<?xml version="1.0" encoding="UTF-8" ?>
<?xml-stylesheet type="text/xsl" href="http://blogs.msdn.com/utility/FeedStylesheets/rss.xsl" media="screen"?><rss version="2.0" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:slash="http://purl.org/rss/1.0/modules/slash/" xmlns:wfw="http://wellformedweb.org/CommentAPI/"><channel><title>Operations Center of Excellence Blog</title><link>http://blogs.msdn.com/mackals/default.aspx</link><description>I'm changing the focus of the blog somewhat. I recently accepted a new job at Microsoft. I'm now an Architect in the Operations Center of Excellence out of Redmond. This is the same team that created the Desired Configuration Monitor SKU (DCM) and the Service Level Management SKU (SLM). I'm currently working on a new SKU call Proactive Monitoring with MOM (PMM). 

While this blog will still focus on MOM, I'll be writing articles in support of our SKU efforts around the product. I hope to still put out valuable content on both MOM 2005 and System Center Operations Manager 2007 as I get it up and start playing with it. I will still post some content for SMS, but not nearly as much attention to it as MOM.
</description><dc:language>en-US</dc:language><generator>CommunityServer 2.1 SP1 (Build: 61025.2)</generator><item><title>New SKU PMM - Proactive Monitoring with MOM</title><link>http://blogs.msdn.com/mackals/archive/2006/06/30/652627.aspx</link><pubDate>Fri, 30 Jun 2006 22:08:00 GMT</pubDate><guid isPermaLink="false">91d46819-8472-40ad-a661-2c78acb4018c:652627</guid><dc:creator>mackals</dc:creator><slash:comments>0</slash:comments><comments>http://blogs.msdn.com/mackals/comments/652627.aspx</comments><wfw:commentRss>http://blogs.msdn.com/mackals/commentrss.aspx?PostID=652627</wfw:commentRss><description>&lt;P&gt;&lt;STRONG&gt;&lt;FONT face=Arial size=5&gt;PMM History&lt;/FONT&gt;&lt;/STRONG&gt;&lt;/P&gt;
&lt;P&gt;&lt;FONT face=Arial&gt;PMM is the third offering from the Operations Center of Excellence. The first two were SLM - Service Level Management and DCM - Desired Configuration Monitor. PMM is in essence a MOM Tuning SKU, but&amp;nbsp; the focus (just like the other two offerings) is to make ITIL/MOF real for our customers. &lt;/FONT&gt;&lt;/P&gt;
&lt;P&gt;&lt;FONT face=Arial&gt;The recurrent theme within each of the Operations SKUs is the idea of both a Process stream and a Technology stream. PMM continues that tradition. The Process stream places focus on Incident and Problem Management as well as sustained engineering (more detailed articles on this later). The Technology stream focuses on insuring that the Management Packs were configured correctly after installation, gathering data about "noisy" alerts from the OnePoint database through custom reports, and reviewing tuning steps with the customer.&lt;/FONT&gt;&lt;/P&gt;
&lt;P&gt;&lt;FONT face=Arial&gt;The actual tuning process occurs when each stream has completed their tasks. At this point the customer has either integrated MOM into their existing Incident/Problem Management processes (or we have helped the establish those) and we have the data we need to start the tuning process from the technology stream.&lt;/FONT&gt;&lt;/P&gt;
&lt;P&gt;&lt;STRONG&gt;&lt;FONT face=Arial&gt;The Technology Stream&lt;/FONT&gt;&lt;/STRONG&gt;&lt;/P&gt;
&lt;P&gt;&lt;FONT face=Arial&gt;The Technology and Process streams start simultaneously. This article will focus on the Technology stream. I'll have another post next week that specifically deals with the process stream.&lt;/FONT&gt;&lt;/P&gt;
&lt;P&gt;&lt;FONT face=Arial&gt;The idea with the Technology stream was to develop a way to gather data about "noisy" alerts with minimal impact to a customer's environment. I needed a way to do this that was both reliable, and reproduceable.The most reliable way to get this information seems to be gathering it from the customer's OnePoint database. I considered using only data from the MOM Data warehouse, but I have run into a fairly large number of customers who didn't implement it. In order to make the engagement reproduceable, it seemed to me that best way was to pull the data from the production database. &lt;/FONT&gt;&lt;/P&gt;
&lt;P&gt;&lt;FONT face=Arial&gt;Now the question became, "What tool do I use to gather the data?". Again it came down to the least impact to the customer. From my days as a consultant I know how difficult it is to ask a customer to install something like SQL Reporting Services if they have standardized across the Enterprise on another reporting or data access solution. Yet, I need an easy way to retrieve and display the data so that they can help us determine which alerts to tune.&lt;/FONT&gt;&lt;/P&gt;
&lt;P&gt;&lt;FONT face=Arial&gt;The solution I chose was to create a Virtual Server image that has SQL Reporting Services loaded and access reports from there. This also gave me the added benefit of being able to incorporate Sharepoint web services from which I created the MOM Rules Record of Change (again with minimal customer impact).&lt;/FONT&gt;&lt;/P&gt;
