KS-Soft. Network Management Solutions
 FAQFAQ   SearchSearch   MemberlistMemberlist   UsergroupsUsergroups   RegisterRegister    ProfileProfile    Log inLog in 

Event viewer test works in Win2k, not NT 4.0

 
This forum is locked: you cannot post, reply to, or edit topics.   This topic is locked: you cannot edit posts or make replies.    KS-Soft Forum Index -> HostMonitor
View previous topic :: View next topic  
Author Message
Guido39



Joined: 17 Sep 2002
Posts: 65

PostPosted: Wed Sep 18, 2002 3:37 pm    Post subject: Reply with quote

I have a test setup to monitor event logs on a Win2k server and NT 4.0 server. They are both monitoring RAS connections and disconnections using RemoteAccess as the source and specific event ID's. Problem is when an event is logged or e-mailed, the Win2K server works great in that the event description is correct. But when checking NT 4.0, the test is tripped but the descriptions are either blank or completely wrong. I look in the event logs on the server and it's not what I'm seeing in the Host Monitor logs or e-mails (using the reply field).

Any ideas?
Back to top
View user's profile Send private message
KS-Soft



Joined: 03 Apr 2002
Posts: 12807
Location: USA

PostPosted: Thu Sep 19, 2002 11:25 pm    Post subject: Reply with quote

I don't have good idea. HostMonitor takes event descriptions from DLL that specified (in the registry) for the event source. In your case the DLL specified in registry key HKEY_LOCAL_MACHINESYSTEMCurrentControlSetServicesEventLogSystemRemoteAccessEventMessageFile
Theoretically problem can appear if Windows 2000 and Windows NT 4.0 use different IDs for the same messages... but I don't see much sense in that, I think IDs the same...

Regards
Alex
Back to top
View user's profile Send private message Visit poster's website
Guido39



Joined: 17 Sep 2002
Posts: 65

PostPosted: Fri Sep 20, 2002 9:29 am    Post subject: Reply with quote

Actually, the event IDs are different between the two. For connecting to RAS, the event ID in NT is 20017 and for Win2k is 20141. For disconnecting from RAS, the event ID in NT is 20050 and for Win2k it's 20048.

You said this could cause problems. Does Hostmonitor use the actual DLL on the system? Seems strange that the event descriptions are correct in the event viewer but Host Monitor is picking up something different if they are both referencing the same DLL.
Back to top
View user's profile Send private message
KS-Soft



Joined: 03 Apr 2002
Posts: 12807
Location: USA

PostPosted: Fri Sep 20, 2002 4:23 pm    Post subject: Reply with quote

No, they are referencing to different DLLs: one DLL located on your W2K system, another located on your NT 4.0 system.
Problem is: HostMonitor (and any other program) cannot (in general case) load DLL from remote system. I tried to find information how to retrieve event description from remote system but even Microsoft says "The message strings are contained in a message file specified in the source entry in the registry. To obtain the appropriate message string from the message file, load the message file with the LoadLibrary function and use the FormatMessage function." (http://msdn.microsoft.com/library/default.asp?url=/library/en-us/debug/base/eventlogrecord_str.asp). HostMonitor works exactly by instruction.
What's interesting standard Event Viewer retrieves information from remote system. I think it uses some undocumented functions (as usually ), unfortunately I cant find information about it

Regards
Alex
Back to top
View user's profile Send private message Visit poster's website
Display posts from previous:   
This forum is locked: you cannot post, reply to, or edit topics.   This topic is locked: you cannot edit posts or make replies.    KS-Soft Forum Index -> HostMonitor All times are GMT - 6 Hours
Page 1 of 1

 
Jump to:  
You cannot post new topics in this forum
You cannot reply to topics in this forum
You cannot edit your posts in this forum
You cannot delete your posts in this forum
You cannot vote in polls in this forum


Powered by phpBB © 2001, 2005 phpBB Group

KS-Soft Forum Index