2.
    The MomBidLdr.dll version changed in the SCOM directories, and needs to be updated in the:
    C:\Program Files\Microsoft\Exchange Server\v14\Bin directory.
    That seemed to stop the errors for me.
    Some troubleshooting steps listed here also:
    https://technet.microsoft.com/en-us/library/ff360495(v=exchg.140).aspx
    Cheers,
    Martin
    Blog:
    http://sustaslog.wordpress.com 
    LinkedIn:
    Note: Posts are provided “AS IS” without warranty of any kind, either expressed or implied, including but not limited to the implied warranties of merchantability and/or fitness for a particular purpose.

  • WLSE2.13 event log

    I have upgraded WLSE to version 2.13.
    After upgrading, "Unable to verify MFP configuration","MFP Timebase Invalid (bad SNTP), Device was not reachable via SNMP" these messages are logging so many on WLSE fault status. What are these mean and How to solve this problems.
    and "Client MAC Spoofing Detected on 004096ae4f8f , and on AP" this message also show up too many.What is this mean and what should i do clear this fault event log?

    For both faults, refer to Table 2-3 in Fault FAQ: http://www.cisco.com/univercd/cc/td/doc/product/rtrmgmt/cwparent/cw_1105/wlse/2_13/ts_gd/faults.htm for details on Fault Description, Explanation, Related Setting and Recommended Action

  • Could not add bundle to session / event log full

    Hi!
    ZCM 10.3.3 on SLES 11 SP1, Windows XP SP3.
    So far ZCM 10.3.3 was very stable, must admit, very pleased! But, I start to see some problems on - so far - few clients which I can't solve, seems to.
    Yesterday (and day before) on WXP device in computer room didn't remove DLU volatile client after logoff, yesterday same device additionally did show NAL window empty. I took a look into logs and see there may errors a'la
    [ERROR] [11/24/2011 10:11:43.824] [208] [ZenworksWindowsService] [66] [] [BundleManager] [BUNDLE.CouldNotAddBundle] [Could not add bundle 33d121df8527419ab00096c1a3b9049d to session] [] []
    [DEBUG] [11/24/2011 10:11:43.824] [208] [ZenworksWindowsService] [66] [] [MessageLogger] [] [Unable to write to event log (Application) using source (Novell.Zenworks.Logger) Exception: System.ComponentModel.Win32Exception: The event log file is full
    at System.Diagnostics.EventLog.InternalWriteEvent(UIn t32 eventID, UInt16 category, EventLogEntryType type, String() strings, Byte() rawData, String currentMachineName)
    at System.Diagnostics.EventLog.WriteEntry(String message, EventLogEntryType type, Int32 eventID, Int16 category, Byte() rawData)
    at System.Diagnostics.EventLog.WriteEntry(String source, String message, EventLogEntryType type, Int32 eventID, Int16 category, Byte() rawData)
    at System.Diagnostics.EventLog.WriteEntry(String source, String message, EventLogEntryType type, Int32 eventID)
    at log4net.Appender.EventLogAppender.Append(LoggingEv ent loggingEvent)] [] []
    Also I noticed that device-attached bundles is not working anymore, not set to start at device boot nor after user logoff.
    On another device with same symptoms I see in log many entries a'la
    [ERROR] [11/24/2011 10:26:37.038] [580] [ZenworksWindowsService] [16] [] [BundleManager] [BUNDLE.CouldNotAddBundle] [Could not add bundle 5aed9420cf9a9277fffbdcee2744981b to session] [] []
    On this device client wasn't able to login today.
    Tried zac.exe cc and also on computer room deleted zcm dir in cache folder, nothing, same result. Via ZCC I see both devices in green, I mean, ZCC show device is ok. When I try to refresh device it does it very quickly, usually it takes a little longer. ZCM server (SLES 11 SP1) seems to work ok.
    Any ideas?
    More thanks, Alar.

