Monitor unlimited number of servers
Filter log events
Create email and web-based reports

Direct access to Microsoft articles
Customized keywords for major search engines
Access to premium content

Comments for event ID 22 currently in the processing queue.

Note: We have not reviewed this information yet so it is unfiltered, exactly how it was submitted by our contributors.

Event ID: 22
Event Source: HpPcad
Event Type: Error
Event Description: The description for Event ID (22) in source (HpPcad) could not be found. It contains the following insertion string(s):, azmpu, \Device\Midiln0. Translated.
Comment: Occurs upon reboot of machine. System is an HP Kayak XA. It is a Pentium II 400 mhz computer. It is a chemstation in an organic chemical laboratory.
Event ID: 22
Event Source: MvServer
Event Type: Information
Event Description: Type de l'événement : Informations
Source de l'événement : MvServer
Catégorie de l'événement : Aucun
ID de l'événement : 22
Date : 24/01/2004
Heure : 16:56:25
Utilisateur : N/A
Ordinateur : XXXX
Description :
MvServer Service- Registre non défini: Jvm_Version

Comment: I have too id 22 MvWebServer and some problems With BSOD  stop 0x00000007F 0x00000008
I don't find any explication.

Could you help me
Event ID: 22
Event Source: mpio
Event Type: Error
Event Description: A fail-over on \Device\MPIODisk3 was attempted however the attempt failed. The devices will be removed.

For more information see Help and Support Center at
Comment: From a Exchange 2003 cluster running Windows 2003 SP1 hardware-HP MSA500 G2 cluster.
Event ID: 22
Event Source: ISAV
Event Type: Error
Event Description: Cannot retrieve information about loaded anti-virus databases (access to scanner subsystem failed)
Event ID: 22
Event Source: Symantec Antivirus
Event Type: Error
Event Description: Symantec AntiVirus Auto-Protect failed to load.
Event ID: 22
Event Source: Norton Antivirus
Event Type: -
Event Description: -
Comment: shame
ina hamash alakie
shoma bayad windows ro az aval nasb konid
hamash kashke
Index: 3766
Event ID: 22
Event Source: OFADriver
Event Type: Error
Event Description: No se encuentra la descripción del Id. de suceso ( 22 ) en el origen ( OFADriver ). Es posible que el equipo local no tenga la información de Registro o archivos DLL de mensajes necesarios para mostrar mensajes desde un equipo remoto. Es posible que pueda usar el indicador /AUXSOURCE= para recuperar esta descripción consulte Ayuda y soporte técnico para obtener más detalles. La siguiente información es parte del suceso:  20 0   Backup Agent for Open Files.
Event ID: 22
Event Source: TimeServ
Event Type: Warning
Event Description: NetRemoteTOD failed for each PrimarySource
Event ID: 22
Event Source: WHEA-Logger
Event Type: Error
Event Description: Component: Memory
Error Source: BOOT
Error Type: 17

The details view of this entry contains further information.

+ System

  - Provider

   [ Name]  Microsoft-Windows-WHEA-Logger
   [ Guid]  {C26C4F3C-3F66-4E99-8F8A-39405CFED220}

