Monitor unlimited number of servers
Filter log events
Create email and web-based reports

Direct access to Microsoft articles
Customized keywords for major search engines
Access to premium content

Event ID: 5 Source: VolSnap

The shadow copy of volume <volume>: could not be created due to insufficient non-paged memory pool for a bitmap structure.
As per Microsoft: "This event indicates that Volume Snapshot Driver was not able to allocate enough system resources to perform an operation". See MSW2KDB for additional information about this event.
See ME887827 for a hotfix applicable to Microsoft Windows Server 2003.

See ME833167 for a Volume Shadow Copy Service (VSS) update package for Windows Server 2003.
After the patch referred by QB833167 failed to solve this problem for me, MS Support suggested that the two following registry keys be set:

HKEY_LOCAL_MACHINE\System\CurrentControlSet\Control\Session Manager\Memory_Management

Key name: PoolUsageMaximum
Data type: REG_DWORD
Radix: Decimal
Value: 60

Key name: PagedPoolSize
Data type: REG_DWORD
Radix: Hex
Value: 0xFFFFFFFF.

After I set these keys in the registry and rebooted, the problem did not appear anymore.

Windows Event Log Analysis Splunk App

Build a great reporting interface using Splunk, one of the leaders in the Security Information and Event Management (SIEM) field, linking the collected Windows events to



Cisco ASA Log Analyzer Splunk App

Obtain enhanced visibility into Cisco ASA firewall logs using the free Firegen for Cisco ASA Splunk App. Take advantage of dashboards built to optimize the threat analysis process.