&lt;P&gt;&lt;FONT face=Arial&gt;Since I now had a platform to work from, we began building Reports that would pull the data we needed from the OnePoint Database. We are still in the process of building those, but I expect to have them completed within the next few weeks. (More updates later).&lt;/FONT&gt;&lt;/P&gt;
&lt;P&gt;&lt;FONT face=Arial&gt;Experience has shown us that many of the alerts customers see in the field&amp;nbsp;are due to misconfiguration of the Exchange Management Pack. Even using the Wizard, some customers configure synthetic transactions between every Exchange Store in their environment. Not only does this incur high traffic costs, it also radically increases the probability of chatter alerts. So the first thing we do during the engagement is ask the customer ro rerun the EXMP Wizard so we can see the original settings used. We also ask them to export the XML file at the end and provide change management for it as new servers are brought on board.&lt;/FONT&gt;&lt;/P&gt;
&lt;P&gt;&lt;FONT face=Arial&gt;Once we are confident that the EXMP is configured correctly, we configure the Virtual Server image and custom reports to point at the customer's OnePoint database. In a large environment, this could be multiple databases or even simply a top tier database depending upon how they are configured. We then begin to gather the data that will be used during the tuning process. &lt;/FONT&gt;&lt;/P&gt;
&lt;P&gt;&lt;FONT face=Arial&gt;I spent last week in Redmond with our Exchange MOM servers running these reports and starting the tuning process there. As with the other SKUs we have created, we want to make sure the processes we take to the field are the same we use internally. By RTM in September, we will be fully utilizing this SKU within MSIT.&lt;/FONT&gt;&lt;/P&gt;
&lt;P&gt;&lt;FONT face=Arial&gt;&lt;STRONG&gt;(7-Jul-2006)&lt;/STRONG&gt;&lt;/FONT&gt;&lt;/P&gt;
&lt;P&gt;&lt;FONT face=Arial&gt;&lt;STRONG&gt;More on Reports &lt;/STRONG&gt;&lt;/FONT&gt;&lt;/P&gt;
&lt;P&gt;&lt;FONT face=Arial&gt;With the 4th of July, this week was a short week. My focus this week was on getting the reports up to speed. I am very pleased with the progress. Currently I have&amp;nbsp;5 linked reports that run queries against the OnePoint database and return results. This blog site doesn't lend itself well to posting graphics, so I won't be able to provide screen shots, but I can describe a little about what the reports provide.&lt;/FONT&gt;&lt;/P&gt;
&lt;P&gt;&lt;FONT face=Arial&gt;I tried to be as descriptive as possible with the report names. They are:&lt;/FONT&gt;&lt;/P&gt;
&lt;UL&gt;
&lt;LI&gt;&lt;FONT face=Arial&gt;Alerts by Computer Group with Alert Counts&lt;/FONT&gt;&lt;/LI&gt;
&lt;LI&gt;&lt;FONT face=Arial&gt;Alerts by Computers in Computer Groups with Alert Counts&lt;/FONT&gt;&lt;/LI&gt;
&lt;LI&gt;&lt;FONT face=Arial&gt;Alerts by Computer Group by Computer&lt;/FONT&gt;&lt;/LI&gt;
&lt;LI&gt;&lt;FONT face=Arial&gt;Alerts by Computer Group by Severity&lt;/FONT&gt;&lt;/LI&gt;
&lt;LI&gt;&lt;FONT face=Arial&gt;Alerts by Computer by Severity&lt;/FONT&gt;&lt;/LI&gt;&lt;/UL&gt;
&lt;P&gt;&lt;FONT face=Arial&gt;The linking is as follows:&lt;/FONT&gt;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&lt;FONT face=Arial size=2&gt;Alerts by Computer Group with Alert Counts&lt;/FONT&gt;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&lt;FONT face=Arial size=2&gt;/&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;\&lt;/FONT&gt;&lt;/P&gt;
&lt;P&gt;&lt;FONT face=Arial size=2&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;/&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;Alerts by Computer Group by Severity&lt;/FONT&gt;&lt;/P&gt;
&lt;P&gt;&lt;FONT face=Arial size=2&gt;Alerts by Computers in Computer Groups with Alert Counts&lt;/FONT&gt;&lt;/P&gt;
&lt;P&gt;&lt;FONT face=Arial size=2&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;/&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;\&lt;/FONT&gt;&lt;/P&gt;
&lt;P&gt;&lt;FONT face=Arial size=2&gt;Alerts by Computer Group by Computer&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;\&lt;/FONT&gt;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&lt;FONT face=Arial size=2&gt;Alerts by Computer by Severity&lt;/FONT&gt;&lt;/P&gt;
&lt;P&gt;&lt;FONT face=Arial&gt;The introductory report (Alerts by Computer Group with Alert Counts)&amp;nbsp;lists the default Exchange Management Pack Computer Groups (Exchange 2000 Server, Exchange 2003 Server) as well as custom computer groups defined by the customer. (These have to be hand coded into the report prior to the engagement.) Beside each of the Computer Groups are columns labeled # Warning, # Error, # Critical Error, and # Service Unavailable. In each of the columns, I list the number of each severity of alert per computer group.