Share via

Wrong Alerts for Operations Manager Failed to Access the Windows Event Log

Sai Kumar M 46 Reputation points
2020-10-27T12:32:33.38+00:00

Hello Folks,

I'm getting the alert" Operations Manager Failed to Access the Windows Event Log" frequently. However the Event Source which is referring as Unable is actually not present in the event log. Could you please help.

Regards
SK

System Center Operations Manager
System Center Operations Manager

A family of System Center products that provide infrastructure monitoring, help ensure the predictable performance and availability of vital applications, and offer comprehensive monitoring for datacenters and cloud, both private and public.

0 comments No comments

4 answers

Sort by: Most helpful
  1. CyrAz 5,181 Reputation points
    2020-11-09T11:32:13.263+00:00

    Did you try any of what I explained in my first answer?

    Was this answer helpful?

    0 comments No comments

  2. Sai Kumar M 46 Reputation points
    2020-11-09T11:14:27.493+00:00

    Someone pls help on how to overcome the situation.

    Was this answer helpful?

    0 comments No comments

  3. CyrAz 5,181 Reputation points
    2020-10-27T16:54:21.613+00:00

    Looks like someone created an event rule or monitor on a custom event log and targeted it a Windows Computers, so it runs everywhere even though that custom event log only exists on specific servers.

    So now you need to find that monitor or rule, and then you have two options :

    • Easy but not optimum : Configure the monitor/rule as "disabled" by default, create a group of servers running the "custom app" where the event log exists and override the monitor/rule to enable it only for that group
    • Best option : create a class and an associated discovery for that "custom app" and then target the monitor/rule at that class instead of "Windows Computer"

    Was this answer helpful?


  4. Leon Laude 86,116 Reputation points
    2020-10-27T12:45:27.603+00:00

    Hi @Sai Kumar M ,

    If SCOM is unable to access the event log because the event log/source doesn't exist, then it's a valid alert.
    Can you please post the full alert description?

    Does this happen on one or many servers?

    ----------

    (If the reply was helpful please don't forget to upvote or accept as answer, thank you)

    Best regards,
    Leon

    Was this answer helpful?


Your answer

Answers can be marked as 'Accepted' by the question author and 'Recommended' by moderators, which helps users know the answer solved the author's problem.