Build a great reporting interface using Splunk, one of the leaders in the Security Information and Event Management (SIEM) field, linking the collected Windows events to www.eventid.net. The EventId.Net for Splunk Add-on assumes that Splunk is collecting information from Windows servers and workstation via the Splunk Universal Forwarder.
The shadow copies of volume <volume name> were aborted because the diff area file could not grow in time. Consider reducing the IO load on this system to avoid this problem in the future.
|English: This information is only available to subscribers. An example of English, please!|
|Concepts to understand:|
What is the diff area?
What is a shadow copy?
To maintain the consistency of shadow copies, the Volume Shadow Copy Service saves the original data to a shadow copy storage area (also referred to as a Diff Area). This event indicates that Volume Shadow Copy Service encountered an issue when writing to this area. See MSW2KDB for additional information about this event.
See ME887827 for a Volume Shadow Copy Service (VSS) update package for Windows Server 2003. Also check ME826936 and ME833167 for more details.
This issue may also occur when the Volsnap.sys driver has encountered excessive I/O activity and as a result the "diff" area cannot grow, or when the computer has run out of shadow copy storage space. See ME925799 for information on fixing these issues.
|Private comment: Subscribers only. See example of private comment|
|Links: ME826936, ME833167, ME887827, ME925799, MSW2KDB, VSS Tuning Recommendations|
|Search: Google - Bing - Microsoft - Yahoo - EventID.Net Queue (2) - More links...|
|Custom search for *****: Google - Bing - Microsoft - Yahoo|
Send comments or solutions
- Notify me when updated