Build a great reporting interface using Splunk, one of the leaders in the Security Information and Event Management (SIEM) field, linking the collected Windows events to www.eventid.net. The EventId.Net for Splunk Add-on assumes that Splunk is collecting information from Windows servers and workstation via the Splunk Universal Forwarder.
The browser driver has enqueued too many Master Announcement Datagrams. For more information about how to resolve this problem please search for KB article 888107 at the Microsoft support site.
|English: Request a translation of the event description in plain English.|
The KB article referenced in the message does not exist nor is there any reference to this event anywhere in Microsoft’s KB as of this writing (it is in the works however). The issue was seen on a Win2k PDC and can be caused by any of the following:
1. Installing security patch MS04-044 or its superseding patch MS05-011.
2. A master browser announcement packet storm.
The issue is resolved by adding the following DWORD registry key, which is also not documented anywhere: “HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\MRxSmb\Parameters\[MaximumMasterAnnouncementsQueueSize]=<value>”.
The default <value> is 150. Increase this value based on how large your network is or until the event ceases. For example, a very large company may need to set this to 2000 or above.
|Private comment: Subscribers only. See example of private comment|
|Search: Google - Bing - Microsoft - Yahoo - EventID.Net Queue (0) - More links...|
Send comments or solutions
- Notify me when updated