&amp;nbsp; All columns in this report are hyperlinked. If you select one of the Computer Group Names, you will jump to a report (Alert by Computers in Computer Groups with Alert Counts) &amp;nbsp;listing all the computers in the computer group with a list of Alerts of differing severity for each (Described next). If you select any of the values listed under the alert severity columns, you are linked to a report ( Alerts by Computer Group by Severity) that shows you all computers within the computer group that have logged the selected&amp;nbsp;severity of alert.&lt;/FONT&gt;&lt;/P&gt;&lt;img src="http://blogs.msdn.com/aggbug.aspx?PostID=652627" width="1" height="1"&gt;</description></item><item><title>Blog focus change</title><link>http://blogs.msdn.com/mackals/archive/2006/06/30/652580.aspx</link><pubDate>Fri, 30 Jun 2006 21:39:00 GMT</pubDate><guid isPermaLink="false">91d46819-8472-40ad-a661-2c78acb4018c:652580</guid><dc:creator>mackals</dc:creator><slash:comments>0</slash:comments><comments>http://blogs.msdn.com/mackals/comments/652580.aspx</comments><wfw:commentRss>http://blogs.msdn.com/mackals/commentrss.aspx?PostID=652580</wfw:commentRss><description>&lt;P&gt;I'm changing the focus of the blog somewhat. I recently accepted a new job at Microsoft. I'm now an Architect in the Operations Center of Excellence out of Redmond. This is the same team that created the Desired Configuration Monitor SKU (DCM)&amp;nbsp;and the Service Level Management SKU (SLM). I'm currently working on a new SKU call Proactive Monitoring with MOM (PMM). &lt;/P&gt;
&lt;P&gt;While this blog will still focus on MOM, I'll be writing articles in support of our SKU efforts around the product. I hope to still put out valuable content on both MOM 2005 and System Center Operations Manager 2007 as I get it up and start playing with it. I will still post some content for SMS, but not nearly as much attention to it as MOM.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;mac&lt;/P&gt;&lt;img src="http://blogs.msdn.com/aggbug.aspx?PostID=652580" width="1" height="1"&gt;</description></item><item><title>Notification Workflow Solution Accelerator</title><link>http://blogs.msdn.com/mackals/archive/2005/11/02/488352.aspx</link><pubDate>Wed, 02 Nov 2005 22:05:00 GMT</pubDate><guid isPermaLink="false">91d46819-8472-40ad-a661-2c78acb4018c:488352</guid><dc:creator>mackals</dc:creator><slash:comments>3</slash:comments><comments>http://blogs.msdn.com/mackals/comments/488352.aspx</comments><wfw:commentRss>http://blogs.msdn.com/mackals/commentrss.aspx?PostID=488352</wfw:commentRss><description>&lt;P&gt;When I was typing the title of this article, my fat fingers made a Freudian slip that is pretty appropriate for this solution accelerator. The original title was "Notification &lt;STRONG&gt;&lt;EM&gt;&lt;U&gt;WorkSlow&lt;/U&gt;&lt;/EM&gt; &lt;/STRONG&gt;Solution Accelerator". Once you finally get the thing installed, it is extremely frustrating trying to set up things like separate day/evening notification schedules for operators. More on this later; for now let me start with setup:&lt;/P&gt;
&lt;P&gt;&lt;STRONG&gt;&lt;FONT size=4&gt;Setting Up the SA&lt;/FONT&gt;&lt;/STRONG&gt;&lt;/P&gt;
&lt;P&gt;The setup documentation for this particular SA is poor at best. There are a number of assumptions made by the authors that just don't match up with the average consultant installing the product. Here are all the components I had to add outside of the instructions to make it work:&lt;/P&gt;
&lt;UL&gt;
&lt;LI&gt;First the SA requires that you have IIS running on the database server where the SA will be installed. (How many Enterprise customers do most of you have that will allow IIS to run on their database servers?) 
&lt;LI&gt;Second, you need to install SQL Notification Services. (I know... I suppose I should have known that, but hey I don't play in the SQL world often) 
&lt;LI&gt;Third, you need to install SQLXML. (This is necessary because you *MUST* install the Engine components when installing the SQL Notification Services. If you select the Engine components and don't have SQLXML installed, you get a pop up telling you to install it and try again.)&lt;/LI&gt;&lt;/UL&gt;
&lt;P&gt;The SA documentation doesn't point out that you need any of these installed. If you don'y install them however (and you run the SA installation) there is absolutely nothing in the log files that would lead you to determine why the SA doesn't install...&lt;/P&gt;
&lt;P&gt;&lt;STRONG&gt;&lt;FONT size=4&gt;Using the SA&lt;/FONT&gt;&lt;/STRONG&gt;&lt;/P&gt;
&lt;P&gt;Once you finally get it installed, you use a web interface to set up users and subscriptions. The url is &lt;A href="http://&lt;servername&gt;/NotificationWorkFlow.Web/HomePage.aspx"&gt;http://&amp;lt;servername&amp;gt;/NotificationWorkFlow.Web/HomePage.aspx&lt;/A&gt;&lt;/P&gt;
&lt;P&gt;Two things you will notice immediately. &lt;/P&gt;
&lt;UL&gt;
&lt;LI&gt;When you add users, they actually go into a local table on the SQL server. There is no AD integration meaning that you will need to enter each subscriber's information manually with no ability to use AD Groups (or groups of any kind for that matter). For a very small shop (5 to 10 Operators) this might be acceptable. For an Enterprise Solution it is extremely poor. 
