Monitor unlimited number of servers
Filter log events
Create email and web-based reports

Direct access to Microsoft articles
Customized keywords for major search engines
Access to premium content

Event ID: 4102 Source: MSExchangeIMC

Source
Level
Description
A serious error has occurred while trying to send mail into the Exchange Information Store. The Internet Mail Service is being shut down.
Comments
 
This issue can occur on the Exchange Server computer that is running the Internet Mail Service if the header of a message contains malformed information. See ME293288 to solve this problem.
See ME812071 and ME837216 for two hotfixes applicable to Microsoft Exchange Server 5.5.

As per Microsoft: "The number of threads available to the IMC or IMS from the Information Store (IS) may be too low". See ME169686 for a workaround.

See ME317653 for more details on this issue.
As per Microsoft: "This problem may occur because Exchange Server may be in a low-memory condition. This situation may be experienced when almost no virtual address space is available for virtual memory". See ME870935 for more details.
As per Microsoft, this was resolved with the latest service pack. See ME232279. Also, this issue can occur on the Exchange Server computer that is running the Internet Mail Service if the header of a message contains malformed information. To resolve this issue see ME293288.

A suggestion from a newsgroup post: "Take the top 5 oldest messages out of the queue, then try and restart the IMC.  If it still won't start take ALL of the messages out of the queue and then restart the IMS.  You'll have to gradually add the messages back in (one or more of the messages is bad).  Keep in mind that the messages won't be recognized until you stop and restart the IMS."
This refers to Exchange 5.5 and Microsoft says that a patched version of store.exe is available. Please see the KB article 325939.


Windows Event Log Analysis Splunk App

Build a great reporting interface using Splunk, one of the leaders in the Security Information and Event Management (SIEM) field, linking the collected Windows events to www.eventid.net.

Read more...

 

Cisco ASA Log Analyzer Splunk App

Obtain enhanced visibility into Cisco ASA firewall logs using the free Firegen for Cisco ASA Splunk App. Take advantage of dashboards built to optimize the threat analysis process.

Read more...