Build a great reporting interface using Splunk, one of the leaders in the Security Information and Event Management (SIEM) field, linking the collected Windows events to www.eventid.net. The EventId.Net for Splunk Add-on assumes that Splunk is collecting information from Windows servers and workstation via the Splunk Universal Forwarder.
<process> (<process id>) Unexpected Win32 error: <error code>.
|English: Request a translation of the event description in plain English.|
|Concepts to understand:|
What is the role of ESENT?
- Error: 267L - See ME307242.
- Error: 80L - See ME294462.
- Error: -273865449L - See ME867670.
Various error codes reported:
Error code: 0x15 = "The device is not ready."
Error code: 0x20 = "The process cannot access the file because it is being used by another process."
Error code: 0x3B = "An unexpected network error occurred." See ME274563.
Error code: 0x10B = "The directory name is invalid."
Error code: 0x569 = "Logon failure: the user has not been granted the requested logon type at this computer."
Process: "tcpsvcs" - Error occurred between successful completion of online defrag pub.edb and starting of online defrag of priv.edb. Please investigate on your Exchange Server if the file level anti-virus (like McAfee NetShield) has in the exclusion list the folder where Exchange database resides.
Also check if the file level backup software is not trying to back up files related to the Exchange database (*.ebd and the log files).
For both anti-virus protection and backup, Exchange aware programs must be used.
Process "groveler" see ME226508.
Similarly, with reference to the Our Approach section, 0x6 (The handle is invalid) could also be attributed to antivirus or backup. If any of these errors happen often and regularly, filemon from sysinternals.com could be used to watch the system file access around the time of the errors.
|Private comment: Subscribers only. See example of private comment|
|Links: ME226508, ME274563, ME294462, ME307242, ME867670|
|Search: Google - Bing - Microsoft - Yahoo - EventID.Net Queue (0) - More links...|
Send comments or solutions
- Notify me when updated