    I'll add here piece of logs where - I think - problem is described. Server info is changed -- server and ip pointing to the same device.
    [DEBUG] [11/25/2011 09:06:45.692] [660] [ZenworksWindowsService] [23] [] [ConnectMan] [] [ Found host server status: Good] [] []
    [DEBUG] [11/25/2011 09:06:45.692] [660] [ZenworksWindowsService] [47] [] [Remote Management Module] [] [<RMSettingsData><RemoteManagementService><RemoteCo ntrolService Enable="true"><Port>5950</Port></RemoteControlService><RemoteLoginService Enable="false"><Port>5951</Port></RemoteLoginService></RemoteManagementService><Session><ViewerDNSLookup> true</ViewerDNSLookup><AllowSessionInUserAbsence>true</AllowSessionInUserAbsence></Session><Performance><AutoBandwidthDetection>true</AutoBandwidthDetection><WallpaperSuppression>true</WallpaperSuppression><EightBitColor>false</EightBitColor><Caching>true</Caching><MirrorDriver>true</MirrorDriver></Performance><RemoteDiagnosticApps><App ID="1"><Name>SystemInformation</Name><Path>C:\Program Files\Common Files\Microsoft Shared\MSInfo\msinfo32.exe</Path></App><App ID="2"><Name>ComputerManagement</Name><Path>C:\WINDOWS\System32\compmgmt.msc</Path></App><App ID="3"><Name>Services</Name><Path>C:\WINDOWS\System32\services.msc</Path></App><App ID="4"><Name>RegistryEditor</Name><Path>C:\WINDOWS\regedit.exe</Path></App></RemoteDiagnosticApps></RMSettingsData>] [] []
    [DEBUG] [11/25/2011 09:06:45.692] [660] [ZenworksWindowsService] [23] [] [ConnectMan] [] [ Found host 199.0.8.11 status: Unknown] [] []
    [DEBUG] [11/25/2011 09:06:45.692] [660] [ZenworksWindowsService] [23] [] [ConnectMan] [] [Trying to locate source location: https://server/zenworks-bundleservice/] [] []
    [DEBUG] [11/25/2011 09:06:45.692] [660] [ZenworksWindowsService] [23] [] [ConnectMan] [] [ Host name to resolve: server] [] []
    [DEBUG] [11/25/2011 09:06:45.692] [660] [ZenworksWindowsService] [23] [] [ConnectMan] [] [ Found host: server, status: Good] [] []
    [DEBUG] [11/25/2011 09:06:45.692] [660] [ZenworksWindowsService] [23] [] [ConnectMan] [] [Marking location https://199.0.8.11/zenworks-bundleservice/ Good at the request of module bundleservice] [] []
    [DEBUG] [11/25/2011 09:06:45.692] [660] [ZenworksWindowsService] [23] [] [ConnectMan] [] [ Setting location name https://199.0.8.11/zenworks-bundleservice/ to status Good] [] []
    [DEBUG] [11/25/2011 09:06:45.692] [660] [ZenworksWindowsService] [23] [] [ConnectMan] [] [ Adding location: https://199.0.8.11/zenworks-bundleservice/, status: Good] [] []
    [DEBUG] [11/25/2011 09:06:45.692] [660] [ZenworksWindowsService] [23] [] [ConnectMan] [] [ Host: server, IP address: 199.0.8.11] [] []
    [DEBUG] [11/25/2011 09:06:45.692] [660] [ZenworksWindowsService] [23] [] [ConnectMan] [] [ Using IP address: 199.0.8.11, status: Good] [] []
    [DEBUG] [11/25/2011 09:06:45.692] [660] [ZenworksWindowsService] [23] [] [ConnectMan] [] [ Built location: https://199.0.8.11/zenworks-bundleservice/ using IP address 199.0.8.11] [] []
    [DEBUG] [11/25/2011 09:06:45.692] [660] [ZenworksWindowsService] [23] [] [ConnectMan] [] [FindFirstContent() returning https://199.0.8.11/zenworks-bundleservice/] [] []
    [DEBUG] [11/25/2011 09:06:45.692] [660] [ZenworksWindowsService] [27] [] [MessageLogger] [] [Settings passed to logger:<ZENSettings Version="1.0"><SettingConfiguration Name="LocalLog" Enabled="True" Revision="0"><Parameter Name="RollingType" Type="String" Value="Size" /><Parameter Name="BackupFiles" Type="Integer" Value="1" /><Parameter Name="FileSize" Type="Integer" Value="10" /><Parameter Name="FileSizeUnit" Type="String" Value="MB" /><Parameter Name="Severity" Type="Integer" Value="8" /></SettingConfiguration></ZENSettings>] [] []
