Monitor unlimited number of servers
Filter log events
Create email and web-based reports

Direct access to Microsoft articles
Customized keywords for major search engines
Access to premium content

Event ID: 1002 Source: MSExchangeDS

The Microsoft Exchange Server database, EDB, could not be initialized and returned error <error>. Unrecoverable error. The directory can't continue.
- Error: -500 - We solved this event by runnning eseutil /p on the "dir.edb" Exchange file and then deleting all log files before starting the service.
- Error: -528 - This event will occur if you do not use Control Panel to start the Directory service. See ME238063 for details on this problem.
- Error: 1 - This behavior can occur if a registry key is missing or has been deleted. See ME263548 for details.
- Error: -550 - See ME268577 to find out how to solve this problem.
- Error: -1008 - This issue can occur because many virus protection programs set files to read only to protect the files. The -1008 error corresponds to JET_errDatabaseFileReadOnly. See ME262371 to solve this issue.
- Error: -514 - This problem may occur if you renamed the Exchange 5.5 service account to something other than the default value of "Administrator". See ME294259 to resolve this problem.
- Error: -1022 - You restore an Exchange Server 5.5 directory from offline backup and you want to try to play the log files forward. When you try to start the Exchange 5.5 Server directory service, the service does not start, and this event is logged. See ME311396 for more information about this problem. Also check ME267987 and ME285675 for two possible situations in which this event occurs.
- Error: -1032 - This error occurs when you restore an Exchange Server 5.5 directory from offline backup and you want to try to play the log files forward for the second time, after failing the first time with error -1022. See ME311396 for details about this problem.
- Error: -1811 - This event is logged if The Dir.edb database file is missing or the registry entries that define the paths to the directory database and to other required files point to the incorrect locations. See ME285675 for details about this issue.
To resolve this problem simply run eseutil /p on your “dir.edb” (Directory Database) Exchange file.
- Error 550 "Unrecoverable error, the directory can't continue". Databases of MSExchangeDS of my Exchange 5.5 were corrupted. I had to restore from a backup (only for the MSExchange databases). One can follow these steps:
1.- Rename the \exchsrvr\DSDATA folder
2.- Restore the \exchsrvr\DSDATA folder from backup tape
3.- Rename the transaction logs in MDBDATA folder except edb and restore form tape.
4.- Run isinteg -patch from \exchsrvr\BIN
After this steps, my Exchange Server was OK and without data loss.
The registry is pointing to the wrong Directory for the Dir.edb file. See ME188674 and ME196159 for more details.
- Error: -1032 - As per Microsoft: "This issue may occur when files that Microsoft Exchange Ddirectory service needs must have are set to read-only. The Symantec Corporation's Norton AntiVirus software may set this attribute on the Microsoft Exchange Server files while the antivirus program completes its antiviral scan". See ME326858 for more details.
- Error: -1811 = "JET_errFileNotFound" - As per Microsoft: " Most virus protection programs have settings to remove, rename or quarantine infected files as a part of their cleanup process. This issue can occur if the virus protection program renames the directory". See ME262374 and ME253309 for more details.
- Error: -1507 - This behavior can occur when the Directory database (Dir.edb) structure is damaged. See ME247770 to resolve this problem.
- Error: -1911 - This issue can occur if one or more dynamic-link library (DLL) files that are associated with the operating system are damaged, missing, or modified. See ME240789 for more information about this problem.
- Error: -1022 - See ME166335 and the link to Error code 1022.

Windows Event Log Analysis Splunk App

Build a great reporting interface using Splunk, one of the leaders in the Security Information and Event Management (SIEM) field, linking the collected Windows events to



Cisco ASA Log Analyzer Splunk App

Obtain enhanced visibility into Cisco ASA firewall logs using the free Firegen for Cisco ASA Splunk App. Take advantage of dashboards built to optimize the threat analysis process.