&lt;LI&gt;Most Enterprise Orgs that I have dealt with usually have email notification during working hours and cell/pager notifications after hours. The SA can accomplish this, but you must create a daytime subscriber ID and and evening subscriber ID for everyone that will need both types of notifications.&lt;/LI&gt;&lt;/UL&gt;
&lt;P&gt;Once you have added the users, there is no way to cut and paste schedules between users. Since most people on a single shift will have the same hours, this could be a huge time saver but it is not possible with the SA. &lt;/P&gt;
&lt;P&gt;The Subscriber devices tab is interesting. It does allow you to specify multiple devicesand you can specify which device (email, pager, etc) can be used for each subscription, but without the ability to set up devices per schedule, you are limited to adding multiple subscribers per user.&lt;/P&gt;
&lt;P&gt;The one thing that is nice about the SA is that it gives you the ability to be paged for alerts on a particular Management Pack, Computer Group, or Individual Computer as well as giving you the choice of notifications by severity threshold.&lt;/P&gt;
&lt;P&gt;&lt;STRONG&gt;&lt;FONT size=4&gt;Overall Score&lt;/FONT&gt;&lt;/STRONG&gt;&lt;/P&gt;
&lt;P&gt;If I rate this Solution Accelerator on a scale of 1 to 5, I would give it a 1.5 for overall functionality. It falls very short in the Enterprise space. i can't imagine that a single Enterprise customer would actually use the SA in production. It could possibly work for a very small organization.&lt;/P&gt;
&lt;P&gt;My suggestion: Unless your customer is up for a dev engagement to make the tool useable, steer them away from this SA...&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;-mac&lt;/P&gt;&lt;img src="http://blogs.msdn.com/aggbug.aspx?PostID=488352" width="1" height="1"&gt;</description></item><item><title>What does "Commit Changes" when rules are changed actually do?</title><link>http://blogs.msdn.com/mackals/archive/2005/01/26/360854.aspx</link><pubDate>Wed, 26 Jan 2005 18:32:00 GMT</pubDate><guid isPermaLink="false">91d46819-8472-40ad-a661-2c78acb4018c:360854</guid><dc:creator>mackals</dc:creator><slash:comments>0</slash:comments><comments>http://blogs.msdn.com/mackals/comments/360854.aspx</comments><wfw:commentRss>http://blogs.msdn.com/mackals/commentrss.aspx?PostID=360854</wfw:commentRss><description>&lt;font size="2"&gt; &lt;p&gt;If you commit changes after a rule change, the management server pushes the new rules at the next heartbeat interval. (By default this is set at every 10 seconds). If you don't commit changes, then the new rule is pushed on the next client configuration request which is by default set at 1 min intervals.&lt;/p&gt; &lt;p&gt;The only place I could foresee this being an issue at all is where you have servers across a slow link so you set the configuration request interval up to reduce traffic…&lt;/p&gt;&lt;/font&gt;&lt;img src="http://blogs.msdn.com/aggbug.aspx?PostID=360854" width="1" height="1"&gt;</description></item><item><title>MOM Event Stream Info</title><link>http://blogs.msdn.com/mackals/archive/2005/01/20/357430.aspx</link><pubDate>Thu, 20 Jan 2005 21:26:00 GMT</pubDate><guid isPermaLink="false">91d46819-8472-40ad-a661-2c78acb4018c:357430</guid><dc:creator>mackals</dc:creator><slash:comments>0</slash:comments><comments>http://blogs.msdn.com/mackals/comments/357430.aspx</comments><wfw:commentRss>http://blogs.msdn.com/mackals/commentrss.aspx?PostID=357430</wfw:commentRss><description>&lt;p&gt;One thing that was unclear to me was the significance or use of the MOM event stream. Somehow I just didn't make the connection between the event stream, alerts, and rules. Our documentation didn't seem to make this clear to me, and it wasn't