RE: Security Log errors

2002-11-12 Thread Ed Crowley
I wouldn't worry about it with 135 users.  Select "Rebuild" whenever you
feel the urge.

Ed Crowley MCSE+Internet MVP kcCC+I
Tech Consultant
hp Services
Protecting the world from PSTs and Bricked Backups!


-Original Message-
From: [EMAIL PROTECTED]
[mailto:bounce-exchange-94760@;ls.swynk.com] On Behalf Of Hooks, Tim
Sent: Tuesday, November 12, 2002 8:25 AM
To: Exchange Discussions
Subject: RE: Security Log errors


The two choices I have for the RUS agreements are "rebuild" or "update
now" - are there potential negative consequences to running either of
these operations in the middle of the day? I have only about 135 users
and the server has lots of RAM and processing power. Thanks.

Tim Hooks

-Original Message-
From: Hooks, Tim 
Sent: Tuesday, November 12, 2002 10:13 AM
To: Exchange Discussions
Subject: Security Log errors


I have security event log errors on my domain controllers ever since
bringing Exchange 2000 into our enterprise. A little background - single
domain, single site, win2k SP3, native mode. Exchange 2k SP2 - moved
mailboxes from an Exchange 5.5 box and followed the steps to remove the
first exchange server. Exchange 5.5 was uninstalled from the old server,
but the box itself remains as a DC on the network.

The errors occur every minute for 15 minutes, every 4 hours, exactly
when one of the RUS runs. When the RUS was "Always Run" so were the
errors. There are 2 RUS entries, one updates all the time and works fine
(Recipient Update Service (Athena)). The other runs every four hours and
produces 15 errors per pop (Recipient Update Service (Enterprise
Configuration)). Do I really need two of these? Is there anyway to see
what exactly is in the individual RUS?

Thanks for your help.

Tim Hooks, MCSE
Columbus, OH

Here is the error message:

Event Type: Failure Audit
Event Source:   Security
Event Category: Directory Service Access 
Event ID:   565
Date:   11/12/2002
Time:   7:05:21 AM
User:   ATHENA\ARIES$
Computer:   HERMES
Description:
Object Open:
Object Server:  DS
Object Type:configuration
Object Name:CN=Configuration,DC=inside,DC=kbhr,DC=com
New Handle ID:  -
Operation ID:   {0,1638256139}
Process ID: 296
Primary User Name:  HERMES$
Primary Domain: ATHENA
Primary Logon ID:   (0x0,0x3E7)
Client User Name:   ARIES$
Client Domain:  ATHENA
Client Logon ID:(0x0,0x61A5CDFF)
AccessesControl Access 

Privileges  -

 Properties:
READ_CONTROL 
Create Child 
Delete Child 
List Contents 
Write Self 
Delete Tree 
Manage Replication Topology

 

_
List posting FAQ:   http://www.swinc.com/resource/exch_faq.htm
Archives:   http://www.swynk.com/sitesearch/search.asp
To unsubscribe: mailto:leave-exchange@;ls.swynk.com
Exchange List admin:[EMAIL PROTECTED]

_
List posting FAQ:   http://www.swinc.com/resource/exch_faq.htm
Archives:   http://www.swynk.com/sitesearch/search.asp
To unsubscribe: mailto:leave-exchange@;ls.swynk.com
Exchange List admin:[EMAIL PROTECTED]


_
List posting FAQ:   http://www.swinc.com/resource/exch_faq.htm
Archives:   http://www.swynk.com/sitesearch/search.asp
To unsubscribe: mailto:leave-exchange@;ls.swynk.com
Exchange List admin:[EMAIL PROTECTED]



RE: Security Log errors

2002-11-12 Thread David N. Precht
http://www.eventid.net/display.asp?eventid=565&source=

-Original Message-
From: [EMAIL PROTECTED]
[mailto:bounce-exchange-224131@;ls.swynk.com] On Behalf Of Hooks, Tim
Sent: Tuesday, November 12, 2002 10:13
To: Exchange Discussions
Subject: Security Log errors


I have security event log errors on my domain controllers ever since
bringing Exchange 2000 into our enterprise. A little background - single
domain, single site, win2k SP3, native mode. Exchange 2k SP2 - moved
mailboxes from an Exchange 5.5 box and followed the steps to remove the
first exchange server. Exchange 5.5 was uninstalled from the old server,
but the box itself remains as a DC on the network.

