Quantcast
Channel: Operations Manager - General forum
Viewing all 11941 articles
Browse latest View live

Service Monitoring - Service should be running only one server at a time

$
0
0

Need to monitor an Application Service which is on a couple of servers but should be running only on one server at a given time.

Need to create a monitor/Alert if it is running on more than 1 server at a given time.

Any suggestions for this?

Thanks

Dilip


Monitor SCVMM 2012 SP1 from SCOM 2012 R2

$
0
0

Hi,

The scenario is the following:

      • SCVMM 2012 SP1 UR5
      • SCOM 2012 R2 UR4

      I want to import the MPs for SCVMM:

      http://www.microsoft.com/en-us/download/details.aspx?id=43707

      http://www.microsoft.com/en-us/download/details.aspx?id=29679

      The document "Guide for System Center Monitoring Pack for System Center 2012 – Virtual Machine Manager" states the following:

      Mandatory Configuration

      In order to use the VMM monitoring pack, you need to integrate Operations Manager with VMM


      And this article http://technet.microsoft.com/en-us/library/hh427297.aspx states the following:


      VMM supports the following versions of Operations Manager:

       

      VMM Version

      Supported Operations Manager Version

      System Center 2012 – Virtual Machine Manager

      • Operations Manager 2007 R2
    • System Center 2012 – Operations Manager
        • VMM in System Center 2012 SP1

          Operations Manager in System Center 2012 SP1

          VMM in System Center 2012 R2

          Operations Manager in System Center 2012 R2


          The questions are:

          Is it possible to monitor SCVMM 2012 SP1 from SCOM 2012 R2?

          if yes,

          Is it possible to only import the SCVMM MPs in SCOM (monitor performance and health of SCVMM) and not integrate SCOM and SCVMM?

          Thanks in advance!

      Operations Manager Event Logs - Event ID 26007 & 26008 on all Domain Controllers - Security Event Log Corrupt

      $
      0
      0

      Hi Fellows,

      I am getting Event ID 26007 & 26008 followed by 26005 very frequently. As described in below thread, I am monitoring SAM Objects Access and have a huge pile of event ID 4661 in my domain controller's security event logs. I cannot compromise on disabling the Object access. I need to know if there is any way to disable monitoring Event ID 4661 or whole Security Event log on domain controllers?

      https://social.technet.microsoft.com/Forums/systemcenter/en-US/28b0c0b1-4fdf-4c6c-a9f6-6f84a0107420/opsmgr-eventid-26007-on-domain-controllers-the-eventlog-service-reported-that-the-security-event?forum=operationsmanagergeneral&prof=required 

      26007:

      The EventLog service reported that the Security event log on computer 'DC1' is corrupt. The Windows Event Log Provider will attempt to recover by re-opening log. 

      One or more workflows were affected by this.  

      Workflow name: MomUIGeneratedRule43c0a0798f374c14960aac5a7cb411ff 
      Instance name: DC1 
      Instance ID: {AEBA31FC-0490-C83F-C22F-6287F6612DEC} 
      Management group: SCOMMG

      26008

      The Security event log on computer 'DC1' is still corrupt. The Event Log Provider will attempt to recover by skipping over a possible bad record. The Provider may skip up to two records. 

      One or more workflows were affected by this.  

      Workflow name: MomUIGeneratedRule43c0a0798f374c14960aac5a7cb411ff 
      Instance name: DC1 
      Instance ID: {AEBA31FC-0490-C83F-C22F-6287F6612DEC} 
      Management group: SCOMMG

      26005

      The Windows Event Log Provider has resumed processing the Security event log on computer 'DC1' after recovering from errors. 

      One or more workflows were affected by this.  

      Workflow name: MomUIGeneratedRule43c0a0798f374c14960aac5a7cb411ff 
      Instance name: DC1 
      Instance ID: {AEBA31FC-0490-C83F-C22F-6287F6612DEC} 
      Management group: SCOMMG


      J.A

      Event 31901 – The registry probe could not connect to the registry of the computer

      $
      0
      0

      Hi, I have been doing a weekly SQL query to try and find any high number of events I get in my SCOM environment.

