Build a great reporting interface using Splunk, one of the leaders in the Security Information and Event Management (SIEM) field, linking the collected Windows events to www.eventid.net. The EventId.Net for Splunk Add-on assumes that Splunk is collecting information from Windows servers and workstation via the Splunk Universal Forwarder.
Reading the Internet Information Services metabase for the Microsoft(R) Exchange default domain at node /LM/W3SVC/1/root/OMA failed with error <error code>.
|English: Request a translation of the event description in plain English.|
|Concepts to understand:|
What is the metabase?
As per Microsoft: "This event indicates that the attempt to read the Internet Information Services (IIS) metabase for the configured virtual directory for Outlook Mobile Access failed with an error. This can indicate a corruption in the metabase or a misconfigured virtual directory". See MSEX2KDB for additional information about this event.
- Error code: -2147024891 - From a newsgroup post: "I am not sure how you got in this state, but "-2147024891" is an access denied error while reading the metabase. On Win2K boxes, OMA runs under the "asp.net" worker process (aspnet_wp.exe). One cause could be that you promoted your server to a DC after installing Exchange. Unlikely you would do this though. There is a way to reset the ASP.NET ACLs by running the "aspnet_regiis.exe" script with the "-i" switch:
Open a command prompt and browse to "<%windir%>\Microsoft.NET\Framework\<version of the framework>" (eg: C:\WINDOWS\Microsoft.NET\Framework\v1.1.4322). Type "aspnet_regiis.exe -i" and press enter".
|Private comment: Subscribers only. See example of private comment|
|Search: Google - Bing - Microsoft - Yahoo - EventID.Net Queue (0) - More links...|
Send comments or solutions
- Notify me when updated