Monitor unlimited number of servers
Filter log events
Create email and web-based reports

Direct access to Microsoft articles
Customized keywords for major search engines
Access to premium content

Comments for event ID 34 currently in the processing queue.

Note: We have not reviewed this information yet so it is unfiltered, exactly how it was submitted by our contributors.

Event ID: 34
Event Source: VMnetAdapter
Event Type: Information
Event Description: () Starting up: 0x894a0bb8 \REGISTRY\MACHINE\SYSTEM\Contr

For more information see Help and Support Center at http://go.microsoft.com/fwlink/events.asp.

Comment:
Event ID: 34
Event Source: OpenFileAgent
Event Type: Error
Event Description: Backup Agent for Open Files Driver not running
Comment:
Event ID: 34
Event Source: Oracle.loaddb
Event Type: Information
Event Description: Audit trail: ACTION : 'CONNECT' DATABASE USER: 'rman' PRIVILEGE : SYSDBA CLIENT USER: larry.ellison CLIENT TERMINAL: AMEDTRMAMC03 STATUS: 0 .
Comment: RAID 5 Recently defragged HDD with 104GB of free space.  When data is copied over and error occurs this error message is generated in event viewer.
Event ID: 34
Event Source: Oracle.jde
Event Type: Information
Event Description: Audit trail: ACTION: 'connect SYS' OSPRIV: OPER CLIENT USER:
SYSTEM CLIENT TERMINAL: DBSERVER STATUS: FAILED (1017).
Comment: We got this Information message every 1 minute. We were not able to find out wich process was causing this issue so we unplugged the net wire from the database machine and the error went out. When we plugged back the cable the issue didn't happen again (weird!!).
Event ID: 34
Event Source: Oracle.ilnk
Event Type: Error
Event Description: Type de l'vnement: Informations
Source de l'vnement: Oracle.ilnk
Catgorie de l'vnement: Aucun
ID de l'vnement: 34
Date: 10/10/2007
Heure: 08:35:52
Utilisateur: N/A
Ordinateur: FRCAPTHY018
Description:
Audit trail: ACTION : 'CONNECT' DATABASE USER: '/' PRIVILEGE : NONE CLIENT USER: EU\FRCAPTHY018''$ CLIENT TERMINAL: FRCAPTHY018 STATUS: 1017 .

Comment:
Event ID: 34
Event Source: VSS
Event Type: -
Event Description: -
Comment: Windows 2008 SP2
In my case the recommended checks were all ok and just the Microsoft Shadow Copy provider installed. Other symptomps: event was preceeded by VSS Event Ids:13 qand 12292, followed by VSS Event Id: 8193.

Solved by recreating the entire shadow copy space
Run

vssadmin list shadowstorage - This lists your current settings

vssadmin Delete ShadowStorage /For=C: /On=D: - Delete the current shadow copy storage space. You'll loose all snapshots! Modify the paramters to your needs.

vssadmin Add ShadowStorage /For=C: /On=D: /MaxSize=1024MB - recreate the shadow copy space



Index: 10572
Event ID: 34
Event Source: VolSnap
Event Type: -
Event Description: -
Comment: Nobody else seems to have documented this, but I found this error can also occur if you have multiple pagefiles configured.
Normally these are defined in HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\Session Manager\Memory Management\PagingFiles

Switching from multiple pagefiles (eg, c:\pagefile1\pagefile.sys and c:\pagefil2\pagefile.sys) to a single pagefile in the root of the filesystem corrected the issue. Index: 5113

Windows Event Log Analysis Splunk App

Build a great reporting interface using Splunk, one of the leaders in the Security Information and Event Management (SIEM) field, linking the collected Windows events to www.eventid.net.

Read more...

 

Cisco ASA Log Analyzer Splunk App

Obtain enhanced visibility into Cisco ASA firewall logs using the free Firegen for Cisco ASA Splunk App. Take advantage of dashboards built to optimize the threat analysis process.

Read more...