The errors occur every minute for 15 minutes, every 4 hours, exactly
when one of the RUS runs. When the RUS was "Always Run" so were the
errors. There are 2 RUS entries, one updates all the time and works fine
(Recipient Update Service (Athena)). The other runs every four hours and
produces 15 errors per pop (Recipient Update Service (Enterprise
Configuration)). Do I really need two of these? Is there anyway to see
what exactly is in the individual RUS?

Thanks for your help.

Tim Hooks, MCSE
Columbus, OH

Here is the error message:

Event Type: Failure Audit
Event Source:   Security
Event Category: Directory Service Access 
Event ID:   565
Date:   11/12/2002
Time:   7:05:21 AM
User:   ATHENA\ARIES$
Computer:   HERMES
Description:
Object Open:
Object Server:  DS
Object Type:configuration
Object Name:CN=Configuration,DC=inside,DC=kbhr,DC=com
New Handle ID:  -
Operation ID:   {0,1638256139}
Process ID: 296
Primary User Name:  HERMES$
Primary Domain: ATHENA
Primary Logon ID:   (0x0,0x3E7)
Client User Name:   ARIES$
Client Domain:  ATHENA
Client Logon ID:(0x0,0x61A5CDFF)
AccessesControl Access 

Privileges  -

 Properties:
READ_CONTROL 
Create Child 
Delete Child 
List Contents 
Write Self 
Delete Tree 
Manage Replication Topology

 

_
List posting FAQ:   http://www.swinc.com/resource/exch_faq.htm
Archives:   http://www.swynk.com/sitesearch/search.asp
To unsubscribe: mailto:leave-exchange@;ls.swynk.com
Exchange List admin:[EMAIL PROTECTED]


_
List posting FAQ:   http://www.swinc.com/resource/exch_faq.htm
Archives:   http://www.swynk.com/sitesearch/search.asp
To unsubscribe: mailto:leave-exchange@;ls.swynk.com
Exchange List admin:[EMAIL PROTECTED]



RE: Security Log errors

2002-11-12 Thread Hooks, Tim
The two choices I have for the RUS agreements are "rebuild" or "update now" - are 
there potential negative consequences to running either of these operations in the 
middle of the day? I have only about 135 users and the server has lots of RAM and 
processing power. Thanks.

Tim Hooks

-Original Message-
From: Hooks, Tim 
Sent: Tuesday, November 12, 2002 10:13 AM
To: Exchange Discussions
Subject: Security Log errors


I have security event log errors on my domain controllers ever since bringing Exchange 
2000 into our enterprise. A little background - single domain, single site, win2k SP3, 
native mode. Exchange 2k SP2 - moved mailboxes from an Exchange 5.5 box and followed 
the steps to remove the first exchange server. Exchange 5.5 was uninstalled from the 
old server, but the box itself remains as a DC on the network.

The errors occur every minute for 15 minutes, every 4 hours, exactly when one of the 
RUS runs. When the RUS was "Always Run" so were the errors. There are 2 RUS entries, 
one updates all the time and works fine (Recipient Update Service (Athena)). The other 
runs every four hours and produces 15 errors per pop (Recipient Update Service 
(Enterprise Configuration)). Do I really need two of these? Is there anyway to see 
what exactly is in the individual RUS?

Thanks for your help.

