Monitor unlimited number of servers
Filter log events
Create email and web-based reports

Direct access to Microsoft articles
Customized keywords for major search engines
Access to premium content

Event ID: 12290 Source: VSS

Volume Shadow Copy Service warning: ESENT ERROR {b2014c9e-8711-4c5c-a5a9-3cf384484757} NTDS: -2402. hr = 0x00000000.
This may be recorded when the Associations under following key are incorrect, too many or pointing to non-existing volumes:


0. Note all values for the current VSS settings. Can be found by right clicking the particular volume and select "Shadowcopies".
1. Try deleting all Subkeys of this Key.
2. Then restart the two "Volume Shadowcopy" and "Microsoft Software Shadow Copy Provider".
3. Right click the Volume you want to reenable VSS again and set your VSS properties accordingly.
4. Restart the two services again and check event log.
Warning: ASR writer Error 0x80070001. hr = 0x00000000 - As per ME968128, this problem occurs if the active EISA partition on the computer is a hidden partition. See the article for resolution.
The VSS update rollup package for Windows Server 2003 described in ME940349 may fix this issue.
See ME833167 for a Volume Shadow Copy Service (VSS) update package for Windows Server 2003.

See ME826936 for additional information on this problem.

Windows Event Log Analysis Splunk App

Build a great reporting interface using Splunk, one of the leaders in the Security Information and Event Management (SIEM) field, linking the collected Windows events to



Cisco ASA Log Analyzer Splunk App

Obtain enhanced visibility into Cisco ASA firewall logs using the free Firegen for Cisco ASA Splunk App. Take advantage of dashboards built to optimize the threat analysis process.