Build a great reporting interface using Splunk, one of the leaders in the Security Information and Event Management (SIEM) field, linking the collected Windows events to www.eventid.net. The EventId.Net for Splunk Add-on assumes that Splunk is collecting information from Windows servers and workstation via the Splunk Universal Forwarder.
The message tracking log file C:\Program Files\Exchsrvr\SOCRATES.log\20020525.log was deleted.
|English: Request a translation of the event description in plain English.|
|Concepts to understand:|
What is the role of the Microsoft Exchange System Attendant (MSExchangeSA) service?
How is message tracking enabled in Exchange 2000 server?
As per Microsoft: "A logfile became outdated and was deleted to conserve disk space". See MSEX2KDB for additional information on this event.
On Exchange, one can configure message tracking in order to monitor the email traffic. In order to avoid filling up the drive, the older logs are periodically deleted and this message is recorded in the event log.
The System Attendant is set to delete the log files after x number of days. To fix this, open MS Exchange Administrator and highlight the server and double click on the System Attendant on the right pane and change the Message tracking log file maintenance settings to the number of days required.
See ME271426 - Message Tracking Log Removal Does Not Include Current Date.
|Private comment: Subscribers only. See example of private comment|
|Links: ME271426, MSEX2KDB|
|Search: Google - Bing - Microsoft - Yahoo - EventID.Net Queue (0) - More links...|
Send comments or solutions
- Notify me when updated