Build a great reporting interface using Splunk, one of the leaders in the Security Information and Event Management (SIEM) field, linking the collected Windows events to www.eventid.net. The EventId.Net for Splunk Add-on assumes that Splunk is collecting information from Windows servers and workstation via the Splunk Universal Forwarder.
The oldest shadow copy of volume <volume> was deleted to keep disk space usage for shadow copies of volume <volume> below the user defined limit.
|English: Request a translation of the event description in plain English.|
|Concepts to understand:|
What is a shadow copy?
When you run Disk Defragmenter on a volume with shadow copies activated, all or some of your shadow copies may be lost, starting with the oldest shadow copies. See ME312067 for more information on this issue.
Go to the server that logs this event and right click on any of the drives, then choose properties. Here, there will be a “shadow copies” tab. Under settings, you can define how much room this feature has. Shadow copy itself is pretty much the “rollback” feature in Win 2003.
|Private comment: Subscribers only. See example of private comment|
|Search: Google - Bing - Microsoft - Yahoo - EventID.Net Queue (0) - More links...|
|Custom search for *****: Google - Bing - Microsoft - Yahoo|
Send comments or solutions
- Notify me when updated