Build a great reporting interface using Splunk, one of the leaders in the Security Information and Event Management (SIEM) field, linking the collected Windows events to www.eventid.net. The EventId.Net for Splunk Add-on assumes that Splunk is collecting information from Windows servers and workstation via the Splunk Universal Forwarder.
The disk is full. Attempting to stop the Microsoft Exchange Information Store service.
|English: Request a translation of the event description in plain English.|
|Concepts to understand:|
What is the role of the Microsoft Exchange Information Store service?
When can a disk become full?
You need to free up space as quickly as possible in order to get users back online. One fast way is to delete the catalog index for this database.
1. Log onto the Exchange 2007 server (active node first) and stop the Microsoft Exchange Search Indexer service.
2. Delete the catalog index folder for this database.
3. Start the Microsoft Exchange Search Indexer service.
4. Repeat steps 1-3 for the passive node.
5. If necessary, mount the database.
As per Microsoft: "This issue can occur if there is insufficient free disk space on the drive that contains the databases that you are trying to mount". See ME294318 for details.
The first thing would be to verify that there is enough space on the hard drives. If there seems to be space, then verify the hard drives for potential corruption. Also check ME328679 - if you have a disk using FAT32 partition there may be a problem.
|Private comment: Subscribers only. See example of private comment|
|Search: Google - Bing - Microsoft - Yahoo - EventID.Net Queue (0) - More links...|
Send comments or solutions
- Notify me when updated