immediately intuitive to me. Now that I have made the correlation however, I look at the event stream in&amp;nbsp;two distinct ways:&lt;/p&gt; &lt;ul&gt; &lt;li&gt;Informational Data &lt;li&gt;Troubleshooting Data &lt;/li&gt;&lt;/ul&gt; &lt;p&gt;&lt;strong&gt;&lt;em&gt;&lt;font size="4"&gt;Informational Data&lt;/font&gt;&lt;/em&gt;&lt;/strong&gt;&lt;/p&gt; &lt;p&gt;For instance, many of the MOM 2005 tasks that you launch from the MOM Operator's console do not display results directly to the operator console directly. For instance, if you run an IP CONFIGURATION&amp;nbsp;task from the task pane against a specific computer, the resultant data is not immediately echoed back to the Operator console. Instead, the&amp;nbsp;action and results are displayed in the MOM event stream. The first thing you see in the event stream&amp;nbsp;for an IP CONFIGURATION&amp;nbsp;task is an information event with the following data:&lt;/p&gt; &lt;div&gt;&lt;em&gt;&lt;font size="2"&gt;The task 'IP Configuration' is scheduled to run against 'Computer:DOMAIN\COMPUTER. &lt;br /&gt;Task Id: {6D260750-134E-48FF-806F-4C08CE2A815C} &lt;br /&gt;Execution Id: {38548CAF-B78B-415F-B64C-62D46B6807E2} &lt;br /&gt;Launched By: DOMAIN\ae_squ2&lt;/font&gt;&lt;/em&gt;&lt;/div&gt; &lt;p&gt;&amp;nbsp;This is followed shortly by an information event with the results of the request as follows:&lt;/p&gt; &lt;div&gt;&lt;font size="2"&gt;&lt;em&gt;The task 'IP Configuration' has successfully executed against 'Computer:DOMAIN\COMPUTER. &lt;br /&gt;Task Id: {6D260750-134E-48FF-806F-4C08CE2A815C} &lt;br /&gt;Execution Id: {38548CAF-B78B-415F-B64C-62D46B6807E2} &lt;br /&gt;Launched By: DOMAIN\ae_squ2 &lt;br /&gt;&lt;br /&gt;The following output has been generated: &lt;br /&gt;&lt;br /&gt;Windows IP Configuration&lt;br /&gt;Host Name . . . . . . . . . . . . : COMPUTER&lt;br /&gt;Primary Dns Suffix . . . . . . . : EXAMPLE.DNSNAME.COM&lt;br /&gt;Node Type . . . . . . . . . . . . : Hybrid&lt;br /&gt;IP Routing Enabled. . . . . . . . : No&lt;br /&gt;WINS Proxy Enabled. . . . . . . . : No&lt;br /&gt;DNS Suffix Search List. . . . . . : example.dnsname.com&lt;br /&gt;home.dnsname.com&lt;br /&gt;dnsname.com&lt;br /&gt;nomad.dnsname.com&lt;br /&gt;&lt;br /&gt;Ethernet adapter adsm:&lt;br /&gt;Connection-specific DNS Suffix . : &lt;br /&gt;Description . . . . . . . . . . . : HP NC6170 Dual Gigabit Server Adapter&lt;br /&gt;Physical Address. . . . . . . . . : 00-02-A5-47-33-F4&lt;br /&gt;DHCP Enabled. . . . . . . . . . . : No&lt;br /&gt;IP Address. . . . . . . . . . . . : 10.128.41.106&lt;br /&gt;Subnet Mask . . . . . . . . . . . : 255.255.252.0&lt;br /&gt;Default Gateway . . . . . . . . . : &lt;br /&gt;NetBIOS over Tcpip. . . . . . . . : Disabled&lt;br /&gt;&lt;br /&gt;Ethernet adapter Internal + Public:&lt;br /&gt;Connection-specific DNS Suffix . : ex.dnsname.org&lt;br /&gt;Description . . . . . . . . . . . : HP NC7781 Gigabit Server Adapter&lt;br /&gt;Physical Address. . . . . . . . . : 00-11-85-BA-CD-2D&lt;br /&gt;DHCP Enabled. . . . . . . . . . . : No&lt;br /&gt;IP Address. . . . . . . . . . . . : 10.128.182.30&lt;br /&gt;Subnet Mask . . . . . . . . . . . : 255.255.255.192&lt;br /&gt;Default Gateway . . . . . . . . . : 10.128.182.1&lt;br /&gt;DNS Servers . . . . . . . . . . . : 10.128.175.201&lt;br /&gt;10.128.175.202&lt;br /&gt;10.64.175.201&lt;br /&gt;Primary WINS Server . . . . . . . : 10.128.175.215&lt;br /&gt;Secondary WINS Server . . . . . . : 10.128.175.216&lt;br /&gt;10.128.175.213&lt;br /&gt;&lt;/em&gt;&lt;/font&gt;&lt;/div&gt; &lt;div&gt;&lt;font size="2"&gt;&lt;em&gt;Ethernet adapter Internal:&lt;/em&gt;&lt;/font&gt;&lt;/div&gt; &lt;div&gt;&lt;font size="2"&gt;&lt;em&gt;Connection-specific DNS Suffix . : &lt;br /&gt;Description . . . . . . . . . . . : HP