Build a great reporting interface using Splunk, one of the leaders in the Security Information and Event Management (SIEM) field, linking the collected Windows events to www.eventid.net. The EventId.Net for Splunk Add-on assumes that Splunk is collecting information from Windows servers and workstation via the Splunk Universal Forwarder.
When deleting the Store Mailbox from '</o=XXX/ou=XXX/cn=Recipients/cn=user>' on server '<server name>' the operation failed with the following error code: 3. (Connection Agreement '<XXX-CA>' #356).
|English: Request a translation of the event description in plain English.|
|Concepts to understand:|
What is the role of the Microsoft Active Directory Connector (MSADC) ?
See MSEX2KDB for information about this event.
This may happen when an Exchange 5.5 Mailbox is deleted from the Active Directory side (e.g. using ADUC), and when the mailbox store does not exist (for example, nobody ever logged into that mailbox).
When the Active Directory Connector replicates the deletion, it deletes the Exchange 5.5 Directory entry for the mailbox and attempts to delete the associated mailbox store. When no store exists, this event is logged. In this case, this event may be ignored.
Of course, if the store deletion fails for some other reason (e.g. the Information store is not running), the mailbox store should still be deleted manually to avoid a DS/IS consistency check recreating the Directory entry.
|Private comment: Subscribers only. See example of private comment|
|Search: Google - Bing - Microsoft - Yahoo - EventID.Net Queue (0) - More links...|
Send comments or solutions
- Notify me when updated