Tim Hooks, MCSE
Columbus, OH

Here is the error message:

Event Type: Failure Audit
Event Source:   Security
Event Category: Directory Service Access 
Event ID:   565
Date:   11/12/2002
Time:   7:05:21 AM
User:   ATHENA\ARIES$
Computer:   HERMES
Description:
Object Open:
Object Server:  DS
Object Type:configuration
Object Name:CN=Configuration,DC=inside,DC=kbhr,DC=com
New Handle ID:  -
Operation ID:   {0,1638256139}
Process ID: 296
Primary User Name:  HERMES$
Primary Domain: ATHENA
Primary Logon ID:   (0x0,0x3E7)
Client User Name:   ARIES$
Client Domain:  ATHENA
Client Logon ID:(0x0,0x61A5CDFF)
AccessesControl Access 

Privileges  -

 Properties:
READ_CONTROL 
Create Child 
Delete Child 
List Contents 
Write Self 
Delete Tree 
Manage Replication Topology

 

_
List posting FAQ:   http://www.swinc.com/resource/exch_faq.htm
Archives:   http://www.swynk.com/sitesearch/search.asp
To unsubscribe: mailto:leave-exchange@;ls.swynk.com
Exchange List admin:[EMAIL PROTECTED]

_
List posting FAQ:   http://www.swinc.com/resource/exch_faq.htm
Archives:   http://www.swynk.com/sitesearch/search.asp
To unsubscribe: mailto:leave-exchange@;ls.swynk.com
Exchange List admin:[EMAIL PROTECTED]



RE: Security Log errors

2002-11-12 Thread Hooks, Tim
Did not have three that I know of. The "Operation ID" changes in each message as does 
the as does the "Client Logon ID:" the rest is exactly the same. Thanks for your help.

Tim Hooks

-Original Message-
From: Tony Hlabse [mailto:thlabse@;hotmail.com]
Sent: Tuesday, November 12, 2002 10:40 AM
To: Exchange Discussions
Subject: Re: Security Log errors


By default two RUS's are setup when you install E2K. One is for the domain
where the Exchange server is located in the other is for the
enterprise configuration. You say you have only two. Did you have a third at
one time when your 5.5 box was online. Also is the error exactly the same
each time. If so maybe an object is being called that is no longer there?

- Original Message -
From: "Hooks, Tim" <[EMAIL PROTECTED]>
To: "Exchange Discussions" <[EMAIL PROTECTED]>
Sent: Tuesday, November 12, 2002 10:13 AM
Subject: Security Log errors


I have security event log errors on my domain controllers ever since
bringing Exchange 2000 into our enterprise. A little background - single
domain, single site, win2k SP3, native mode. Exchange 2k SP2 - moved
mailboxes from an Exchange 5.5 box and followed the steps to remove the
first exchange server. Exchange 5.5 was uninstalled from the old server, but
the box itself remains as a DC on the network.

The errors occur every minute for 15 minutes, every 4 hours, exactly when
one of the RUS runs. When the RUS was "Always Run" so were the errors. There
are 2 RUS entries, one updates all the time and works fine (Recipient Update
Service (Athena)). The other runs every four hours and produces 15 errors
per pop (Recipient Update Service (Enterprise Configuration)). Do I really
need two of these? Is there anyway to see what exactly is in the individual
RUS?

Thanks for your help.

Tim Hooks, MCSE
Columbus, OH

Here is the error message:

Event Type: Failure Audit
Event Source: Security
Event Category: Directory Service Access
Event ID: 565
Date: 11/12/2002
Time: 7:05:21 AM
User: ATHENA\ARIES$
Computer: HERMES
Description:
Object Open:
  Object Server: DS
  Object Type: configuration
  Object Name: CN=Configuration,DC=inside,DC=kbhr,DC=com
  New Handle ID: -
  Operation ID: {0,1638256139}
  Process ID: 296
  Primary User Name: HERMES$
  Primary Domain: ATHENA
  Primary Logon ID: (0x0,0x3E7)
  Client User Name: ARIES$
  Client Domain: ATHENA
  Client Logon ID: (0x0,0x61A5CDFF)
  Accesses Control Access