NC7781 Gigabit Server Adapter #2&lt;br /&gt;Physical Address. . . . . . . . . : 00-11-85-BA-DF-2C&lt;br /&gt;DHCP Enabled. . . . . . . . . . . : No&lt;br /&gt;IP Address. . . . . . . . . . . . : 10.128.65.16&lt;br /&gt;Subnet Mask . . . . . . . . . . . : 255.255.255.128&lt;br /&gt;Default Gateway . . . . . . . . . : &lt;br /&gt;NetBIOS over Tcpip. . . . . . . . : Disabled&lt;/em&gt;&lt;/font&gt;&lt;/div&gt; &lt;div&gt;&lt;em&gt;&lt;font size="2"&gt;&lt;/font&gt;&lt;/em&gt;&amp;nbsp;&lt;/div&gt; &lt;div&gt;&lt;strong&gt;&lt;em&gt;&lt;font size="4"&gt;Troubleshooting Data&lt;/font&gt;&lt;/em&gt;&lt;/strong&gt;&lt;/div&gt; &lt;div&gt;&lt;strong&gt;&lt;em&gt;&lt;font size="4"&gt;&lt;/font&gt;&lt;/em&gt;&lt;/strong&gt;&amp;nbsp;&lt;/div&gt; &lt;div&gt;The second thing&amp;nbsp; found important about the MOM event stream is that lots of additional ionformation is available outside of an alert. This is especially true for alerts with repeat counts. So for instance if I see an alert conatining the following information:&lt;/div&gt; &lt;div&gt; &lt;table style="PADDING-RIGHT: 5px; FONT-SIZE: 8.25pt; PADDING-BOTTOM: 2px; FONT-FAMILY: MS Shell Dlg 2" height="100%" cellspacing="0" cols="2" cellpadding="0" width="100%" border="0"&gt; &lt;tbody&gt; &lt;tr valign="top"&gt; &lt;td style="BORDER-RIGHT: buttonface 1px solid; PADDING-LEFT: 3px" width="50%"&gt; &lt;div style="PADDING-BOTTOM: 0.5em; PADDING-TOP: 3px"&gt;&lt;font size="1"&gt;&lt;em&gt;Description:&lt;/em&gt;&lt;/font&gt;&lt;/div&gt; &lt;div&gt;&lt;font size="1"&gt;&lt;em&gt;Error during synthetic Outlook Mobile Access logon.&lt;br /&gt;&lt;br /&gt;To determine the current state of this problem, look at the events associated with this alert and find the most recent event.&lt;br /&gt;&lt;br /&gt;The initial event reported that:&lt;br /&gt;&lt;br /&gt;Cannot measure OMA availability. Unexpected error.&lt;br /&gt;&lt;br /&gt;OmaStatus failed to initialize&lt;br /&gt;&lt;br /&gt;This event was generated by the script: "Exchange 2003 - OMA logon verification"&lt;/em&gt;&lt;/font&gt;&lt;/div&gt;&lt;/td&gt; &lt;td style="PADDING-LEFT: 5px" width="50%"&gt; &lt;table style="FONT-SIZE: 8.25pt; FONT-FAMILY: MS Shell Dlg 2" cellspacing="3" cols="2" cellpadding="0" border="0"&gt; &lt;tbody&gt; &lt;tr valign="top"&gt; &lt;td nowrap=""&gt;&lt;font size="1"&gt;&lt;em&gt;Name:&lt;/em&gt;&lt;/font&gt;&lt;/td&gt; &lt;td&gt;&lt;font size="1"&gt;&lt;em&gt;General error during synthetic Outlook Mobile Access logon.&lt;/em&gt;&lt;/font&gt;&lt;/td&gt;&lt;/tr&gt; &lt;tr valign="top"&gt; &lt;td nowrap=""&gt;&lt;font size="1"&gt;&lt;em&gt;Severity:&lt;/em&gt;&lt;/font&gt;&lt;/td&gt; &lt;td&gt;&lt;font size="1"&gt;&lt;em&gt;Warning&lt;/em&gt;&lt;/font&gt;&lt;/td&gt;&lt;/tr&gt; &lt;tr valign="top"&gt; &lt;td nowrap=""&gt;&lt;font size="1"&gt;&lt;em&gt;Resolution State:&lt;/em&gt;&lt;/font&gt;&lt;/td&gt; &lt;td&gt;&lt;font size="1"&gt;&lt;em&gt;New&lt;/em&gt;&lt;/font&gt;&lt;/td&gt;&lt;/tr&gt; &lt;tr valign="top"&gt; &lt;td nowrap=""&gt;&lt;font size="1"&gt;&lt;em&gt;Domain:&lt;/em&gt;&lt;/font&gt;&lt;/td&gt; &lt;td&gt;&lt;font size="1"&gt;&lt;em&gt;GOMER&lt;/em&gt;&lt;/font&gt;&lt;/td&gt;&lt;/tr&gt; &lt;tr valign="top"&gt; &lt;td nowrap=""&gt;&lt;font size="1"&gt;&lt;em&gt;Computer:&lt;/em&gt;&lt;/font&gt;&lt;/td&gt; &lt;td&gt;&lt;font size="1"&gt;&lt;em&gt;LITTLEPYLE&lt;/em&gt;&lt;/font&gt;&lt;/td&gt;&lt;/tr&gt; &lt;tr valign="top"&gt; &lt;td nowrap=""&gt;&lt;font size="1"&gt;&lt;em&gt;Time of First Event:&lt;/em&gt;&lt;/font&gt;&lt;/td&gt; &lt;td&gt;&lt;font size="1"&gt;&lt;em&gt;1/21/2005 2:49:00 PM&lt;/em&gt;&lt;/font&gt;&lt;/td&gt;&lt;/tr&gt; &lt;tr valign="top"&gt; &lt;td nowrap=""&gt;&lt;font size="1"&gt;&lt;em&gt;Time of Last Event:&lt;/em&gt;&lt;/font&gt;&lt;/td&gt; &lt;td&gt;&lt;font