    [DEBUG] [11/25/2011 09:06:45.692] [660] [ZenworksWindowsService] [27] [] [MessageLogger] [] [Ignoring the Settings as the revision number is same] [] []
    [DEBUG] [11/25/2011 09:06:45.692] [660] [ZenworksWindowsService] [27] [] [LOGGERCONFIGURATOR] [] [A new settings has been provided to Logger to change its configuration for localLogging] [] []
    [DEBUG] [11/25/2011 09:06:45.692] [660] [ZenworksWindowsService] [27] [] [MessageLogger] [] [Settings passed to logger:<ZENSettings Version="1.0"><SettingConfiguration Name="SystemLog" Enabled="True" Revision="0"><Parameter Name="Severity" Type="Integer" Value="12" /></SettingConfiguration></ZENSettings>] [] []
    [DEBUG] [11/25/2011 09:06:45.692] [660] [ZenworksWindowsService] [27] [] [MessageLogger] [] [Ignoring the Settings as the revision number is same] [] []
    [DEBUG] [11/25/2011 09:06:45.692] [660] [ZenworksWindowsService] [27] [] [MessageLogger] [] [Ignoring the Settings as the revision number is same] [] []
    [DEBUG] [11/25/2011 09:06:45.692] [660] [ZenworksWindowsService] [27] [] [LOGGERCONFIGURATOR] [] [A new settings has been provided to Logger to change its configuration for sysLogging] [] []
    [DEBUG] [11/25/2011 09:06:45.770] [660] [ZenworksWindowsService] [47] [] [Remote Management Module] [] [Updated the RM Configuration file.] [] []
    [DEBUG] [11/25/2011 09:06:45.848] [660] [ZenworksWindowsService] [47] [] [Remote Management Module] [] [Info: Sent ZRMConfigurationChangeEvent event to WinVNC server.] [] []
    [DEBUG] [11/25/2011 09:06:45.864] [660] [ZenworksWindowsService] [23] [] [ZenCache] [] [(Thread 23) GetObject(PROXY_OVERRIDE, UserContext{_LocalId=none; _RemoteId=(Public)}) called] [] []
    [DEBUG] [11/25/2011 09:06:45.880] [660] [ZenworksWindowsService] [23] [] [ZenCache] [] [(Thread 23) GetObject returning <not cached> in 0 ms] [] []
    [DEBUG] [11/25/2011 09:06:45.880] [660] [ZenworksWindowsService] [23] [] [ZenCache] [] [(Thread 23) GetObject(PROXY_DEFAULT, UserContext{_LocalId=none; _RemoteId=(Public)}) called] [] []
    [DEBUG] [11/25/2011 09:06:45.880] [660] [ZenworksWindowsService] [23] [] [ZenCache] [] [(Thread 23) GetObject returning <not cached> in 0 ms] [] []
    [DEBUG] [11/25/2011 09:06:45.880] [660] [ZenworksWindowsService] [23] [] [BundleManager] [] [ApplicationService GetAppService appContext.GetWebServiceURI() = https://199.0.8.11/zenworks-bundleservice/] [] []
    [DEBUG] [11/25/2011 09:06:45.880] [660] [ZenworksWindowsService] [23] [] [ZMD] [] [Soap Utility: KeepAlive is read from registry. KeepAlive = True] [] []
    [DEBUG] [11/25/2011 09:07:03.230] [660] [ZenworksWindowsService] [23] [] [BundleManager] [] [BUNDLE.CouldNotGetBundleDetailsException] [] []
    [DEBUG] [11/25/2011 09:07:03.230] [660] [ZenworksWindowsService] [23] [] [ZMD] [] [GetCurrentURIFromConnectMan - URI is bad https://199.0.8.11/zenworks-bundleservice/ trying to find another one] [] []
    [DEBUG] [11/25/2011 09:07:03.230] [660] [ZenworksWindowsService] [23] [] [ConnectMan] [] [FindNextContent()] [] []
    [DEBUG] [11/25/2011 09:07:03.230] [660] [ZenworksWindowsService] [23] [] [ConnectMan] [] [ badUri: https://199.0.8.11/zenworks-bundleservice/] [] []
