Build a great reporting interface using Splunk, one of the leaders in the Security Information and Event Management (SIEM) field, linking the collected Windows events to www.eventid.net. The EventId.Net for Splunk Add-on assumes that Splunk is collecting information from Windows servers and workstation via the Splunk Universal Forwarder.
The cluster resource host subsystem (RHS) stopped unexpectedly. An attempt will be made to restart it. This is usually due to a problem in a resource DLL. Please determine which resource DLL is causing the issue and report the problem to the resource vendor.
|English: Request a translation of the event description in plain English.|
|Concepts to understand:|
What is the RHS?
T773478 provides a general approach in troubleshooting this type of problems, including instructions on configuring a resource to run in its own Resource Monitor.
As per ME978527, this may be recorded because the path defined for the cluster resource DLL contains a system environment variable in the path, which contains another environment variable in its path. The RHS.exe process incorrectly overwrites heap memory beyond its tail when the RHS.exe process expands the multiple system environment variables. See the article for a suggested hotfix available for Windows Server 2008 R2.
|Private comment: Subscribers only. See example of private comment|
|Search: Google - Bing - Microsoft - Yahoo - EventID.Net Queue (0) - More links...|
|Custom search for *****: Google - Bing - Microsoft - Yahoo|
Send comments or solutions
- Notify me when updated