      One of the events I have stumbled across is 31901 (“The registry probe could not connect to the registry of the computer <name>”) which comes from the “Collect Registry Probe Module Events”

      I have read a couple of previous suggestions on the forum and upon checking I found two different scenarios. For a couple of servers I checked the health and it looked like they had RPC issues. A restart got rid of these problems.

      However the ones left seem to have something in common. They relate to hosts referring to SQL “instances/clusters”. So the “logging computer” is the host and the probe cannot to the registry of the “virtual computer”. In other words the computers that can’t be connected to are all agentless and show as managed by the logging computer under “Agentless Managed”

      If I log onto the host with my SCOM action account and run something like “reg query” against the virtual “instance” I get “ERROR: The network path was not found”. I can ping the instance fine though. I don’t really understand how these instances work but I presume they don’t have services or a registry as such. Therefore is this normal or is there any way I can get rid of the events? I don’t really want to get rid of the rule itself as it did help me find a couple of RPC issues. I could override for that host if this is “normal” and how it should work.

      Windows Server 2012 Logical Disk Free Space (%) Low

      $
      0
      0

      I enabled the monitor "Windows Server 2012 Logical Disk Free Space (%) Low" and configured a low threshold to test. I started to get a bunch of warnings from servers, for example:

      The disk \\?\Volume{ee0222ed-16de-40a5-af89-f95db3fdf5a4} on computer PC is running out of disk space. The value that exceeded the threshold is 11% free space.

      Now I checked on the server, and all the disks have more than 11% free space. Additionally, I don't see any disks with such a name/guid.

      When looking at the additional knowledge of the monitor, I see that it is using the following information:

      Object Name: Logical Disk

      Counter Name: PercentFree 

      My question is where is this disk coming from, and how can I avoid these disks from creating false alarms? When looking in the Windows Server

      From my analyzing the DB, I see that these are the partitions on the server without a volume letter. Any way to avoid getting these discovered and/or alerts, without overriding each one?

      critical error All management server resource pool

      $
      0
      0

      I just receive critical error: All management server resource pool in scom 2012 management console.

      Alert detail:


      Alert subscription data source module encountered errors while running: Alert subscription data source module was unable to find alerts that match the subscription because of database errors.

      The following error(s) were encountered:

      Exception Message: ExecuteScalar requires an open and available Connection. The connection's current state is closed.

       

      One or more workflows were affected by this.


      Workflow name: Subscription3f818422_f4a1_42aa_b1b3_8bc14eb54cd8

      Instance name: Alert Notification Subscription Server

      Instance ID: {E07E3FAB-53BC-BC14-1634-5A6E949F9230}

      Management group: SCOM_2012

       

      What is problem and how to fix it ? I haven't changed any setting in scom !!

       

      Multiple SCOM Alerts for the same unique Windows Event

      $
      0
      0

      Multiple SCOM Alerts are being raised for a single Windows event.

      For e.g., below is the event :

      Date and Time: Description:
      12/15/2014 5:15:36 PM Initiating move for database 'xxxdb02' (FromServer=xxxdagnode1.dt.inc, ToServer=, MoveComment=<Null>)
      Log Name:
      Microsoft-Exchange-HighAvailability/Operational
      Source:
      Microsoft-Exchange-HighAvailability
      Event Number:
      306
      Level:
      4
      Logging Computer:
      xxxdagnode1.dt.inc
      User:
      NT AUTHORITY\SYSTEM
      Event Data:
      < DataItem type =" System.XmlData " time =" 2014-12-15T17:15:37.9848250-05:00 " sourceHealthServiceId =" 261D34BA-3596-ABCF-3728-B5A0AC035D90 " >
      < UserData >
      < EventXML >
        < UniqueId > 2014.12.15.05.15.35.285#9#xxxdagnode2#4d0ce477-5f5c-4304-8c59-292a4a8ca809 </ UniqueId >
        < DatabaseName > xxxdb02 </ DatabaseName >
        < DatabaseGuid > 4d0ce477-5f5c-4304-8b59-292a4a8ca809 </ DatabaseGuid >
        < ActiveServer > XXXDAGNODE1.dt.inc </ ActiveServer >
        < ActionCategory > Move </ ActionCategory >
        < ActionInitiator > Automatic </ ActionInitiator >
        < ActionReason > StoreStopped </ ActionReason >
        < AmRole > PAM </ AmRole >
        < PAMServer > xxxdagnode2.dt.inc </ PAMServer >
        < MountFlags > None </ MountFlags >
        < DismountFlags > SkipCacheFlush </ DismountFlags >
        < MountdialOverride > None </ MountdialOverride >
        < FromServer > xxxdagnode1.dt.inc </ FromServer >
        < TargetServer />
        < TryOtherHealthyServers > True </ TryOtherHealthyServers >
        < SkipValidationChecks > None </ SkipValidationChecks >
        < MoveComment > <Null> </ MoveComment >
        </ EventXML >
        </ UserData >
        </ DataItem >

