Duplicate event ??

  • Thread starter Thread starter Steve Grosz
  • Start date Start date
S

Steve Grosz

Starting today I've been getting this message in my event logs:

The COM sub system is suppressing duplicate event log entries for a
duration of 549888 seconds. The suppression timeout can be controlled
by a REG_DWORD value named SuppressDuplicateDuration under the following
registry key: HKLM\Software\Microsoft\Ole\EventLog.

Can anyone tell me what it is refering to? And how to get it to stop?

Thanks!
Steve
 
In said:
Starting today I've been getting this message in my event logs:

The COM sub system is suppressing duplicate event log entries
for a duration of 549888 seconds. The suppression timeout can
be controlled by a REG_DWORD value named
SuppressDuplicateDuration under the following registry key:
HKLM\Software\Microsoft\Ole\EventLog.

Can anyone tell me what it is refering to? And how to get it to
stop?

What is the offending Event Log entry? Address the source of the
problem rather than just cosmetically hide it. JMO
 
I would love to know that....but I'm not seeing anything wrong in the
event log, except for term servers saying that a printer on my local
machine isn't defined on the remote system.....

How can I find out what the cause is?
 
When you view the logged events in Event Viewer (double-click them in the
right-hand pane) in the upper right corner, third button down is a copy to
clipboard, then you can paste in the body of a reply message.

Please do so for each of the different System Log events (that are a Type:
'Error' or 'Warning') since last boot so we can see all of the event detail.

--
Regards,

Dave Patrick ....Please no email replies - reply in newsgroup.
Microsoft Certified Professional
Microsoft MVP [Windows]
http://www.microsoft.com/protect

:
|I would love to know that....but I'm not seeing anything wrong in the
| event log, except for term servers saying that a printer on my local
| machine isn't defined on the remote system.....
|
| How can I find out what the cause is?
 
In said:
I would love to know that....but I'm not seeing anything wrong
in the event log, except for term servers saying that a printer
on my local machine isn't defined on the remote system.....

Perhaps that is the one. Paste it here as it may be the first
event and thereafter the "flood" of like events is being supressed.

I think that normally at least one event will be posted before
suppression kicks in and that it may offer clues to persue. In
this case it may be that fixing the printer driver mis-match (or or
whatever is the source) resolves the problem. Yoo early to say
much more. IMO
 
Ok, here goes:

Event Type: Warning
Event Source: Print
Event Category: None
Event ID: 3
Date: 8/20/2005
Time: 1:14:12 PM
User: NT AUTHORITY\SYSTEM
Computer: WEB2
Description:
Printer Canon i550 on web2 (from DB1) in session 2 was deleted.

Event Type: Warning
Event Source: Print
Event Category: None
Event ID: 4
Date: 8/20/2005
Time: 1:14:12 PM
User: NT AUTHORITY\SYSTEM
Computer: WEB2
Description:
Printer Canon i550 on web2 (from DB1) in session 2 is pending deletion.

Event Type: Warning
Event Source: Print
Event Category: None
Event ID: 8
Date: 8/20/2005
Time: 1:14:12 PM
User: NT AUTHORITY\SYSTEM
Computer: WEB2
Description:
Printer Canon i550 on web2 (from DB1) in session 2 was purged.

Event Type: Warning
Event Source: Print
Event Category: None
Event ID: 3
Date: 8/20/2005
Time: 1:14:12 PM
User: NT AUTHORITY\SYSTEM
Computer: WEB2
Description:
Printer Auto Canon i550 on web2 (from DB1) in session 2 was deleted.

Event Type: Warning
Event Source: Print
Event Category: None
Event ID: 4
Date: 8/20/2005
Time: 1:14:12 PM
User: NT AUTHORITY\SYSTEM
Computer: WEB2
Description:
Printer Auto Canon i550 on web2 (from DB1) in session 2 is pending deletion.

Event Type: Warning
Event Source: Print
Event Category: None
Event ID: 8
Date: 8/20/2005
Time: 1:14:12 PM
User: NT AUTHORITY\SYSTEM
Computer: WEB2
Description:
Printer Auto Canon i550 on web2 (from DB1) in session 2 was purged.

And then some entires I haven't seen before:

Event Type: Information
Event Source: IPSec
Event Category: None
Event ID: 4294
Date: 8/20/2005
Time: 1:15:34 PM
User: N/A
Computer: WEB2
Description:
The IPSec driver has entered Secure mode. IPSec policies, if they have been
configured, are now being applied to this computer.

Data:
0000: 00 00 00 00 01 00 54 00 ......T.
0008: 00 00 00 00 c6 10 00 40 ....Æ..@
0010: 01 00 00 00 00 00 00 00 ........
0018: 00 00 00 00 00 00 00 00 ........
0020: 00 00 00 00 00 00 00 00 ........