    [DEBUG] [11/25/2011 09:07:03.230] [660] [ZenworksWindowsService] [23] [] [ConnectMan] [] [ Exception: There is an error in XML document (92, 393489).] [] []
    [DEBUG] [11/25/2011 09:07:03.230] [660] [ZenworksWindowsService] [23] [] [ConnectMan] [] [ ] [] []
    [DEBUG] [11/25/2011 09:07:03.230] [660] [ZenworksWindowsService] [23] [] [ConnectMan] [] [https://server/zenworks-bundleservice/ ] [] []
    [DEBUG] [11/25/2011 09:07:03.230] [660] [ZenworksWindowsService] [23] [] [ConnectMan] [] [https://199.0.8.11/zenworks-bundleservice/ ] [] []
    [DEBUG] [11/25/2011 09:07:03.230] [660] [ZenworksWindowsService] [23] [] [ConnectMan] [] [ ] [] []
    [DEBUG] [11/25/2011 09:07:03.230] [660] [ZenworksWindowsService] [23] [] [ConnectMan] [] [Marking IP Location https://server/zenworks-bundleservice/: Bad] [] []
    [DEBUG] [11/25/2011 09:07:03.230] [660] [ZenworksWindowsService] [23] [] [ConnectMan] [] [Unknown Exception] [] []
    [DEBUG] [11/25/2011 09:07:03.230] [660] [ZenworksWindowsService] [23] [] [ConnectMan] [] [There is an error in XML document (92, 393489).] [] []
    [DEBUG] [11/25/2011 09:07:03.230] [660] [ZenworksWindowsService] [23] [] [ConnectMan] [] [ at System.Xml.Serialization.XmlSerializer.Deserialize (XmlReader xmlReader, String encodingStyle, XmlDeserializationEvents events)
    at System.Xml.Serialization.XmlSerializer.Deserialize (XmlReader xmlReader, String encodingStyle)
    at System.Web.Services.Protocols.SoapHttpClientProtoc ol.ReadResponse(SoapClientMessage message, WebResponse response, Stream responseStream, Boolean asyncCall)
    at System.Web.Services.Protocols.SoapHttpClientProtoc ol.Invoke(String methodName, Object() parameters)
    at Novell.Zenworks.AppModule.Schema.ApplicationServic e.getAppDetails(GetAppDetailsRequest GetAppDetailsRequest)
    at Novell.Zenworks.AppModule.WebAppService.GetAppDeta ils(GetAppDetailsRequest request)] [] []
    [DEBUG] [11/25/2011 09:07:03.246] [660] [ZenworksWindowsService] [23] [] [ConnectMan] [] [Marking location https://199.0.8.11/zenworks-bundleservice/ Bad at the request of module bundleservice] [] []
    [DEBUG] [11/25/2011 09:07:03.246] [660] [ZenworksWindowsService] [23] [] [ConnectMan] [] [ Setting location name https://199.0.8.11/zenworks-bundleservice/ to status Bad] [] []
    [DEBUG] [11/25/2011 09:07:03.246] [660] [ZenworksWindowsService] [23] [] [ConnectMan] [] [ Exception causing location name https://199.0.8.11/zenworks-bundleservice/ to be marked Bad: System.InvalidOperationException: There is an error in XML document (92, 393489). ---> System.Xml.XmlException: The 'null' start tag on line 92 does not match the end tag of 'DestDir'. Line 92, position 393489.
    at System.Xml.XmlTextReaderImpl.Throw(Exception e)
    at System.Xml.XmlTextReaderImpl.Throw(String res, String() args)
    at System.Xml.XmlTextReaderImpl.ThrowTagMismatch(Node Data startTag)
    at System.Xml.XmlTextReaderImpl.ParseEndElement()
    at System.Xml.XmlTextReaderImpl.ParseElementContent()
    at System.Xml.XmlTextReaderImpl.Read()
    at System.Xml.XmlTextReader.Read()
    at System.Xml.XmlLoader.LoadNode(Boolean skipOverWhitespace)
    at System.Xml.XmlLoader.ReadCurrentNode(XmlDocument doc, XmlReader reader)
    at System.Xml.XmlDocument.ReadNode(XmlReader reader)
    at System.Xml.Serialization.XmlSerializationReader.Re adXmlNode(Boolean wrapped)
    at Microsoft.Xml.Serialization.GeneratedAssembly.XmlS erializationReaderApplicationService.Read14_AppDat aActionSetsInstall(Boolean isNullable, Boolean checkType)
