Build a great reporting interface using Splunk, one of the leaders in the Security Information and Event Management (SIEM) field, linking the collected Windows events to www.eventid.net. The EventId.Net for Splunk Add-on assumes that Splunk is collecting information from Windows servers and workstation via the Splunk Universal Forwarder.
An operation on a socket could not be performed because the system lacked sufficient buffer space or because a queue was full.
|English: Request a translation of the event description in plain English.|
According to a Microsoft support enginner, this error can occur if OS is running out of non-paged pool. Are you using the /3GB switch on the machine? Please turn it off and try again.
As we know, using /3GB will cause the OS to have only 1GB memory for system use. The paged pool and non-paged pool size will be half the default size. These memory pools are used by OS to store network buffers, etc. Thus, when /3GB is turned on, it is more likely that OS will run out of non-paged pool and be unable to serve socket calls.
As you are using /PAE, the user application already can use the additional 4GB memory. It is recommended to turn off /3GB so that OS could run more smoothly.
|Private comment: Subscribers only. See example of private comment|
|Search: Google - Bing - Microsoft - Yahoo - EventID.Net Queue (0) - More links...|
|Custom search for *****: Google - Bing - Microsoft - Yahoo|
Send comments or solutions
- Notify me when updated