Build a great reporting interface using Splunk, one of the leaders in the Security Information and Event Management (SIEM) field, linking the collected Windows events to www.eventid.net. The EventId.Net for Splunk Add-on assumes that Splunk is collecting information from Windows servers and workstation via the Splunk Universal Forwarder.
Content index on f:\inetpub\catalog.wci is corrupt. Please shutdown and restart the Content Index Service (cisvc).
|English: Request a translation of the event description in plain English.|
This behavior can occur because of insufficient contiguous virtual memory. The dir files associated with each catalog must be mapped into contiguous virtual memory within the 2 GB of CiSvc process address space. If there is insufficient contiguous virtual memory, the catalog fails to start, and therefore the catalog is reported as corrupted and will be deleted. See ME318339 for a resolution on this problem.
See MSW2KDB for additional information about this event.
Often the trouble shooting of catalog corruption involves simply stopping and starting the Index Server. However, sometimes you will need to rebuild the catalog from scratch (stop Index Server, delete or move the contents of the Catalog.wci directory, and then restart Index). See ME209304 for details.
|Private comment: Subscribers only. See example of private comment|
|Links: ME209304, ME318339, MSW2KDB|
|Search: Google - Bing - Microsoft - Yahoo - EventID.Net Queue (0) - More links...|
Send comments or solutions
- Notify me when updated