    at Microsoft.Xml.Serialization.GeneratedAssembly.XmlS erializationReaderApplicationService.Read21_AppDat aActionSets(Boolean isNullable, Boolean checkType)
    at Microsoft.Xml.Serialization.GeneratedAssembly.XmlS erializationReaderApplicationService.Read24_AppDat a(Boolean isNullable, Boolean checkType)
    at Microsoft.Xml.Serialization.GeneratedAssembly.XmlS erializationReaderApplicationService.Read25_GetApp DetailsResponseAppResult(Boolean isNullable, Boolean checkType)
    at Microsoft.Xml.Serialization.GeneratedAssembly.XmlS erializationReaderApplicationService.Read26_GetApp DetailsResponse(Boolean isNullable, Boolean checkType)
    at Microsoft.Xml.Serialization.GeneratedAssembly.XmlS erializationReaderApplicationService.Read32_getApp DetailsResponse()
    at Microsoft.Xml.Serialization.GeneratedAssembly.Arra yOfObjectSerializer5.Deserialize(XmlSerializationR eader reader)
    at System.Xml.Serialization.XmlSerializer.Deserialize (XmlReader xmlReader, String encodingStyle, XmlDeserializationEvents events)
    --- End of inner exception stack trace ---
    at System.Xml.Serialization.XmlSerializer.Deserialize (XmlReader xmlReader, String encodingStyle, XmlDeserializationEvents events)
    at System.Xml.Serialization.XmlSerializer.Deserialize (XmlReader xmlReader, String encodingStyle)
    at System.Web.Services.Protocols.SoapHttpClientProtoc ol.ReadResponse(SoapClientMessage message, WebResponse response, Stream responseStream, Boolean asyncCall)
    at System.Web.Services.Protocols.SoapHttpClientProtoc ol.Invoke(String methodName, Object() parameters)
    at Novell.Zenworks.AppModule.Schema.ApplicationServic e.getAppDetails(GetAppDetailsRequest GetAppDetailsRequest)
    at Novell.Zenworks.AppModule.WebAppService.GetAppDeta ils(GetAppDetailsRequest request)] [] []
    [DEBUG] [11/25/2011 09:07:03.246] [660] [ZenworksWindowsService] [23] [] [ConnectMan] [] [Exiting MarkLocationBad] [] []
    [DEBUG] [11/25/2011 09:07:03.246] [660] [ZenworksWindowsService] [23] [] [ConnectMan] [] [FindFirstContent()] [] []
    [DEBUG] [11/25/2011 09:07:03.246] [660] [ZenworksWindowsService] [23] [] [ConnectMan] [] [ ] [] []
    [DEBUG] [11/25/2011 09:07:03.246] [660] [ZenworksWindowsService] [23] [] [ConnectMan] [] [ ] [] []
    [DEBUG] [11/25/2011 09:07:03.246] [660] [ZenworksWindowsService] [23] [] [ConnectMan] [] [ Found host server status: Good] [] []
    [DEBUG] [11/25/2011 09:07:03.246] [660] [ZenworksWindowsService] [23] [] [ConnectMan] [] [ Found location https://199.0.8.11/zenworks-bundleservice/ status: Bad] [] []
    [DEBUG] [11/25/2011 09:07:03.246] [660] [ZenworksWindowsService] [23] [] [ConnectMan] [] [ Skipping IP location: https://199.0.8.11/zenworks-bundleservice/, status: Bad] [] []
    [DEBUG] [11/25/2011 09:07:03.246] [660] [ZenworksWindowsService] [23] [] [ConnectMan] [] [ Found host 199.0.8.11 status: Unknown] [] []
    [DEBUG] [11/25/2011 09:07:03.246] [660] [ZenworksWindowsService] [23] [] [ConnectMan] [] [ Found location https://199.0.8.11/zenworks-bundleservice/ status: Bad] [] []
    [DEBUG] [11/25/2011 09:07:03.246] [660] [ZenworksWindowsService] [23] [] [ConnectMan] [] [ Skipping IP location: https://199.0.8.11/zenworks-bundleservice/, status: Bad] [] []
    [DEBUG] [11/25/2011 09:07:03.246] [660] [ZenworksWindowsService] [23] [] [ConnectMan] [] [Trying to locate source location: https://server/zenworks-bundleservice/] [] []
    [DEBUG] [11/25/2011 09:07:03.246] [660] [ZenworksWindowsService] [23] [] [ConnectMan] [] [ Host name to resolve: server] [] []
