Event ID's 4254, 4255, and 4256 - Digest

Article:TECH213756  |  Created: 2014-01-07  |  Updated: 2014-09-15  |  Article URL http://www.symantec.com/docs/TECH213756
Article Type
Technical Solution


Subject

Issue



Event ID's 4254, 4255, and 4256 are all part of the Event Filtering feature released in version 10.0.3. 

Event filtering will periodically provide a summary report on events that have been suppressed (every 15 minutes by default). The event ID and severity of the summary event depends upon the severity of the event suppressed. The text for all three events, 4254, 4255, and 4256 are identical and logged to both the Enterprise Vault and Application event logs
 


Error



V-437-4254
V-437-4255
V-437-4256

An example of Event 4255 is in the screenshot below.


Cause



  • If errors are suppressed, error 4254 is logged
  • If warnings are suppressed, warning 4255 is logged
  • If informational logs are suppressed, informational 4256 is logged

Solution



To identify the underlying issue, refer to the actual Event ID that is in the body of one of the three events listed above.  In the example above, the actual Event ID to review is 8229.

Open the Enterprise Vault logs and filter on 8229 to begin troubleshooting.

For additional information and registry keys related to Event Filtering, refer to DOC6303 below under Related Articles.


Supplemental Materials

SourceEvent ID
Value4254
Description

Enterprise Vault has condensed the Event Logs by suppressing repeating event from 1 process(es)


SourceEvent ID
Value4255
Description

Enterprise Vault has condensed the Event Logs by suppressing repeating event from 1 process(es)


SourceEvent ID
Value4256
Description

Enterprise Vault has condensed the Event Logs by suppressing repeating event from 1 process(es)





Article URL http://www.symantec.com/docs/TECH213756


Terms of use for this information are found in Legal Notices