      But three alerts were raised for this event.

      I double checked with the Unique ID for the Windows Event.

      Also the Duplicate alerts show the Same event in the 'Alert Context' field.

      My environment:

      3 SCOM 2012 R2 UR3 Management Servers.

      1 SQL DB Server

      Service Manager Connector is configured for Alert Sync. However this issue also affect the alerts that are not synced.

      Anybody else faced this issue?

      Can SCOM 2012 monitor IBM Tape Library Events?

      $
      0
      0

      We are looking and researching online to see if someone out there has already developed a solution or MP for monitoring IBM TotalStorage Systems. Even if the MP isn't free, we would be interested in acquiring an already developed solution rather than taking time to authoring our own if need be. I have seen some pretty impressive stuff out there where people have gotten SCOM 2012 to monitor SNMP traps (v1, v2 and v3) for everything from Air Handler fan speeds to old APC UPS systems for going on/off battery. 

      Our situation involves an older IBM TotalStorage 3494 Tape Library. The product that currently receives information from the SNMP traps (Tivoli TEPS) has gone off contract and will soon go away. They have approached our SCOM Team wondering if SCOM can even monitor non-Windows devices via SNMP Trapping. I know it can, and have seen lots of creative solutions. But our Dept. has authorized funds if needed to purchase a MP for this (if one even exists) and would rather take an already existing solution over us trying to create our own.


      Self Healing via SCOM

      $
      0
      0

      Hi,

      Is there anything in SCOM 2012 that can automatically fix problems?  I understand that it's possible to execute scripts so in theory anything can be done but I was wondering if there is anything say in a file server management pack that could manage disk space, event logs, patches, CPU, Memory etc?

      Just a general question, any feedback would be gr8

      Thanks


      Alter De Ruine

      How much additional traffic does agentless monitoring add to your network

      $
      0
      0

      I know this is not a fully evolved question because you could respond, what MP's (Maintenance Packs) do I have installed, and what all am I monitoring, however I am somewhat new to SCOM 2012, I've set it up and have it going, getting great alerting, right on so far! I have about a dozen servers that will not install the SCOM agent either from the management server via discovery, nor manually, and I want to be sure as not to overload the network with additional traffic.

      Your thoughts on this please.

      This is a great product once you wrap your head around it, and after a solid 4 days on it.  :)

      SCOM 2007 R2 migration 2012 R2 questions

      $
      0
      0

      We have a SCOM 2007 R2 CU4 environment which consists of a single server running Windows 2008 Enterprise (non-R2) SP2 32 bit.  The SCOM database runs locally on this server as well, which is SQL 2008 R2 standard.

      I understand our environment is not a candidate for in-place upgrade which is fine, so I started researching the migration steps but am a bit confused since our existing server is 32 bit.  I'd like to just spin up a new 2012 R2 server running SQL 2012 R2 to host the new SCOM 2012 R2 environment and just move everything over, but I'm not sure what the correct order of operations would be since our existing environment is 32 bit.  Do I need to build up a new secondary server in our existing 2007 environment as well as a new SQL server and move clients/operational DB there before I can migrate to 2012 R2?  Can I go straight from 2007 R2 CU4 to 2012 R2?

