Build a great reporting interface using Splunk, one of the leaders in the Security Information and Event Management (SIEM) field, linking the collected Windows events to www.eventid.net. The EventId.Net for Splunk Add-on assumes that Splunk is collecting information from Windows servers and workstation via the Splunk Universal Forwarder.
The Microsoft Exchange System Attendant was stopped while message tracking information was being written. Some message tracking information was lost.
|English: Request a translation of the event description in plain English.|
|Concepts to understand:|
What is the role of the Microsoft Exchange System Attendant (MSExchangeSA) service?
As per Microsoft: "The event occurs when there is a backlog of tracking events to be written to the message tracking log and the Exchange System Attendant service is shut down. Although a relatively rare event, it is possible under high Active Directory load conditions". See MSEX2K3DB for more details.
|Private comment: Subscribers only. See example of private comment|
|Search: Google - Bing - Microsoft - Yahoo - EventID.Net Queue (0) - More links...|
Send comments or solutions
- Notify me when updated