Solved

System cannot access one or more event logs after upgrade to Windows 2012 R2

Posted on 2014-09-17
11
2,661 Views
Last Modified: 2014-09-29
Hello,
I recently upgraded a Windows 2008 R2 SP1 virtual VMware server to Windows 2012 R2.  The upgrade went well and all applications are functioning properly.  The only hiccup that I have is when I open the Server Manager Dashboard I get a warning the says "Refresh completed with one or more warning messages".  In the Details I get the following:

Configuration refresh message:  the system cannot access one or more event logs because of insufficient access rights, file corruption, or other reasons.  For more information, see the Operational channel in the ServerManagerProvider error log on the target server.

Okay, no problem, I'm logged in as a domain admin so I don't think I really have a permissions issue so here I come Google.  Not surprisingly I find a few posts that point to removing the Microsoft-Windows-DxpTaskRingtone/Analytic registry key.  I don't see that one in my registry.  I find another article that talks about deleting 4 other registry keys:

HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\WINEVT\Channels\Microsoft-Windows-DxpTaskRingtone/Analytic
HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\WINEVT\Channels\Microsoft-Windows-IME-Roaming/Analytic
HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\WINEVT\Channels\Microsoft-Windows-IME-SCDICCOMPILER/Analytic
HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\WINEVT\Channels\Microsoft-Windows-IME-SCTIP/Analytic
HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\WINEVT\Channels\Microsoft-Windows-SPB-HIDI2C/Analytic

I do that and still no love.   Please help if you have any further words of wisdom.

Thanks!
0
Comment
Question by:blkfoot
  • 6
  • 2
  • 2
  • +1
11 Comments
 
LVL 23

Expert Comment

by:bhanukir7
ID: 40329852
Hi blkfoot,

have you verified the permissions on the C:\windows\system32\winevt this needs to have permissions for "eventlog" user and authenticated users normally these two accounts have special permissions.

Try setting the permissions on this folder and confirm if this fixes your issue.

http://social.msdn.microsoft.com/Forums/windowsserver/en-US/c231b5d0-2a36-4ddf-a457-e5f471667302/server-2008-event-log-restore?forum=winserver2008appcompatabilityandcertification

The above link gives the SID of eventlog account.

regards
Bhanu
0
 
LVL 43

Expert Comment

by:Davis McCarn
ID: 40330063
Before doing that, I would always clear the event logs because, most of the time, one of them actually got corrupted.
0
 

Author Comment

by:blkfoot
ID: 40330403
Thanks, Bhanu.  I verified the permission you asked about above as well as the KB article and all of the permissions are correctly set.  I still get the same error.

Thanks, Davis.  I did clear EVERY log and I still get the same error.
0
 
LVL 43

Expert Comment

by:Davis McCarn
ID: 40330460
What version of VMware and the 2012 is a guest (meaning virtualized)?
0
 

Author Comment

by:blkfoot
ID: 40330463
We are running vmWare 5.5 and yes the Windows 2012 R2 server is virtualized.
0
Efficient way to get backups off site to Azure

This user guide provides instructions on how to deploy and configure both a StoneFly Scale Out NAS Enterprise Cloud Drive virtual machine and Veeam Cloud Connect in the Microsoft Azure Cloud.

 

Author Comment

by:blkfoot
ID: 40330474
I guess I should add a little more history to this server in case it's relevant.  This was a physical server that we cloned to vmWare 4.0 and then recently upgraded to vmWare 5.5.  It has always been Windows 2008 R2 though since we virtualized it.
0
 
LVL 53

Expert Comment

by:McKnife
ID: 40331540
Leave out virtualization, it does not operate at that layer.
To find your problem, please run procmon while provoking the error, then search procmon's log for "access denied".
0
 

Author Comment

by:blkfoot
ID: 40331652
Thanks.  I'll give this a try as soon as my application upgrade finishes and let you know what I find.
0
 

Accepted Solution

by:
blkfoot earned 0 total points
ID: 40342023
Sorry, McKnife.  I forgot to respond to this.  I ran procmon but did not find any access denied when I recreated the problem.  I did find that I was having a problem with one of my third party apps though on this server that required me to build a replacement server and migrate away from this server.

I think I had more problems with my upgrade than I thought.

Thanks all for your efforts but this time a rebuild was required.
0
 
LVL 53

Expert Comment

by:McKnife
ID: 40342060
Alright, no problem... glad it worked out for you.
Others forget their threads for several weeks and then come back as if nothing's happened ;)
0
 

Author Closing Comment

by:blkfoot
ID: 40349498
I had to rebuild this server for other reasons so I didn't need to continue pursuing a solution.
0

Featured Post

Is Your AD Toolbox Looking More Like a Toybox?

Managing Active Directory can get complicated.  Often, the native tools for managing AD are just not up to the task.  The largest Active Directory installations in the world have relied on one tool to manage their day-to-day administration tasks: Hyena. Start your trial today.

Question has a verified solution.

If you are experiencing a similar issue, please ask a related question

Suggested Solutions

Title # Comments Views Activity
DNS CName is not working properly? 11 63
Renaming VMware ESXi Hosts 5 63
virtualization 6 54
Understanding VMware NSX 7 18
HOW TO: Upload an ISO image to a VMware datastore for use with VMware vSphere Hypervisor 6.5 (ESXi 6.5) using the vSphere Host Client, and checking its MD5 checksum signature is correct.  It's a good idea to compare checksums, because many installat…
In this article, I will show you HOW TO: Perform a Physical to Virtual (P2V) Conversion the easy way from a computer backup (image).
This Micro Tutorial walks you through using a remote console to access a server and install ESXi 5.1. This example is showing remote access and installation using a Dell server. The hypervisor is the very first component of your virtual infrastructu…
This video shows you how easy it is to boot from ISO images for virtual machines with the ISO images stored on a local datastore on the ESXi host.

948 members asked questions and received personalized solutions in the past 7 days.

Join the community of 500,000 technology professionals and ask your questions.

Join & Ask a Question

Need Help in Real-Time?

Connect with top rated Experts

21 Experts available now in Live!

Get 1:1 Help Now