  Privileges -

 Properties:
READ_CONTROL
Create Child
Delete Child
List Contents
Write Self
Delete Tree
Manage Replication Topology



_
List posting FAQ:   http://www.swinc.com/resource/exch_faq.htm
Archives:   http://www.swynk.com/sitesearch/search.asp
To unsubscribe: mailto:leave-exchange@;ls.swynk.com
Exchange List admin:[EMAIL PROTECTED]

_
List posting FAQ:   http://www.swinc.com/resource/exch_faq.htm
Archives:   http://www.swynk.com/sitesearch/search.asp
To unsubscribe: mailto:leave-exchange@;ls.swynk.com
Exchange List admin:[EMAIL PROTECTED]

_
List posting FAQ:   http://www.swinc.com/resource/exch_faq.htm
Archives:   http://www.swynk.com/sitesearch/search.asp
To unsubscribe: mailto:leave-exchange@;ls.swynk.com
Exchange List admin:[EMAIL PROTECTED]



Re: Security Log errors

2002-11-12 Thread Tony Hlabse
By default two RUS's are setup when you install E2K. One is for the domain
where the Exchange server is located in the other is for the
enterprise configuration. You say you have only two. Did you have a third at
one time when your 5.5 box was online. Also is the error exactly the same
each time. If so maybe an object is being called that is no longer there?

- Original Message -
From: "Hooks, Tim" <[EMAIL PROTECTED]>
To: "Exchange Discussions" <[EMAIL PROTECTED]>
Sent: Tuesday, November 12, 2002 10:13 AM
Subject: Security Log errors


I have security event log errors on my domain controllers ever since
bringing Exchange 2000 into our enterprise. A little background - single
domain, single site, win2k SP3, native mode. Exchange 2k SP2 - moved
mailboxes from an Exchange 5.5 box and followed the steps to remove the
first exchange server. Exchange 5.5 was uninstalled from the old server, but
the box itself remains as a DC on the network.

The errors occur every minute for 15 minutes, every 4 hours, exactly when
one of the RUS runs. When the RUS was "Always Run" so were the errors. There
are 2 RUS entries, one updates all the time and works fine (Recipient Update
Service (Athena)). The other runs every four hours and produces 15 errors
per pop (Recipient Update Service (Enterprise Configuration)). Do I really
need two of these? Is there anyway to see what exactly is in the individual
RUS?

Thanks for your help.

Tim Hooks, MCSE
Columbus, OH

Here is the error message:

Event Type: Failure Audit
Event Source: Security
Event Category: Directory Service Access
Event ID: 565
Date: 11/12/2002
Time: 7:05:21 AM
User: ATHENA\ARIES$
Computer: HERMES
Description:
Object Open:
  Object Server: DS
  Object Type: configuration
  Object Name: CN=Configuration,DC=inside,DC=kbhr,DC=com
  New Handle ID: -
  Operation ID: {0,1638256139}
  Process ID: 296
  Primary User Name: HERMES$
  Primary Domain: ATHENA
  Primary Logon ID: (0x0,0x3E7)
  Client User Name: ARIES$
  Client Domain: ATHENA
  Client Logon ID: (0x0,0x61A5CDFF)
  Accesses Control Access

  Privileges -

 Properties:
READ_CONTROL
Create Child
Delete Child
List Contents
Write Self
Delete Tree
Manage Replication Topology



_
List posting FAQ:   http://www.swinc.com/resource/exch_faq.htm
Archives:   http://www.swynk.com/sitesearch/search.asp
To unsubscribe: mailto:leave-exchange@;ls.swynk.com
Exchange List admin:[EMAIL PROTECTED]

_
List posting FAQ:   http://www.swinc.com/resource/exch_faq.htm
Archives:   http://www.swynk.com/sitesearch/search.asp
To unsubscribe: mailto:leave-exchange@;ls.swynk.com
Exchange List admin:[EMAIL PROTECTED]