   EventID 22

   Version 0

   Level 2

   Task 0

   Opcode 0

   Keywords 0x8000000000000000

  - TimeCreated

   [ SystemTime]  2013-07-28T03:20:32.900766000Z

   EventRecordID 5592

  - Correlation

   [ ActivityID]  {BADC0011-F912-4FF7-B0A4-F58325A64950}

  - Execution

   [ ProcessID]  1624
   [ ThreadID]  1644

   Channel System

   Computer WIN-EIJ0HJEBK5D

  - Security

   [ UserID]  S-1-5-19

- EventData

  ErrorSource 7
  FRUId {00000000-0000-0000-0000-000000000000}
  FRUText Slot 23
  ValidBits 0xd821
  ErrorStatus 0x400
  PhysicalAddress 0x8000000000000000
  PhysicalAddressMask 0x0
  Node 0x1
  Card 0x1
  Module 0xff
  Bank 0x0
  Device 0xff
  Row 0x0
  Column 0x0
  BitPosition 0x0
  RequesterId 0x0
  ResponderId 0x0
  TargetId 0x0
  ErrorType 17
  Length 1304
  RawData 435045521002FFFFFFFF0100010000000200000018050000352A11001A060C140000000000000000000000000000000000000000000000000000000000000000BDC407CF89B7184EB3C41F732CB5713166A4613D40AB9A40A698F362D464B38F51630C1AC353CD01020000000000000000000000000000000000000000000000C80000004900000001020000010000001411BCA5646FDE4EB8633E83ED7C83B10000000000000000000000000000000001000000536C6F742032330000000000000000000000000021D800000000000000040000000000000000000000000080000000000000000001000100FF000000FF00000000000000000000000000000000000000000000000000000000000000110000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000

Event ID: 22
Event Source: MSExchange RBAC
Event Type: Error
Event Description: (Process w3wp.exe PID 6868) "RBAC-Autorisierung ist wegen des folgenden vorübergehenden Fehlers nicht verfügbar." The Microsoft Exchange Active Directory Topology service on server localhost can''t be contacted via RPC. Error 0x6D9."

Details pane has more precise information on what went wrong:
The Microsoft Exchange Active Directory Topology service on server localhost can''t be contacted via RPC. Error 0x6D9.
   Microsoft.Exchange.Data.Directory.ADTransientException: The Microsoft Exchange Active Directory Topology service on server localhost can''t be contacted via RPC. Error 0x6D9. ---> Microsoft.Exchange.Rpc.RpcException: Error 0x6d9 (In der Endpunktzuordnung sind keine weiteren Endpunkte verfügbar) from HrGetServersForRole bei ThrowRpcException(Int32 rpcStatus String message) bei Microsoft.Exchange.Rpc.RpcClientBase.ThrowRpcException(Int32 rpcStatus String routineName) bei Microsoft.Exchange.Rpc.ADTopology.ADTopoRpcClient.HrGetServersForRole(String[] currentlyUsedServers ServerRole role Int32 serversRequested ServerInfo[]& suitableServers Int32[]& mapping) bei Microsoft.Exchange.Data.Directory.DSAccessTopologyProvider.GetServersForRole(String[] currentlyUsedServers ADServerRole role Int32 serversRequested Int32[]& mapping) --

Comment: The error in my case popped up after I migrated my Exchange 2010 mailboxes to Offie365/Exchange Online and deactivated the Exchange Services as per Microsoft one should do (we did not want to deinstall Exchange yet because we thought this would be a cool fallback solution if anything went wrong with our migration)
However these event gets logged every 30 minutes and is accompanied by id 1015 being logged. Mainly these all are RPC errors as services look for Exchange but it is not answering anymore. Here is what I did to solve the problem:

1. Make sure you have disabled all Exchange related services and you have ended all Exchange related reports in Perfmon (mailboxquotas or whatever you want reported in Server Manager or SBS Console)
2. Go to IIS-Manager. Do not forget to backup your current configuration before doing any changes to IIS configuration. Info on how to do this is found here:
3. After this do the following:
a.) stop all Exchange related app pools by right-clicking and choosing "stop"
b.) go to the extended settings of the respective app pool and alter the entry for immediate startup from "true" to "false". This will prevent the app pools from being started the next time you restart your server
c.) check back your eventlogs after an hour or so. No more entries for eventid 22 and 1015 sometimes even 1019 will have been logged.

Windows Event Log Analysis Splunk App

Build a great reporting interface using Splunk, one of the leaders in the Security Information and Event Management (SIEM) field, linking the collected Windows events to



Cisco ASA Log Analyzer Splunk App

Obtain enhanced visibility into Cisco ASA firewall logs using the free Firegen for Cisco ASA Splunk App. Take advantage of dashboards built to optimize the threat analysis process.