I am facing problem suddenly shutdwon of server 2003 - TechRepublic
Question
October 11, 2008 at 03:09 AM
mohankumar.delhi

I am facing problem suddenly shutdwon of server 2003

by mohankumar.delhi . Updated 17 years, 9 months ago

Getting error in event log.
We are using Sap Ecc5 and
oracle 9i on Window 2003.
Production Server is in MSCS cluster involving two nodes

I am facing problem suddenly shutdwon of server

Please find the EVENT LOG..

SNMP Trap: 18006

Date time:
Computer: **********
Source: NIC Agents
Type: Warning
Category: (5)

Description:
A ‘NIC Connectivity Lost’ trap indicates the logical network adapter is failed and connectivity is lost.

Details:
Affected Adapter Slot 0
Affected Adapter Port 2

Event Type: Information
Event Source: EventSystem
Event Category: None
Event ID: 4625
User: N/A
Computer: #####-#####
Description:
The EventSystem sub system is suppressing duplicate event log entries for a duration of 86400 seconds. The suppression timeout can be controlled by a REG_DWORD value named SuppressDuplicateDuration under the following registry key: HKLM\Software\Microsoft\EventSystem\EventLog.

Event Type: Information
Event Source: SAPSGP_35
Event Category: None
Event ID: 0
User: N/A
Computer: #####-#####
Description:
The description for Event ID ( 0 ) in Source ( SAPSGP_35 ) cannot be found. The local computer may not have the necessary registry information or message DLL files to display messages from a remote computer. You may be able to use the /AUXSOURCE= flag to retrieve this description; see Help and Support for details. The following information is part of the event: SAP Service SAPSGP_35 has been stopped successfully..

Event Type: Information
Event Source: SAPPRD_00
Event Category: None
Event ID: 0
User: N/A
Computer: #####-#####
Description:
SAP Service SAPPRD_00 successfully started.
Event Type: Information
Event Source: SAPSGP_35
Event Category: None
Event ID: 0
User: N/A
Computer: #####-#####
Description:
The description for Event ID ( 0 ) in Source ( SAPSGP_35 ) cannot be found. The local computer may not have the necessary registry information or message DLL files to display messages from a remote computer. You may be able to use the /AUXSOURCE= flag to retrieve this description; see Help and Support for details. The following information is part of the event: SAP Service SAPSGP_35 successfully started..

Event Type: Error
Event Source: SAPPRD_00
Event Category: None
Event ID: 35712
User: N/A
Computer: #####-#####
Description:
SAP Basis System: Operating system call SiPeekPendConn failed (error no. 10061)

Event Type: Error
Event Source: SAPPRD_00
Event Category: None
Event ID: 38461
Date: 9/27/2008
Time: 3:08:22 PM
User: N/A
Computer: #####-#####
Description:
Communications data: NiConnect Unsuccessful, Return Code: -0010

Event Type: Error
Event Source: SAPPRD_00
Event Category: None
Event ID: 35716
User: N/A
Computer: #####-#####
Description:
SAP Basis System: Message server disconnected
Event Type: Error
Event Source: SAPPRD_00
Event Category: None
Event ID: 0
Date: 9/27/2008
Time: 3:08:30 PM
User: N/A
Computer: #####-#####
Description:
SAPRC: System died. Reason: (null)

Event Type: Error
Event Source: SAPPRD_00
Event Category: None
Event ID: 0
User: N/A
Computer: #####-#####
Description:
SAPRC: System died. Reason: (null)

Event Type: Information
Event Source: SAPPRD_00
Event Category: None
Event ID: 0
User: N/A
Computer: #####-#####
Description:
SAP Service SAPPRD_00 has been stopped successfully.
Event Type: Information
Event Source: SAPPRD_00
Event Category: None
Event ID: 0
User: N/A
Computer: #####-#####
Description:
SAP Service SAPPRD_00 successfully started.

Event Type: Information
Event Source: LoadPerf
Event Category: None
Event ID: 1001
User: N/A
Computer: #####-#####
Description:
Performance counters for the WmiApRpl (WmiApRpl) service were removed successfully. The Record Data contains the new values of the system Last Counter and Last Help registry entries.

Event Type: Information
Event Source: LoadPerf
Event Category: None
Event ID: 1000
User: N/A
Computer: #####-#####
Description:
Performance counters for the WmiApRpl (WmiApRpl) service were loaded successfully. The Record Data contains the new index values assigned to this service.

