Monitor unlimited number of servers
Filter log events
Create email and web-based reports

Direct access to Microsoft articles
Customized keywords for major search engines
Access to premium content

Event ID: 3 Source: ECMagent

The description for Event ID ( 3 ) in Source ( ECM agent ) cannot be found. The local computer may not have the necessary registry information or message DLL files to display messages from a remote computer. The following information is part of the event: ECM Started Successfully on the system..
My application log on my backup server was full with this event that arrived once a minute. After some investigation I discovered that I had installed ExecView agent when I last installed Backup Exec and that the Service ExecView Communication Module (ECM) might be connected to the problem. By investigating when it started and what I did to the server at that time, I discovered that I had installed a new version of APC PowerChute Business Edition and that the event had turned up after this point. The backup server has a separate UPS. Some further search on Symantec and Veritas turned up a viable explanation for the problem on Netware servers. The service cannot access Java due to a very long path to Java runtime, due to the location where by APC PowerChute Business Edition installs Java. I did not want to reinstall BackupExec, and therefore, turned the service ExecView Communication Module (ECM) off and set it to manual. This has apparently solved the problem. Further investigations must be done to completely resolve the issue.

Windows Event Log Analysis Splunk App

Build a great reporting interface using Splunk, one of the leaders in the Security Information and Event Management (SIEM) field, linking the collected Windows events to



Cisco ASA Log Analyzer Splunk App

Obtain enhanced visibility into Cisco ASA firewall logs using the free Firegen for Cisco ASA Splunk App. Take advantage of dashboards built to optimize the threat analysis process.