Monitor unlimited number of servers
Filter log events
Create email and web-based reports

Direct access to Microsoft articles
Customized keywords for major search engines
Access to premium content

Event ID: 12347 Source: VSS

Volume Shadow Copy Service error: An internal inconsistency was detected in trying to contact shadow copy service writers.  The Registry Writer failed to respond to a query  from VSS. Please check to see that the Event Service and Volume Shadow Copy Service  are operating properly and please check the Application event log for any other events.

   Gathering Writer Data
   Executing Asynchronous Operation

   Execution Context: Requestor
   Current State: GatherWriterMetadata
According to TE264216, this event indicates that the registry Volume Shadow Copy Service (VSS) writer did not respond to a query from the VSS service.
To resolve this issue, first check that the COM+ Event System and VSS services are enabled, and then make sure that the registry VSS writer is operating properly. See the article for more details.
See the blog article related to this problem at EV100455 (Windows 2008 VSS and backup issues).

Windows Event Log Analysis Splunk App

Build a great reporting interface using Splunk, one of the leaders in the Security Information and Event Management (SIEM) field, linking the collected Windows events to



Cisco ASA Log Analyzer Splunk App

Obtain enhanced visibility into Cisco ASA firewall logs using the free Firegen for Cisco ASA Splunk App. Take advantage of dashboards built to optimize the threat analysis process.