Build a great reporting interface using Splunk, one of the leaders in the Security Information and Event Management (SIEM) field, linking the collected Windows events to www.eventid.net. The EventId.Net for Splunk Add-on assumes that Splunk is collecting information from Windows servers and workstation via the Splunk Universal Forwarder.
|Source: Operations Manager|
Service <service name> has gone from <previous status> to <current status> in the last <number> minutes
|English: Request a translation of the event description in plain English.|
See ME883342 for details on using the Microsoft Operations Manager 2005 Management Pack Wizard to create a Management Pack rule that monitors specific Windows services.
This message is recorded by the Microsoft Operations Manager anytime it detects a change in the status of a service on one the the monitored computers (agents).
It may not be a bad message necessarely as some service stop/start as part of their normal operations or due to changes made by administrators. If the change is not expected then further investigation is necessary.
|Private comment: Subscribers only. See example of private comment|
|Search: Google - Bing - Microsoft - Yahoo - EventID.Net Queue (0) - More links...|
Send comments or solutions
- Notify me when updated