Monitor unlimited number of servers
Filter log events
Create email and web-based reports

Direct access to Microsoft articles
Customized keywords for major search engines
Access to premium content

Event ID: 9360 Source: MSExchangeSA

OALGen encountered an error while generating the changes.oab file for version 2 and 3 differential downloads of address list "\Global Address List". The offline address list has not been updated so clients will not be able to download the current set of changes. Check other logged events to find the cause of this error.
If the cause of the problem was intentional or cannot be resolved OALGen can be forced to post a full offline address list by creating the DWORD registry key "HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\MSExchangeSA\Parameters\OAL post full if diff fails" and setting it to 1 on this server. When OALGen next generates the offline address list clients will perform a full OAB download. After that time the registry key should be removed to prevent further full downloads.
This issue may occur if an error occurs when Exchange Server 2003 generates changes to the .oab file. If this error occurs, Outlook may not download the Offline Address Book. See ME922255 to solve this problem.

See the link to "MSDN Blog" and MSEX2K3DB for information about this event.
For Outlook clients that use OAB v2 or v3a, if Exchange Server determines that a differences download is more efficient and if a differences file cannot be generated on a server running Exchange Server 2003 SP2 Exchange Server will not automatically force a full offline address book download. Instead by default Exchange logs MSExchangeSA event 9360 indicating that it was unable to produce a differences file and will not produce a full offline address book file. To change this default setting you must edit the Windows registry as specified in the event log message. See the link to "Improvements for Offline Address Books" for additional information on this issue.

Windows Event Log Analysis Splunk App

Build a great reporting interface using Splunk, one of the leaders in the Security Information and Event Management (SIEM) field, linking the collected Windows events to



Cisco ASA Log Analyzer Splunk App

Obtain enhanced visibility into Cisco ASA firewall logs using the free Firegen for Cisco ASA Splunk App. Take advantage of dashboards built to optimize the threat analysis process.