Event log doesn't overwrite as needed in SP4

Posted on 2003-11-05
Last Modified: 2010-04-13
Hello All,
After upgrading from SP3 to SP4 on several Windows 2000 PRO machines everything looked fine, but from time to time applications can't write to the event log.
When I try to view the application event log it appears to be empty. If I "clear all events" and re-start the service, the problem is fixed and applications can write to the event log. But it usually repeats itself after a few hours/days.

I could replicate this problem several times and it is very disturbing because I have many applications writing to the event log.
The application event log is set to "overwrite events as needed'.

Any ideas?

Question by:idophir
Welcome to Experts Exchange

Add your voice to the tech community where 5M+ people just like you are talking about what matters.

  • Help others & share knowledge
  • Earn cash & points
  • Learn & ask questions
  • 4
  • 2
  • 2
  • +1
LVL 49

Expert Comment

ID: 9687335
Check this

you may get some idea


Author Comment

ID: 9687388
Couldn't find anything.
Optimize your web performance

What's in the eBook?
- Full list of reasons for poor performance
- Ultimate measures to speed things up
- Primary web monitoring types
- KPIs you should be monitoring in order to increase your ROI


Author Comment

ID: 9687507
The event log is proparly configured - it just not working as it should.
The first link shows a way to clear the log using a script. I might use it if I won't find any other solution but I don't like it.
LVL 15

Expert Comment

by:Rob Stone
ID: 9687904
Try going back to SP3 on one machine and see if it still happens.  If it doesn't, reapply SP4 and hope it works OK.

Author Comment

ID: 9688029
It worked fine with SP3.
It happened on many machines including in a different company - I don't think re-applying will help.
LVL 15

Expert Comment

by:Rob Stone
ID: 9693033
There are a lot of bugs with SP4 so it might be worth just keeping on SP3 with latest patch's until SP4a/SP5 comes out.

Author Comment

ID: 9693594
That is always a good advice - always be one step behind with MS products.
However, I don't want to go back to SP3 because I would hate to test the MS uninstall utility.

Accepted Solution

royaleflan earned 400 total points
ID: 10082581

I am also experiencing this same problem (event log not overwriting as needed) on W2K systems in the field.

You might want to try this SP4 hotfix. The hotfix claims to fix a problem with corrupt event log files when the log is full and wraps.;en-us;829246

Featured Post

Complete VMware vSphere® ESX(i) & Hyper-V Backup

Capture your entire system, including the host, with patented disk imaging integrated with VMware VADP / Microsoft VSS and RCT. RTOs is as low as 15 seconds with Acronis Active Restore™. You can enjoy unlimited P2V/V2V migrations from any source (even from a different hypervisor)

Question has a verified solution.

If you are experiencing a similar issue, please ask a related question

NTFS file system has been developed by Microsoft that is widely used by Windows NT operating system and its advanced versions. It is the mostly used over FAT file system as it provides superior features like reliability, security, storage, efficienc…
A look at what happened in the Verizon cloud breach.
In this video, viewers will be given step by step instructions on adjusting mouse, pointer and cursor visibility in Microsoft Windows 10. The video seeks to educate those who are struggling with the new Windows 10 Graphical User Interface. Change Cu…
Monitoring a network: why having a policy is the best policy? Michael Kulchisky, MCSE, MCSA, MCP, VTSP, VSP, CCSP outlines the enormous benefits of having a policy-based approach when monitoring medium and large networks. Software utilized in this v…

622 members asked questions and received personalized solutions in the past 7 days.

Join the community of 500,000 technology professionals and ask your questions.

Join & Ask a Question