Security Log

Event Type: Success Audit
Event Source: Security
Event Category: Logon/Logoff
Event ID: 576
Time: 3:09:53 PM
User: NT AUTHORITY\SYSTEM
Computer: #####-#####
Description:
Special privileges assigned to new logon:
User Name: #####-#####$
Domain: #####
Logon ID: (0x0,0x1193A24D)
Privileges: SeBackupPrivilege
SeRestorePrivilege
SeTakeOwnershipPrivilege
SeDebugPrivilege
SeSystemEnvironmentPrivilege
SeLoadDriverPrivilege
SeImpersonatePrivilege
SeSecurityPrivilege

For more information, see Help and Support Center at http://go.microsoft.com/fwlink/events.asp.
Event Type: Success Audit
Event Source: Security
Event Category: Logon/Logoff
Event ID: 540
Time: 3:09:53 PM
User: NT AUTHORITY\SYSTEM
Computer: #####-#####
Description:
Successful Network Logon:
User Name: #####-#####$
Domain: #####
Logon ID: (0x0,0x1193A24D)
Logon Type: 3
Logon Process: Kerberos
Authentication Package: Kerberos
Workstation Name:
Logon GUID: {28b2059a-93c3-1c91-4ef8-1b12361b3924}
Caller User Name: –
Caller Domain: –
Caller Logon ID: –
Caller Process ID: –
Transited Services: –
Source Network Address: –
Source Port: –

Event Type: Success Audit
Event Source: Security
Event Category: Logon/Logoff
Event ID: 538
Time: 3:09:53 PM
User: NT AUTHORITY\SYSTEM
Computer: #####-#####
Description:
User Logoff:
User Name: #####-#####$
Domain: #####
Logon ID: (0x0,0x1193A24D)
Logon Type: 3

Event Type: Error
Event Source: Userenv
Event Category: None
Event ID: 1508
Date: 10/11/2008
Time: 12:37:25 PM
User: NT AUTHORITY\SYSTEM
Computer: ***-***
Description:
Windows was unable to load the registry. This is often caused by insufficient memory or insufficient security rights.

DETAIL – The process cannot access the file because it is being used by another process. for C:\Documents and Settings\ADM\ntuser.dat

Event Type: Error
Event Source: Userenv
Event Category: None
Event ID: 1502
Date: 10/11/2008
Time: 12:37:27 PM
User: ***\ADM
Computer: ***-***
Description:
Windows cannot load the locally stored profile. Possible causes of this error include insufficient security rights or a corrupt local profile. If this problem persists, contact your network administrator.

DETAIL – The process cannot access the file because it is being used by another process.

Event Type: Error
Event Source: Userenv
Event Category: None
Event ID: 1515
User: ***\ADM
Computer: ***-***
Description:
Windows has backed up this user’s profile. Windows will automatically try to use the backed up profile the next time this user logs on.

Event Type: Error
Event Source: Userenv
Event Category: None
Event ID: 1511
Date: 10/11/2008
Time: 12:37:27 PM
User: ***\ADM
Computer: ***-***
Description:
Windows cannot find the local profile and is logging you on with a temporary profile. Changes you make to this profile will be lost when you log off.

Event Type: Information
Event Source: Application Management
Event Category: None
Event ID: 308
Date: 10/11/2008
Time: 12:37:31 PM
User: ***\ADM
Computer: ***-***
Description:
Changes to software installation settings were applied successfully.

Event Type: Information
Event Source: Application Error
Event Category: (100)
Event ID: 1004
Date: 10/11/2008
Time: 12:38:16 PM
User: N/A
Computer: ***-***
Description:
Reporting queued error: faulting application disp+work.EXE, version 6400.128.12.45192, faulting module oracommon9.dll, version 9.2.0.7, fault address 0x00000000000c7500.

For more information, see Help and Support Center at http://go.microsoft.com/fwlink/events.asp.
Data:
0000: 41 70 70 6c 69 63 61 74 Applicat
0008: 69 6f 6e 20 46 61 69 6c ion Fail
0010: 75 72 65 20 20 64 69 73 ure dis
0018: 70 2b 77 6f 72 6b 2e 45 p+work.E
0020: 58 45 20 36 34 30 30 2e XE 6400.
0028: 31 32 38 2e 31 32 2e 34 128.12.4
0030: 35 31 39 32 20 69 6e 20 5192 in
0038: 6f 72 61 63 6f 6d 6d 6f oracommo
0040: 6e 39 2e 64 6c 6c 20 39 n9.dll 9
0048: 2e 32 2e 30 2e 37 20 61 .2.0.7 a
0050: 74 20 6f 66 66 73 65 74 t offset
0058: 20 30 30 30 30 30 30 30 0000000
0060: 30 30 30 30 63 37 35 30 0000c750
0068: 30 0

Thanks

This discussion is locked

All Comments