Monitor unlimited number of servers
Filter log events
Create email and web-based reports

Direct access to Microsoft articles
Customized keywords for major search engines
Access to premium content

Event ID: 9671 Source: MSExchangeIS

Source
Level
Description
User <user name> has exceeded the allowed maximum number of simultaneous registrations for MAPI notifications.

The configured maximum number of event notification registrations is <number>.
Comments
 
As per Microsoft: "When a MAPI client (such as Outlook) starts and connects to an Exchange server, the client registers itself with the Information Store. The client registers its User Datagram Protocol (UDP) post and an IP address so that the server can use this information to communicate to the client when a new message is received by the store for the client. This is called a PUSH NOTIFICATION because the Server PUSHes this information to the client. The server saves the client's Push Notification Registrations in its memory. When a new message is received for a particular client, the server looks up that client's registration information (UDP port and IP address) and informs the client that a new message is waiting in the store. It is then the client's responsibility to download the information so that the user sees the new mail.
Exchange Server now has a limit on the default number of registrations (and context size settings) that can be set up by a particular client. This is set on the server by adding a registry entry and prevents clients from registering more push notifications than set. In such a situation, if the client attempts to set more than the expected number of Push notification registrations an MSExchangeIS event 9671 is logged in the server's application log". See MSEX2K3DB for more details on this event.

Windows Event Log Analysis Splunk App

Build a great reporting interface using Splunk, one of the leaders in the Security Information and Event Management (SIEM) field, linking the collected Windows events to www.eventid.net.

Read more...

 

Cisco ASA Log Analyzer Splunk App

Obtain enhanced visibility into Cisco ASA firewall logs using the free Firegen for Cisco ASA Splunk App. Take advantage of dashboards built to optimize the threat analysis process.

Read more...