size="1"&gt;&lt;em&gt;1/26/2005 10:34:00 AM&lt;/em&gt;&lt;/font&gt;&lt;/td&gt;&lt;/tr&gt; &lt;tr valign="top"&gt; &lt;td nowrap=""&gt;&lt;font size="1"&gt;&lt;em&gt;Alert latency:&lt;/em&gt;&lt;/font&gt;&lt;/td&gt; &lt;td&gt;&lt;font size="1"&gt;&lt;em&gt;1 sec&lt;/em&gt;&lt;/font&gt;&lt;/td&gt;&lt;/tr&gt; &lt;tr valign="top"&gt; &lt;td nowrap=""&gt;&lt;font size="1"&gt;&lt;em&gt;Problem State:&lt;/em&gt;&lt;/font&gt;&lt;/td&gt; &lt;td&gt;&lt;font size="1"&gt;&lt;em&gt;Active&lt;/em&gt;&lt;/font&gt;&lt;/td&gt;&lt;/tr&gt; &lt;tr valign="top"&gt; &lt;td nowrap=""&gt;&lt;font size="1"&gt;&lt;em&gt;Repeat Count:&lt;/em&gt;&lt;/font&gt;&lt;/td&gt; &lt;td&gt;&lt;font size="1"&gt;&lt;em&gt;463&lt;/em&gt;&lt;/font&gt;&lt;/td&gt;&lt;/tr&gt; &lt;tr valign="top"&gt; &lt;td nowrap=""&gt;&lt;font size="1"&gt;&lt;em&gt;Age:&lt;/em&gt;&lt;/font&gt;&lt;/td&gt; &lt;td&gt;&lt;font size="1"&gt;&lt;em&gt;&lt;/em&gt;&lt;/font&gt;&lt;/td&gt;&lt;/tr&gt; &lt;tr valign="top"&gt; &lt;td nowrap=""&gt;&lt;font size="1"&gt;&lt;em&gt;Source:&lt;/em&gt;&lt;/font&gt;&lt;/td&gt; &lt;td&gt;&lt;font size="1"&gt;&lt;em&gt;Exchange MOM&lt;/em&gt;&lt;/font&gt;&lt;/td&gt;&lt;/tr&gt; &lt;tr valign="top"&gt; &lt;td nowrap=""&gt;&lt;font size="1"&gt;&lt;em&gt;Alert Id:&lt;/em&gt;&lt;/font&gt;&lt;/td&gt; &lt;td&gt;&lt;font size="1"&gt;&lt;em&gt;01bc0bca-e2dd-40af-90c2-69171008b7b3&lt;/em&gt;&lt;/font&gt;&lt;/td&gt;&lt;/tr&gt; &lt;tr valign="top"&gt; &lt;td nowrap=""&gt;&lt;font size="1"&gt;&lt;em&gt;Rule (enabled):&lt;/em&gt;&lt;/font&gt;&lt;/td&gt; &lt;td&gt;&lt;font size="1"&gt;&lt;em&gt;Microsoft Exchange Server\Exchange 2003\Availability and State Monitoring\Verify Outlook Mobile Access Front-End Availability\General error during synthetic Outlook Mobile Access logon.&lt;/em&gt;&lt;/font&gt;&lt;/td&gt;&lt;/tr&gt;&lt;/tbody&gt;&lt;/table&gt;&lt;/td&gt;&lt;/tr&gt;&lt;/tbody&gt;&lt;/table&gt;&lt;/div&gt; &lt;div&gt;&amp;nbsp;&lt;/div&gt; &lt;div&gt;I would customize the event stream under My Views so that I could see all events associated with this computer. Further investigation would eventually reveal that when the Exchange Management Pack Wizard was run in this environment, a selection was made *NOT* to monitor front end servers, but this rule and others were never disabled. It was easy to see that multiple events were being raised that lead back to these rules.&lt;/div&gt; &lt;div&gt;&amp;nbsp;&lt;/div&gt;&lt;img src="http://blogs.msdn.com/aggbug.aspx?PostID=357430" width="1" height="1"&gt;</description><category domain="http://blogs.msdn.com/mackals/archive/tags/Microsoft+Operations+Manager/default.aspx">Microsoft Operations Manager</category></item><item><title>Access Denied Errors during Computer Scan</title><link>http://blogs.msdn.com/mackals/archive/2005/01/20/357307.aspx</link><pubDate>Thu, 20 Jan 2005 18:42:00 GMT</pubDate><guid isPermaLink="false">91d46819-8472-40ad-a661-2c78acb4018c:357307</guid><dc:creator>mackals</dc:creator><slash:comments>0</slash:comments><comments>http://blogs.msdn.com/mackals/comments/357307.aspx</comments><wfw:commentRss>http://blogs.msdn.com/mackals/commentrss.aspx?PostID=357307</wfw:commentRss><description>I ran into a problem today where when I set up discovery rules and forced a computer scan, I received a slew of Access Denied errors from computers that are part of the discovery rule. After much troubleshooting as to why the problem was occuring, I found that the Action Account had become locked out due to too many password retries. (Still don't know the reason why there we so many retries). This is a highly secured environment and the action account is low privileged anyway, but this account lockout resulted in the inability to discover computers. Once we unlocked the action account everything worked fine. &lt;img src="http://blogs.msdn.com/aggbug.aspx?PostID=357307" width="1" height="1"&gt;</description></item><item><title>Management Pack versions on MOM 2005?