event id 2019

Im gettin this event id 2019 every 5seconds from time to time on my PDC. And havin event id 1083 and 1955 on directory service.

Reading another posts here I downloaded the err.exe and got this:
===========================================================
C:\Documents and Settings\sysadm\My Documents\Err>err c0002a5
# as an HRESULT: Severity: SUCCESS (0), Facility: 0xc00, Code 0x2a5
# for hex 0x2a5 / decimal 677 :
  SE_AUDITID_TGS_TICKET_FAILURE                                 msaudite.h
# Service Ticket Request Failed:%n
# %tUser Name:%t%1%n
# %tUser Domain:%t%2%n
# %tService Name:%t%3%n
# %tTicket Options:%t%4%n
# %tFailure Code:%t%5%n
# %tClient Address:%t%6%n
  ERROR_VOICE_ANSWER                                            raserror.h
# 2 matches found for "c0002a5"
===========================================================

Anyone know how to solve this?
cce-puc-rioAsked:
Who is Participating?
I wear a lot of hats...

"The solutions and answers provided on Experts Exchange have been extremely helpful to me over the last few years. I wear a lot of hats - Developer, Database Administrator, Help Desk, etc., so I know a lot of things but not a lot about one thing. Experts Exchange gives me answers from people who do know a lot about one thing, in a easy to use platform." -Todd S.

Mike KlineCommented:
You are going to have to try and track down what is eating up that non paged pool memory.  It could be something in windows, a driver, an application.  This first blog entry by the debug team goes into great detail and I can't add much to what they have written.

http://blogs.msdn.com/ntdebugging/archive/2006/12/18/Understanding-Pool-Consumption-and-Event-ID_3A00_--2020-or-2019.aspx



http://support.microsoft.com/kb/177415

Thanks

Mike
0
cce-puc-rioAuthor Commented:
Sorry, Im analyzin the event viewer on PDC these days and wrote the wrong event ID on the topic.

The event id that´s happening every 5seconds sometimes is 12294(SAM).

In last few weeks I got the the 2019 (SRV) error too, but it has happened a few days only, the 12294 happens everyday. Are those related?


0
The Ultimate Tool Kit for Technolgy Solution Provi

Broken down into practical pointers and step-by-step instructions, the IT Service Excellence Tool Kit delivers expert advice for technology solution providers. Get your free copy for valuable how-to assets including sample agreements, checklists, flowcharts, and more!

Mike KlineCommented:
They could be related looks like that 12294 is also caused by a resource error

http://support.microsoft.com/kb/887433

There they are advising for checking for malware, so do that; but maybe that 2019 is what is causing the resources to be drained.

Thanks
Mike
0
evilsiCommented:
Hi,
Do you have any symantec products installed on this server? Both Backup exec and symantec antivirus can cuase this if they havent been updated yet the Microsoft updates have been applied.
If so, check the minidump (if blue screens have been occouring) and you may find its the storeport.sys driver that causes it. to fix, manually update all symantec products.
0
cce-puc-rioAuthor Commented:
Nope, I just have Veritas Backup Exec but its on a different server.

This is the 12294 message:
"The SAM database was unable to lockout the account of sysadm due to a resource error, such as a hard disk write failure (the specific error code is in the error data) . Accounts are locked after a certain number of bad passwords are provided so please consider resetting the password of the account mentioned above."

It gives this error like 4 times on a second from time to time. On sunday theres no one working here and the error still happens. I think its some service tryin to use the domain admin account. The password has been changed 3 months ago.

Is there a way to monitor the event to know wich service is trying to use the account?
0
cce-puc-rioAuthor Commented:
mkline71:
After using "dfsutil /PurgeMupCache" the event id 2019 didnt happen(so far). I guess the SAM error is not related... ?
0
cce-puc-rioAuthor Commented:
Moderator please close the topic. We had an issue where the ORF antispam was tryin to use the domain admin account with old credentials. Took a while to figure it out(why windows cannot recognize the service is tryin to use the account? *sigh*)
0

Experts Exchange Solution brought to you by

Your issues matter to us.

Facing a tech roadblock? Get the help and guidance you need from experienced professionals who care. Ask your question anytime, anywhere, with no hassle.

Start your 7-day free trial
It's more than this solution.Get answers and train to solve all your tech problems - anytime, anywhere.Try it for free Edge Out The Competitionfor your dream job with proven skills and certifications.Get started today Stand Outas the employee with proven skills.Start learning today for free Move Your Career Forwardwith certification training in the latest technologies.Start your trial today
OS Security

From novice to tech pro — start learning today.