Build a great reporting interface using Splunk, one of the leaders in the Security Information and Event Management (SIEM) field, linking the collected Windows events to www.eventid.net. The EventId.Net for Splunk Add-on assumes that Splunk is collecting information from Windows servers and workstation via the Splunk Universal Forwarder.
Failure setting file attributes on file D:\EXCHSRVR\imcdata\in\RB81R3WK. The error code returned was The system cannot find the file specified. This is an unexpected error and the IMS is shutting down
|English: Request a translation of the event description in plain English.|
|Concepts to understand:|
Why are some errors “unexpected”?
What is the role of the Microsoft Exchange Internet Mail Connector service?
Microsoft states that this problem may occur if your antivirus software scans and tries to delete files in the C:\Exchsrvr\Imcdata folder. See ME328667 for more details on this issue.
See Symantec Knowledge Base ID 2000110108382454 for more details.
If you have a software, a file-level virus scanner for example, that is locking the file at the same time Exchange is trying to remove this, you can get this type of error. For example, antivirus scan at file level by NAV 7. It tries to scan messagesin IMCDATA, locks them and IMC can not delete file.
Exclude \exchsrvr on all volumes from scanning by NAV.
|Private comment: Subscribers only. See example of private comment|
|Links: ME328667, Symantec Knowledge Base ID 2000110108382454|
|Search: Google - Bing - Microsoft - Yahoo - EventID.Net Queue (0) - More links...|
Send comments or solutions
- Notify me when updated