Monitor unlimited number of servers
Filter log events
Create email and web-based reports

Direct access to Microsoft articles
Customized keywords for major search engines
Access to premium content

Event ID: 4093 Source: MSExchangeIMC

The error code 2 was returned when trying to remove the spool file C:\EXCHSRVR\imcdata\in\KTB2M9SQ. This file may cause duplicate mail to be sent when the server is restarted.
This issue may occur if your antivirus software scans and tries to delete files in the "c:\Exchsrvr\Imcdata" folder. See ME328667 for more details.
If you have software, a file-level virus scanner for example, that is locking the file at the same time Exchange is trying to remove this, you can get this type of error. For example, antivirus scan at file level by NAV 7. It tries to scan messagesin IMCDATA, locks them and IMC can not delete file.
Exclude \exchsrvr on all volumes from scanning by NAV.

Windows Event Log Analysis Splunk App

Build a great reporting interface using Splunk, one of the leaders in the Security Information and Event Management (SIEM) field, linking the collected Windows events to



Cisco ASA Log Analyzer Splunk App

Obtain enhanced visibility into Cisco ASA firewall logs using the free Firegen for Cisco ASA Splunk App. Take advantage of dashboards built to optimize the threat analysis process.