Build a great reporting interface using Splunk, one of the leaders in the Security Information and Event Management (SIEM) field, linking the collected Windows events to www.eventid.net. The EventId.Net for Splunk Add-on assumes that Splunk is collecting information from Windows servers and workstation via the Splunk Universal Forwarder.
|Source: MSExchangeIS Mailbox Store|
Unexpected error "DOC_TOO_HUGE: There are not enough resources to process the document or row" occurred while indexing document.
Mailbox Database: Mailbox01
Folder ID: 2-22B
Message ID: 2-3DE2CD
Document ID: 11975663
Error Code: 0x8004364a
|English: Request a translation of the event description in plain English.|
From a Microsoft support forum:
This is by design.
Exchange will log this event anytime that we try to index a message with more than 256 attachments
1) Run Exfolders and Export the FIDs from the server
2) Search thru the list of FIDS looking for the mailbox associated with the FID in the event
3) Run exfolders and open the mailbox that contains the folder
4) Select the folder associated with the FID
5) Choose “Export Item Properties”
6) Put ptagMID (0x674A0014) in the property list
7) Run the export to a file and you will have a searchable list of MIDs
|Private comment: Subscribers only. See example of private comment|
|Search: Google - Bing - Microsoft - Yahoo - EventID.Net Queue (0) - More links...|
|Custom search for *****: Google - Bing - Microsoft - Yahoo|
Send comments or solutions
- Notify me when updated