    [DEBUG] [11/25/2011 09:07:03.246] [660] [ZenworksWindowsService] [23] [] [ConnectMan] [] [ Found host: server, status: Good] [] []
    [DEBUG] [11/25/2011 09:07:03.246] [660] [ZenworksWindowsService] [23] [] [ConnectMan] [] [ Skipping location: https://199.0.8.11/zenworks-bundleservice/, status: Bad] [] []
    [DEBUG] [11/25/2011 09:07:03.246] [660] [ZenworksWindowsService] [23] [] [ConnectMan] [] [Trying to locate source location: https://199.0.8.11/zenworks-bundleservice/] [] []
    [DEBUG] [11/25/2011 09:07:03.246] [660] [ZenworksWindowsService] [23] [] [ConnectMan] [] [ Host name to resolve: 199.0.8.11] [] []
    [DEBUG] [11/25/2011 09:07:03.246] [660] [ZenworksWindowsService] [23] [] [ConnectMan] [] [ Found host: 199.0.8.11, status: Unknown] [] []
    [DEBUG] [11/25/2011 09:07:03.246] [660] [ZenworksWindowsService] [23] [] [ConnectMan] [] [ Host: 199.0.8.11, IP address: 199.0.8.11] [] []
    [DEBUG] [11/25/2011 09:07:03.246] [660] [ZenworksWindowsService] [23] [] [ConnectMan] [] [ Using IP address: 199.0.8.11, status: Good] [] []
    [DEBUG] [11/25/2011 09:07:03.246] [660] [ZenworksWindowsService] [23] [] [ConnectMan] [] [Entered FindServerFromBusyList] [] []
    [DEBUG] [11/25/2011 09:07:03.246] [660] [ZenworksWindowsService] [23] [] [ConnectMan] [] [ FindServerFromBusyList() Found host: server, status: Good] [] []
    [DEBUG] [11/25/2011 09:07:03.246] [660] [ZenworksWindowsService] [23] [] [ConnectMan] [] [ IP address 199.0.8.11 marked Good] [] []
    [DEBUG] [11/25/2011 09:07:03.246] [660] [ZenworksWindowsService] [23] [] [ConnectMan] [] [GetGoodOrBusyIp() returning 199.0.8.11] [] []
    [DEBUG] [11/25/2011 09:07:03.246] [660] [ZenworksWindowsService] [23] [] [ConnectMan] [] [ FindServerFromBusyList() Skipping location: https://199.0.8.11/zenworks-bundleservice/, status: Bad] [] []
    [DEBUG] [11/25/2011 09:07:03.246] [660] [ZenworksWindowsService] [23] [] [ConnectMan] [] [ FindServerFromBusyList() Found host: 199.0.8.11, status: Unknown] [] []
    [DEBUG] [11/25/2011 09:07:03.246] [660] [ZenworksWindowsService] [23] [] [ConnectMan] [] [ IP address 199.0.8.11 marked Good] [] []
    [DEBUG] [11/25/2011 09:07:03.246] [660] [ZenworksWindowsService] [23] [] [ConnectMan] [] [GetGoodOrBusyIp() returning 199.0.8.11] [] []
    [DEBUG] [11/25/2011 09:07:03.246] [660] [ZenworksWindowsService] [23] [] [ConnectMan] [] [ FindServerFromBusyList() Skipping location: https://199.0.8.11/zenworks-bundleservice/, status: Bad] [] []
    [DEBUG] [11/25/2011 09:07:03.246] [660] [ZenworksWindowsService] [23] [] [ConnectMan] [] [Exited FindServerFromBusyList with Server = to null] [] []
    [DEBUG] [11/25/2011 09:07:03.246] [660] [ZenworksWindowsService] [23] [] [ConnectMan] [] [FindFirstContent() returning ] [] []
    [DEBUG] [11/25/2011 09:07:03.246] [660] [ZenworksWindowsService] [23] [] [ConnectMan] [] [FindNextContent: Exiting with content null] [] []
    [DEBUG] [11/25/2011 09:07:03.246] [660] [ZenworksWindowsService] [23] [] [ZMD] [] [GetCurrentURIFromConnectMan - New uri is: ] [] []
    [DEBUG] [11/25/2011 09:07:03.246] [660] [ZenworksWindowsService] [23] [] [BundleManager] [] [!!!!!!!!!!! No Bundle Data Retrieved !!!!!!!!!!!!!!!!!] [] []
    [DEBUG] [11/25/2011 09:07:03.246] [660] [ZenworksWindowsService] [23] [] [BundleManager] [] [Exiting GetBundle details] [] []
    [DEBUG] [11/25/2011 09:07:03.246] [660] [ZenworksWindowsService] [23] [] [BundleManager] [] [Time for GeneralRefresh: 553] [] []
