Monitor unlimited number of servers
Filter log events
Create email and web-based reports

Direct access to Microsoft articles
Customized keywords for major search engines
Access to premium content

Event ID: 2012 Source: Srv

Source
Level
Description
While transmitting or receiving data, the server encountered a network error. Occassional errors are expected, but large amounts of these indicate a possible error in your network configuration. The error status code is contained within the returned data (formatted as Words) and may point you towards the problem.

Data:
0000: 00040000 00540001 00000000 00540001 00000000 800007dc
0010: 00000000 c0000184 00000000 00000000
0020: 00000000 00000000 0000097a
Comments
 
The relevant error code from all the data recorded at the end of the event is the second set of digits from the second row. The most common code encountered for this message is Error code 0xc0000184 (Invalid Device State).

Another code encountered with this message is Error code 0xc000023d (Host Unreachable).

* * *

ME200017 suggests that this may happen due to faulty network adapters or old software drivers.

* * *

From a support forum post:

First thing I recommend you is to optimize memory configuration on the
Server. Please refer to ME815372 (How to optimize memory usage in Exchange Server 2003) and ME823440 (Use of the /3GB switch in Exchange Server 2003 on a Windows Server 2003-based system).

For 2012 event, this basically is an error that the network driver is giving SRV on the send IRPs. Perhaps 3rd party network software that is bound to the server. You can see this by checking the following registry key:

HKLM\SYSTEM\CCS\Services\LanmanServer\Linkage
Bind : REG_MULTI_SZ

* * *

In another support forum, a user discovered that this problem was caused by the Trend Micro Client Security Agent installed on that system. The firewall network driver installed by the Trend Micro client would interfere with the normal network traffic.
In my case, removing the Service Advertising Protocol from adapter stopped the warnings from appearing.
See ME898060 for a possible cause of this event's appearance.

Windows Event Log Analysis Splunk App

Build a great reporting interface using Splunk, one of the leaders in the Security Information and Event Management (SIEM) field, linking the collected Windows events to www.eventid.net.

Read more...

 

Cisco ASA Log Analyzer Splunk App

Obtain enhanced visibility into Cisco ASA firewall logs using the free Firegen for Cisco ASA Splunk App. Take advantage of dashboards built to optimize the threat analysis process.

Read more...