Build a great reporting interface using Splunk, one of the leaders in the Security Information and Event Management (SIEM) field, linking the collected Windows events to www.eventid.net. The EventId.Net for Splunk Add-on assumes that Splunk is collecting information from Windows servers and workstation via the Splunk Universal Forwarder.
DOMAIN/USERNAME was unable to connect as /o=Organization/ou=OrgUnit/cn=Exchange/cn=User Alias. Error <error code>
|English: Request a translation of the event description in plain English.|
|Concepts to understand:|
What is the role of the Microsoft Exchange Information Store service?
- Error code: 0x4de (Mapi sessions exceeded) - In my case, it turned out to be that one of our engineers had attempted to enable RPC over HTTP. Once RPC over HTTP was disabled, and the Information Store was restarted, the client worked properly.
From a newsgroup post: "Error code: 0x80040111 – I fixed the problem by recreating missing System Attendant mailbox".
- Error code: 0x503 - This error occurs when someone tries to connect and Exchange is out of licenses.
See MSEX2KDB for information about this event.
- 0x3f2 - An error reading the hard disk. This issue can occur when you do not have the correct NTFS file system permissions on the Exchsrvr folder on the Exchange Server computer. See ME249892.
- 0x80040111 - MAPI_E_LOGON_FAILED = An unsuccessful logon attempt when you query the directory. ME278966 might help?
|Private comment: Subscribers only. See example of private comment|
|Links: ME249892, ME278966, MSEX2KDB|
|Search: Google - Bing - Microsoft - Yahoo - EventID.Net Queue (0) - More links...|
Send comments or solutions
- Notify me when updated