      I'm also considering just starting over from scratch with a fresh 2012 R2 SCOM environment.  Does anyone have a guide for this process or is it just literally rip/replace agents on the endpoints and uninstall 2007

      Agent managed count and windows computer count is different

      $
      0
      0

      Hi team,

      Windows computer count shows 7000 and agent-managed count shows 6800. could you please tell me how to fix this issue.We are having scom 2012 r2 update 3

      SCOM 2012 R2 Audit Collection Service

      $
      0
      0

      Hi,

      We have 2 management servers in one datacenter and 2 gateway servers in another datacenter. We are planning to implement audit collection service. Can we have single ACS collector in one datacenter to collect logs from all servers ( approx 1000 servers) if port 51909 is open from all servers or do we need seperate ACS collector in each datacenter and dedicated ACS database?where can I have ACS collector and dedicated database?

      Thanks in advance,

      Bunny

      How to configure windows services alerts in SCOM 2012 for all agent servers. For eg, Terminal Services, Netlogon, RPC etc..

      $
      0
      0

      Hi,

      I need to configure different windows services alerts in SCOM 2012. Below are some of the windows services I need to monitor through SCOM.

      Serivce: Windows Management Instrumentation
      Service: Netlogon
      Service: Remote Procedure Call (RPC)
      Service: Server Service
      Service: Terminal Services
      Service: Windows Time
      Service: Workstation
      Service : WWW Publishing Service

      Could some one please assist or share me the details, how to configure these services for windows agent servers.

      Thanks..


      Regards, Rajeev Parambil

      SCOM 2012 - Computer Not Reachable monitor is not cleared

      $
      0
      0

      Hello,

      We are using SCOM 2012 SP1 with Rollup 3.

      We have a problem with the "Computer Not Reachable" monitor.

      Sometimes the monitor is not cleared after the server is available again.

      The monitor "Health Service Heartbeat Failure" is successfully resolved in this situation.

      How can we investigate/debug the problem ?

      Thanks.


      SCOM 2012 R2 - Audit collection Service

      $
      0
      0

      Hi,

      We have 2 management servers in one datacenter and 2 gateway servers in another datacenter. We are planning to implement ACS. Where can i have ACS collector and Database to collect logs from both windows and Linux servers.

      Thanks in Advance

      Bunny

      SQL 2012 DB Engine [Login failed: Account locked out] alerts not received from SCOM 2007 R2

      $
      0
      0

      Dear Experts,

      In our SCOM 2007 R2 environment SQL 2012 DB Engine [Login failed: Account locked out] alerts not received but we are receiving the following alerts fr the DB instance.

      1. Database Backup Failed To Complete
      2. Login failed: Password expired
      3. Log Backup Failed to Complete
      4. Login failed: Password cannot be used at this time
      5. Login failed: Password must be changed
      6. IS Package Failed.

      Why we are not receiving the "Login failed: Account locked out" ? Customers are asking the notification email alert for this Rule even I have checked the override settings everything is enabled by default same as above rules.

      What can be the issue here ?

      Thanks,

      Saravana




      Saravana Raja

      Bypass certificate errors in web transaction monitoring

      $
      0
      0

      Hello,

      I have a portal that has a certificate issue which is creating alerts.

      I am getting error code 2147954575  ERROR_WINHTTP_SECURE_FAILURE

      Is there a way to bypass this? When I record session, the browser takes me to the login page without any errors. This is failing only when I run the test from within SCOM.

      Thanks!

      Monitoring Real-Time Network Device

      $
      0
      0

      Hi
      I have SCOM 2012 and I have network discovery rule, I want to Monitoring my Device Network on Real-Time. I can see Vicinity and Performance Monitor but I must define a specific time range for view history. I want see monitor on Real-Time for view status of Ping response of my network device.
      My Question is, How to configure Monitor (ICMP Ping) on real-time for view status network device. Is possible?

      Thanks.


      Cluster group is not healthy

      $
      0
      0

      Hello,

      My Resource group availability monitor is not healthy although Resource group state monitor is healthy.

      Why "Resource group availability monitor" is not healthy?

      Screen shot attached

      Thanks


      TechNet

      Viewing all 11941 articles
      Browse latest View live


      <script src="https://jsc.adskeeper.com/r/s/rssing.com.1596347.js" async> </script>