Monitor unlimited number of servers
Filter log events
Create email and web-based reports

Direct access to Microsoft articles
Customized keywords for major search engines
Access to premium content

Event ID: 9102 Source: MSExchangeSA

Source
Level
Description
The MAD Monitoring thread was unable to read the state of cluster resources, error '<error code>'.
Comments
 
As per MSEX2K3DB , this event indicates that the monitoring thread of the System Attendant process (Mad.EXE) was unable to query WMI for the state of the Cluster Resources. Specifically, System Attendant could not query WMI for instances of the ExchangeClusterResource class (which is provided by the Exchange WMI Provider, EXWMI.DLL). If this event appears occasionally, it can be safely ignored. If it occurs every five minutes, then the causes need to be investigated. This error can occur because of corruption in the WMI infrastructure, other transient problems with the WMI infrastructure, or network connectivity issues.
MAD is the Exchange System Attendant monitoring thread.

- Error code: 0x80010108 = RPC_E_DISCONNECTED - See ME810861.
- Error code: 0x80041006 = WBEM_E_OUT_OF_MEMORY - There was not enough memory for the operation. Users reported the problem as being solved after increasing the Paging File 4 time the size of physical memory.
- Error code: 0x80041013 = wbemErrProviderLoadFailure - As per Microsoft: "COM cannot locate a provider referenced in the schema. This error may be caused by any of the following:
1. The provider is using a WMI DLL that does not match the .lib fileused when the provider was built.
2. The provider's DLL or any of the DLLs on which it depends is corrupt.
3. The provider failed to export DllRegisterServer.
4. An in-process provider was not registered using /regsvr32.
5. An out-of-process provider was not registered using /regserver". See WMI Errors List for more details.

Error code: 0x800706ba (Error code 0x800706BA) = RPC_S_SERVER_UNAVAILABLE - No additional information.

Windows Event Log Analysis Splunk App

Build a great reporting interface using Splunk, one of the leaders in the Security Information and Event Management (SIEM) field, linking the collected Windows events to www.eventid.net.

Read more...

 

Cisco ASA Log Analyzer Splunk App

Obtain enhanced visibility into Cisco ASA firewall logs using the free Firegen for Cisco ASA Splunk App. Take advantage of dashboards built to optimize the threat analysis process.

Read more...