Build a great reporting interface using Splunk, one of the leaders in the Security Information and Event Management (SIEM) field, linking the collected Windows events to www.eventid.net. The EventId.Net for Splunk Add-on assumes that Splunk is collecting information from Windows servers and workstation via the Splunk Universal Forwarder.
Microsoft Exchange System Attendant encountered an error while processing the security data for Exchange server '<server name>'.
|English: Request a translation of the event description in plain English.|
|Concepts to understand:|
What is the role of the Microsoft Exchange System Attendant (MSExchangeSA) service?
What is the role on System Attendant service?
As per Microsoft: "This event indicates that the Microsoft Exchange System Attendant Service was unable to access the password management keys for the server specified in the Description section of the Event". See MSEX2K3DB for the most common causes known and for possible resolutions for this problem.
This could be because permissions on one of these key containers are corrupted. See per ME325964 and ME325964 for more details.
This event ID can be accompanied by event IDs 9149, 1005. Essentially there are corrupted keys within the server's key container. See ME280432.
Also together with 9149 and 1005, as per ME325674, "This issue may occur if the server account does not have the correct permissions on both the Exchange Organization container and the server container in Active Directory".
|Private comment: Subscribers only. See example of private comment|
|Links: ME280432, ME325674, ME329033, ME325964, MSEX2K3DB|
|Search: Google - Bing - Microsoft - Yahoo - EventID.Net Queue (0) - More links...|
Send comments or solutions
- Notify me when updated