    [DEBUG] [11/25/2011 09:07:03.246] [660] [ZenworksWindowsService] [23] [] [BundleManager] [] [Found details for 3 bundles] [] []
    [DEBUG] [11/25/2011 09:07:03.246] [660] [ZenworksWindowsService] [23] [] [BundleManager] [] [ Found bundle Infutik auth; GUID: 5f49e281737695163d4c929d98844c25; Version: 0] [] []
    [DEBUG] [11/25/2011 09:07:03.246] [660] [ZenworksWindowsService] [23] [] [BundleManager] [] [ Found bundle Windows XP default ekraani-asetused; GUID: 3b78a17437ec0c9c9be7b8bb5cf484c5; Version: 2] [] []
    [DEBUG] [11/25/2011 09:07:03.246] [660] [ZenworksWindowsService] [23] [] [BundleManager] [] [ Found bundle Log-kataloog; GUID: 7b78a1535264a515dcb72a8d87485101; Version: 0] [] []
    [ERROR] [11/25/2011 09:07:03.246] [660] [ZenworksWindowsService] [23] [] [BundleManager] [BUNDLE.CouldNotAddBundle] [Could not add bundle 34ddcd7a97507d05b754a1b05be8c19a to session] [] []
    [ERROR] [11/25/2011 09:07:03.261] [660] [ZenworksWindowsService] [23] [] [BundleManager] [BUNDLE.CouldNotAddBundle] [Could not add bundle b1f973c7db610170c53eb630a381236c to session] [] []
    [ERROR] [11/25/2011 09:07:03.261] [660] [ZenworksWindowsService] [23] [] [BundleManager] [BUNDLE.CouldNotAddBundle] [Could not add bundle 0e265efd29dee160013d4030b90ebab3 to session] [] []
    [ERROR] [11/25/2011 09:07:03.261] [660] [ZenworksWindowsService] [23] [] [BundleManager] [BUNDLE.CouldNotAddBundle] [Could not add bundle 53880f0e33e70a863c6acf218814a498 to session] [] []
    [DEBUG] [11/25/2011 09:07:03.261] [660] [ZenworksWindowsService] [23] [] [MessageLogger] [] [Unable to write to event log (Application) using source (Novell.Zenworks.Logger) Exception: System.ComponentModel.Win32Exception: The event log file is full
    at System.Diagnostics.EventLog.InternalWriteEvent(UIn t32 eventID, UInt16 category, EventLogEntryType type, String() strings, Byte() rawData, String currentMachineName)
    at System.Diagnostics.EventLog.WriteEntry(String message, EventLogEntryType type, Int32 eventID, Int16 category, Byte() rawData)
    at System.Diagnostics.EventLog.WriteEntry(String source, String message, EventLogEntryType type, Int32 eventID, Int16 category, Byte() rawData)
    at System.Diagnostics.EventLog.WriteEntry(String source, String message, EventLogEntryType type, Int32 eventID)
    at log4net.Appender.EventLogAppender.Append(LoggingEv ent loggingEvent)] [] []
    [ERROR] [11/25/2011 09:07:03.261] [660] [ZenworksWindowsService] [23] [] [BundleManager] [BUNDLE.CouldNotAddBundle] [Could not add bundle e0b738c3966a354de7cd84e3e76ef366 to session] [] []
    [DEBUG] [11/25/2011 09:07:03.261] [660] [ZenworksWindowsService] [23] [] [MessageLogger] [] [Unable to write to event log (Application) using source (Novell.Zenworks.Logger) Exception: System.ComponentModel.Win32Exception: The event log file is full
    at System.Diagnostics.EventLog.InternalWriteEvent(UIn t32 eventID, UInt16 category, EventLogEntryType type, String() strings, Byte() rawData, String currentMachineName)
    at System.Diagnostics.EventLog.WriteEntry(String message, EventLogEntryType type, Int32 eventID, Int16 category, Byte() rawData)
    at System.Diagnostics.EventLog.WriteEntry(String source, String message, EventLogEntryType type, Int32 eventID, Int16 category, Byte() rawData)
    at System.Diagnostics.EventLog.WriteEntry(String source, String message, EventLogEntryType type, Int32 eventID)
    at log4net.Appender.EventLogAppender.Append(LoggingEv ent loggingEvent)] [] []
    More thanks, Alar.

