HI,
we have an issue with scom on our Domain Controllers. Every Time we have an Event id 31 from Kerberos-Key-Distribution-Center, Scom Client writes an Error from a few Monitors into Operations Manager EVENTLOG.
i have also tried to create a Alert Rule for this Event, but this rule has no effect - i receive Alerts. Maybe someon has an idea how to resolve this issue.
Maybe i should create an Ticket for this issue?
Event ID 31:
A ticket to the service ldap/"DC Name"/"DomainName" is issued for account"AccountName"@"DomainName". The size of the encrypted part of this ticket is 36650 bytes, which is close or greater than the configured ticket size threshold (12000 bytes). This ticket or any additional tickets issued from this ticket might result in authentication failures if the client or server application allocates SSPI token buffers bounded by a value that is close to the threshold value.
The size of ticket is largely determined by the size of authorization data it carries. The size of authorization data is determined by the groups the account is member of, the claims data the account is setup for, and the resource groups resolved in the resource domain.
Operations Manager Events 26007
The EventLog service reported that the System event log on computer DC is corrupt. The Windows Event Log Provider will attempt to recover by re-opening log.
One or more workflows were affected by this.
Workflow name: many
Instance name: many
Instance ID: many
Management group: xxxx
The EventLog service reported that the System event log on computer DC is corrupt. The Windows Event Log Provider will attempt to recover by re-opening log.
One or more workflows were affected by this.
Workflow name: Microsoft.SystemCenter.Apm.Infrastructure.Monitoring.ApmAgent.IISRecycle.Monitor
Instance name: DC
Instance ID: {6BA8F68D-8FD9-907F-6533-A2D5D946D985}
Management group: XXXX
The EventLog service reported that the System event log on Computer DC is corrupt. The Windows Event Log Provider will attempt to recover by re-opening log.
One or more workflows were affected by this.
Workflow name: Microsoft.SystemCenter.Apm.Infrastructure.Monitoring.ApmAgent.IISRestart.Monitor
Instance name: DC
Instance ID: {6BA8F68D-8FD9-907F-6533-A2D5D946D985}
Management group: XXXX
The EventLog service reported that the System event log on computer DC is corrupt. The Windows Event Log Provider will attempt to recover by re-opening log.
One or more workflows were affected by this.
Workflow name: Microsoft.Windows.Server.2008.OperatingSystem.ServerServiceConfiguration
Instance name: Microsoft Windows Server 2012 R2 Standard
Instance ID: {C611D00E-24D1-4A5A-CE00-92D16473403E}
Management group: XXXXX
many thanks
Christian