Build a great reporting interface using Splunk, one of the leaders in the Security Information and Event Management (SIEM) field, linking the collected Windows events to www.eventid.net. The EventId.Net for Splunk Add-on assumes that Splunk is collecting information from Windows servers and workstation via the Splunk Universal Forwarder.
Volume Shadow Copy Service error: Shadow Copy writer RemovableStorageManager called routine OpenNtmsSessionW which failed with status 0x80070422 (converted to 0x800423f4).
|English: Request a translation of the event description in plain English.|
|Concepts to understand:|
What is Volume Shadow Copy Service (VSS)?
What is a shadow copy?
This problem occurs when you uninstall a program that is listed in this registry subkey: HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\ContentIndex\Catalogs but only the location information is removed from the registry subkey. See ME907574 to solve this problem.
As per Microsoft: "This problem can occur when you back up the system state on a domain controller that has more than 12 IP addresses on one network adapter". See ME311141 to fix this problem.
|Private comment: Subscribers only. See example of private comment|
|Links: ME311141, ME907574|
|Search: Google - Bing - Microsoft - Yahoo - EventID.Net Queue (0) - More links...|
Send comments or solutions
- Notify me when updated