  • PS script to save event logs

     
    Hi,
    I want to create a PS script which will pick the server name from a text file and save the event logs one by one of all the server with server name in a shared folder in network
    For this I tried to create below code, but not successful. I know there are some silly mistake in this code which i m not able to identify
    Please help me because I’m new in scripting and have very little knowledge about this.
    ==================
    $Computer_Name = Get-Content \\sharepath\name.txt
    $logfile = ForEach ($Computer_Name)
    Get-WmiObject -Class win32_NTEventlogFile  -Filter "logFileName='Application'"
    $logfile.ClearEventlog('Sharepath\%computername%_Application_Logs.evt')
    ========================

    Thanks !!!
    The share path is working fine.
    If I am running the below script it will save the logs files of local computer to the shared drive with computer name.
    ==============
    $logfile = Get-WmiObject -Class win32_NTEventlogFile  -Filter "logFileName='Application'"
    $logfile.ClearEventlog('\\sharepath\%computername%_Application_Logs.evt')
    ================
    Now, I want to create a script which will pick the server name from a text file and save that to a shared folder with respective computer name.
    Also, is there any way to SAVE AS the log files rather than clearing the logs ?
    You can export the logs using Get-EventLog and Export-Csv  Get-EventLog can specify a filter of -after and -before to set a date range.
    Help get-eventlog -full
    You can specify an array or file of computer names on the commandline.  You can specify credentials on the commandline.
    You can also save eventlogs in their entirety but that is not a good practice as it produces too much overlap.
    I suggest that weekly extractions ican be managed on an overnight basis. Monthly extracts are likely to take too much time.
    LogParser is much better at extracting Eventlogs in many formats.
    Logs should beset to rol lover on a size basis.  I use 32 and 64 megabytes on bsic systems and much larger on busier systems.   like to have a year online if possible.
    ¯\_(ツ)_/¯

  • Warning on Event Log of Aironet 1300 Bridge

    I've been getting warning messages from the event log of a 1300 series bridge, which is set as an Access Point in the network, states: 'Packet to client (mac address) reached max retries, removing the client';  I'm not sure why the client is removed.  Does 'reached max retries' mean that the client has tried to many times to connect to the AP/Bridge?  What are other possible reasons why? 

    It means the AP has attempted to send a packet to the client and has not received an ack from it. The AP assumes the client is no longer in range of it and disconnects it.
    Sent from Cisco Technical Support iPad App

  • How To Block logging of 405's to Event Log?

    I've got a webserver accessible to the outside world that comes under constant vulnerability scans, many of which involve accessing .exe filetypes.
    When any of these scans are made, not a 404, but a 405 error message is generated.
    Each 405 is stored in the event log, clogging up the eventlog and making it difficult to search for useful information.
    Is there any way to block 405 error messages from being put into the event log or perhaps a way to force a 404 error message in such cases?
    I do use some CGIs so altering .exe in mime.types won't do. I'm running win2k adv. server.
    -R

    The customary way to force the server to return a 404 for an arbitrary resource is to use the deny-existence SAF. However, deny-existence will itself log a message each time a "denied" resource is requested, so this probably isn't what you want.
    Fortunately, there are numerous ways to address the issue. One possibility is redirecting accesses to these resources elsewhere, e.g. to your web site's front page. The following 3 lines could be added to the end of obj.conf to redirect requests for URIs that end in "/system32/cmd.exe":
    <Object ppath="*/system32/cmd.exe">
    NameTrans fn="redirect" from="/" url="/"
    </Object>

  • Office 2013 Click-to-Run Event Logs

    Anyone know what the event logs are (Source, Event ID, etc) for Office 2013 Click-to-Run version? Specifically, I'm trying to find out when my installation was last updated (automatic updates are enabled). In general it would also be nice to know
    what all of the different events are that the program will log.
    Shaun

    Hi,
    To view the Office updates log, we can just go to Control Panel > All Control Panel Items > Windows Update and click
    View update history.
    If you want to know all the event logs related to Microsoft Office, we can use Event Viewer.
    http://windows.microsoft.com/en-in/windows/open-event-viewer#1TC=windows-7
    To find Office-related logs, click Event Viewer > Applications and Services Logs > Microsoft Office Alerts in the Event Viewer window.
    Regards,
    Steve Fan
    Forum Support
    Come back and mark the replies as answers if they help and unmark them if they provide no help.
    If you have any feedback on our support, please click
    here

Maybe you are looking for