Monitor for specific Event ID not working

SCOM 2007 R2

I'm going by this article for the How-To
http://technet.microsoft.com/en-us/library/bb309597.aspx

I'm monitoring for Event ID 55.  I got one on a server but no alert was generated.  I tested it using EventCreate.exe, still no alert.

Here's a few screenshots on the config of my monitor.
Why doesn't this work?



For Event Source I used "DNS Name"


March 12th, 2014 4:00pm

I looked up the details for that event id and the source you've specified appears to be incorrect: it should be NTFS

See the following for details:

http://social.technet.microsoft.com/Forums/windows/en-US/c9bbd077-9b27-4a3c-815a-f5a87f2a914e/error-logged-event-id-55-ntfs

So...

Event id equals 55

Event Source equals NTFS

  • Edited by Chunky.1 12 hours 40 minutes ago
Free Windows Admin Tool Kit Click here and download it now
March 12th, 2014 5:46pm

I looked up the details for that event id and the source you've specified appears to be incorrect: it should be NTFS

See the following for details:

http://social.technet.microsoft.com/Forums/windows/en-US/c9bbd077-9b27-4a3c-815a-f5a87f2a914e/error-logged-event-id-55-ntfs

So...

Event id equals 55

Event Source equals NTFS

  • Edited by Chunky.1 Wednesday, March 12, 2014 9:56 PM
  • Marked as answer by JohnB352 15 hours 12 minutes ago
March 13th, 2014 12:41am

I looked up the details for that event id and the source you've specified appears to be incorrect: it should be NTFS

See the following for details:

http://social.technet.microsoft.com/Forums/windows/en-US/c9bbd077-9b27-4a3c-815a-f5a87f2a914e/error-logged-event-id-55-ntfs

So...

Event id equals 55

Event Source equals NTFS

  • Edited by Chunky.1 Wednesday, March 12, 2014 9:56 PM
  • Marked as answer by JohnB352 Thursday, March 13, 2014 7:23 PM
Free Windows Admin Tool Kit Click here and download it now
March 13th, 2014 12:41am

I looked up the details for that event id and the source you've specified appears to be incorrect: it should be NTFS

See the following for details:

http://social.technet.microsoft.com/Forums/windows/en-US/c9bbd077-9b27-4a3c-815a-f5a87f2a914e/error-logged-event-id-55-ntfs

So...

Event id equals 55

Event Source equals NTFS

It souned like you were onto something here.  But.... the field for Event Source is a drop-down list, and NTFS, or even File System, is not one of the choices.  And sure enough, if I open Event Viewer and look at one of the 55s, source is listed as NTFS.

This is my list of choices:

Under Management Group it has Name and ID.  I don't think that would help.  It appears that I'm at a deadend.  I'll Google more.

March 13th, 2014 8:54am

Its not really a drop down, you can type the text value you need.

The choices you see in there are used when you need to specify any SCOM discovered property of the target entity in your event conditions.

Regards,

Saravanan

Free Windows Admin Tool Kit Click here and download it now
March 13th, 2014 10:39am

Can you try to Manually feed in  "NTFS" as the Event Source.

March 13th, 2014 10:39am

The problem may be come form the event source. you should refer to  Marnix Wolf blog on what is the proper value to use to for event source
http://thoughtsonopsmgr.blogspot.hk/2013/11/windows-event-log-monitoring-how-to-get.html
Roger
Free Windows Admin Tool Kit Click here and download it now
March 13th, 2014 10:58am

Just enter NTFS as the event source - as shown in the image provided by Saravanan.

This should resolve the issue, let us know how you get on.


  • Edited by Chunky.1 19 hours 13 minutes ago
March 13th, 2014 11:20am

I looked at something similar relatively recently, you should probably take a look at the following (especially if you're working with 2012);

http://blogs.technet.com/b/kevinholman/archive/2012/09/27/opsmgr-mp-update-new-base-os-mp-6-0-6989-0-adds-support-for-monitoring-windows-server-2012-os-and-fixes-some-previous-issues.aspx

Just for information as an alert for this should already be present - take a look at the rule "NTFS - File System Corrupt" this looks for event id55 or 44 from NTFS or DISK...



  • Edited by Chunky.1 19 hours 4 minutes ago
Free Windows Admin Tool Kit Click here and download it now
March 13th, 2014 11:31am

Chunky.1, yes that was it.  It is now working correctly, I'm getting the alerts.

Thank you Microsoft Hopeless Guy, that was a very helpful article.  And thanks Marnix.

We're on SCOM 2007.  I don't know if that explains why we don't already get the alert that you speak of.

Thank you.

March 13th, 2014 3:25pm

Just enter NTFS as the event source - as shown in the image provided by Saravanan.

This should resolve the issue, let us know how you get on.


  • Edited by Chunky.1 Thursday, March 13, 2014 3:22 PM
Free Windows Admin Tool Kit Click here and download it now
March 13th, 2014 6:18pm

I looked at something similar relatively recently, you should probably take a look at the following (especially if you're working with 2012);

http://blogs.technet.com/b/kevinholman/archive/2012/09/27/opsmgr-mp-update-new-base-os-mp-6-0-6989-0-adds-support-for-monitoring-windows-server-2012-os-and-fixes-some-previous-issues.aspx

Just for information as an alert for this should already be present - take a look at the rule "NTFS - File System Corrupt" this looks for event id55 or 44 from NTFS or DISK...



  • Edited by Chunky.1 Thursday, March 13, 2014 3:31 PM
March 13th, 2014 6:29pm

This topic is archived. No further replies will be accepted.

Other recent topics Other recent topics