Event Type: Information
Event Source: DCOM
Event Category: None
Event ID: 10026
Date: 8/20/2005
Time: 1:15:24 PM
User: N/A
Computer: WEB2
Description:
The COM sub system is suppressing duplicate event log entries for a duration
of 549888 seconds. The suppression timeout can be controlled by a REG_DWORD
value named SuppressDuplicateDuration under the following registry key:
HKLM\Software\Microsoft\Ole\EventLog.

Steve

Dave Patrick said:
When you view the logged events in Event Viewer (double-click them in the
right-hand pane) in the upper right corner, third button down is a copy to
clipboard, then you can paste in the body of a reply message.

Please do so for each of the different System Log events (that are a Type:
'Error' or 'Warning') since last boot so we can see all of the event
detail.

--
Regards,

Dave Patrick ....Please no email replies - reply in newsgroup.
Microsoft Certified Professional
Microsoft MVP [Windows]
http://www.microsoft.com/protect

:
|I would love to know that....but I'm not seeing anything wrong in the
| event log, except for term servers saying that a printer on my local
| machine isn't defined on the remote system.....
|
| How can I find out what the cause is?
 
The 'Print' 3,4, and 8 are informational only and can be ignored. Someone
TS'ing into your box? This article may also help.

http://www.microsoft.com/windows2000/technologies/fileandprint/print/terminalsrvcs.asp

For the IPSec 4294 possibly;
http://support.microsoft.com/default.aspx?scid=kb;en-us;M555281


--
Regards,

Dave Patrick ....Please no email replies - reply in newsgroup.
Microsoft Certified Professional
Microsoft MVP [Windows]
http://www.microsoft.com/protect

:
| Ok, here goes:
|
| Event Type: Warning
| Event Source: Print
| Event Category: None
| Event ID: 3
| Date: 8/20/2005
| Time: 1:14:12 PM
| User: NT AUTHORITY\SYSTEM
| Computer: WEB2
| Description:
| Printer Canon i550 on web2 (from DB1) in session 2 was deleted.
|
| Event Type: Warning
| Event Source: Print
| Event Category: None
| Event ID: 4
| Date: 8/20/2005
| Time: 1:14:12 PM
| User: NT AUTHORITY\SYSTEM
| Computer: WEB2
| Description:
| Printer Canon i550 on web2 (from DB1) in session 2 is pending deletion.
|
| Event Type: Warning
| Event Source: Print
| Event Category: None
| Event ID: 8
| Date: 8/20/2005
| Time: 1:14:12 PM
| User: NT AUTHORITY\SYSTEM
| Computer: WEB2
| Description:
| Printer Canon i550 on web2 (from DB1) in session 2 was purged.
|
| Event Type: Warning
| Event Source: Print
| Event Category: None
| Event ID: 3
| Date: 8/20/2005
| Time: 1:14:12 PM
| User: NT AUTHORITY\SYSTEM
| Computer: WEB2
| Description:
| Printer Auto Canon i550 on web2 (from DB1) in session 2 was deleted.
|
| Event Type: Warning
| Event Source: Print
| Event Category: None
| Event ID: 4
| Date: 8/20/2005
| Time: 1:14:12 PM
| User: NT AUTHORITY\SYSTEM
| Computer: WEB2
| Description:
| Printer Auto Canon i550 on web2 (from DB1) in session 2 is pending
deletion.
|
| Event Type: Warning
| Event Source: Print
| Event Category: None
| Event ID: 8
| Date: 8/20/2005
| Time: 1:14:12 PM
| User: NT AUTHORITY\SYSTEM
| Computer: WEB2
| Description:
| Printer Auto Canon i550 on web2 (from DB1) in session 2 was purged.
|
| And then some entires I haven't seen before:
|
| Event Type: Information
| Event Source: IPSec
| Event Category: None
| Event ID: 4294
| Date: 8/20/2005
| Time: 1:15:34 PM
| User: N/A
| Computer: WEB2
| Description:
| The IPSec driver has entered Secure mode. IPSec policies, if they have
been
| configured, are now being applied to this computer.
|
| Data:
| 0000: 00 00 00 00 01 00 54 00 ......T.
| 0008: 00 00 00 00 c6 10 00 40 ....Æ..@
| 0010: 01 00 00 00 00 00 00 00 ........
| 0018: 00 00 00 00 00 00 00 00 ........
| 0020: 00 00 00 00 00 00 00 00 ........
|
| Event Type: Information
| Event Source: DCOM
| Event Category: None
| Event ID: 10026
| Date: 8/20/2005
| Time: 1:15:24 PM
| User: N/A
| Computer: WEB2
| Description:
| The COM sub system is suppressing duplicate event log entries for a
duration
| of 549888 seconds. The suppression timeout can be controlled by a
REG_DWORD
| value named SuppressDuplicateDuration under the following registry key:
| HKLM\Software\Microsoft\Ole\EventLog.
|
| Steve
 
Back
Top