</title><link>http://blogs.msdn.com/mackals/archive/2004/10/20/245420.aspx</link><pubDate>Thu, 21 Oct 2004 03:24:00 GMT</pubDate><guid isPermaLink="false">91d46819-8472-40ad-a661-2c78acb4018c:245420</guid><dc:creator>mackals</dc:creator><slash:comments>3</slash:comments><comments>http://blogs.msdn.com/mackals/comments/245420.aspx</comments><wfw:commentRss>http://blogs.msdn.com/mackals/commentrss.aspx?PostID=245420</wfw:commentRss><description>&lt;P&gt;I ran into an interesting question from one of my consultants today. He asked me how to determine the version number of the Management Pack that was currently running on a MOM 2000 SP1 server. To be honest, I don't think there is a way to do this. I normally suggest that customers export the current management packs into a BASE directory. Then as new management packs are available and imported, you should create a subdirectory under BASE that in the form of {ManagementPackName}{Date} and store the new management packs in that directory.&lt;/P&gt;
&lt;P&gt;&lt;STRONG&gt;Exported Management Packs&lt;/STRONG&gt;&lt;/P&gt;
&lt;P&gt;I noticed today as I installed MOM 2005 for a customer that after you import the first management pack, a directory gets created in the Operations Manager Program Directory named MPBackup (C:\Program Files\Microsoft Operations Manager 2005\MPBackup). Guess what gets added into that directory when you do a management pack import? That's right! the management pack name followed by date and time. One I imported today shows up like this:&lt;/P&gt;
&lt;P&gt;MicrosoftExchangeServer2003_10.20.04 13.57.49.akm&lt;/P&gt;
&lt;P&gt;&lt;STRONG&gt;So how do I find the version I'm running today?&lt;/STRONG&gt;&lt;/P&gt;
&lt;P&gt;To find out what released version you have in production, go to the administrator's console. Right click the management pack you are interested in and select properties. The management pack version is a field on the Properties page.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;img src="http://blogs.msdn.com/aggbug.aspx?PostID=245420" width="1" height="1"&gt;</description><category domain="http://blogs.msdn.com/mackals/archive/tags/Microsoft+Operations+Manager/default.aspx">Microsoft Operations Manager</category></item><item><title>MOM 2005 Management UI and Computer Groups</title><link>http://blogs.msdn.com/mackals/archive/2004/10/18/244217.aspx</link><pubDate>Tue, 19 Oct 2004 01:47:00 GMT</pubDate><guid isPermaLink="false">91d46819-8472-40ad-a661-2c78acb4018c:244217</guid><dc:creator>mackals</dc:creator><slash:comments>0</slash:comments><comments>http://blogs.msdn.com/mackals/comments/244217.aspx</comments><wfw:commentRss>http://blogs.msdn.com/mackals/commentrss.aspx?PostID=244217</wfw:commentRss><description>So Computer Groups have changed between MOM 2000 and MOM 2005. In MOM 2000, the server itself was responsible for server discovery and Computer Groups in the UI showed which computers had been discovered and were populated in the Computer Group. In MOM 2005, the discovered servers do not show up in the management UI. This causes some consternation for most MOM admins until they realize that the Computer Group members are displayed in the Operator's Console not the Admin Console. (I think we did this because we partitioned the MOM 2005 tables...)&lt;img src="http://blogs.msdn.com/aggbug.aspx?PostID=244217" width="1" height="1"&gt;</description><category domain="http://blogs.msdn.com/mackals/archive/tags/Microsoft+Operations+Manager/default.aspx">Microsoft Operations Manager</category></item></channel></rss>