Build a great reporting interface using Splunk, one of the leaders in the Security Information and Event Management (SIEM) field, linking the collected Windows events to www.eventid.net. The EventId.Net for Splunk Add-on assumes that Splunk is collecting information from Windows servers and workstation via the Splunk Universal Forwarder.
The error code 2 was returned when trying to remove the spool file C:\EXCHSRVR\imcdata\in\KTB2M9SQ. This file may cause duplicate mail to be sent when the server is restarted.
|English: Request a translation of the event description in plain English.|
|Concepts to understand:|
What is the role of the Microsoft Exchange Internet Mail Connector service?
This issue may occur if your antivirus software scans and tries to delete files in the "c:\Exchsrvr\Imcdata" folder. See ME328667 for more details.
If you have software, a file-level virus scanner for example, that is locking the file at the same time Exchange is trying to remove this, you can get this type of error. For example, antivirus scan at file level by NAV 7. It tries to scan messagesin IMCDATA, locks them and IMC can not delete file.
Exclude \exchsrvr on all volumes from scanning by NAV.
|Private comment: Subscribers only. See example of private comment|
|Search: Google - Bing - Microsoft - Yahoo - EventID.Net Queue (0) - More links...|
Send comments or solutions
- Notify me when updated