Windows SharePoint Services writes to a specific instance of the Windows trace log. This log file is reused by many applications that are built on top of Windows SharePoint Services.
Windows SharePoint Services writes to a specific instance of the Windows trace log. This log file is reused by many applications that are built on top of Windows SharePoint Services.
Possible causes include:
The hard drive on which the trace log is located is full.
The permissions on the trace logging directory are not set correctly.
If the problem is caused by a full hard drive, free up space on the drive containing the trace log by increasing the drive capacity of the drive containing the trace log or by moving the trace log to a partition with more hard drive space.
Otherwise, if the problem is caused by a permissions issue, on the Web front-end, ensure that the WSS_Admin_WPG Windows group has Full Control and the WSS_WPG Windows group has Read and Execute, List Folder Contents, and Read permissions or higher on the folder that contains the trace log.
Note: You can view or change the location of the trace log on the Diagnostic Logging page in Central Administration. To access this page, in Central Administration, on the Operations menu, click Diagnostic logging.
© 2000-2007 Microsoft Corporation, all rights reserved.
Target | Microsoft.Windows.SharePoint.Services.3.0.WSS.Application | ||
Category | EventCollection | ||
Enabled | True | ||
Event_ID | 5401 | ||
Event Source | Windows SharePoint Services 3 | ||
Alert Generate | True | ||
Alert Severity | Warning | ||
Alert Priority | Normal | ||
Remotable | True | ||
Alert Message |
| ||
Event Log | Application |
ID | Module Type | TypeId | RunAs |
---|---|---|---|
DS | DataSource | Microsoft.Windows.EventProvider | Default |
CollectData | WriteAction | Microsoft.SystemCenter.CollectEvent | Default |
DataWarehousePublishData | WriteAction | Microsoft.SystemCenter.DataWarehouse.PublishEventData | Default |
WSS.GenerateAlert | WriteAction | System.Health.GenerateAlert | Default |
<Rule ID="Microsoft.Windows.SharePoint.Services.3.0.Unable_to_write_to_trace_log" Enabled="onEssentialMonitoring" Target="Microsoft.Windows.SharePoint.Services.3.0.WSS.Application" ConfirmDelivery="true" Remotable="true" Priority="Normal" DiscardLevel="100">
<Category>EventCollection</Category>
<DataSources>
<DataSource ID="DS" TypeID="MSWL!Microsoft.Windows.EventProvider">
<ComputerName>$Target/Host/Property[Type="MSWL!Microsoft.Windows.Computer"]/NetworkName$</ComputerName>
<LogName>Application</LogName>
<Expression>
<And>
<Expression>
<SimpleExpression>
<ValueExpression>
<XPathQuery Type="Integer">EventDisplayNumber</XPathQuery>
</ValueExpression>
<Operator>Equal</Operator>
<ValueExpression>
<Value>5401</Value>
</ValueExpression>
</SimpleExpression>
</Expression>
<Expression>
<SimpleExpression>
<ValueExpression>
<XPathQuery Type="String">PublisherName</XPathQuery>
</ValueExpression>
<Operator>Equal</Operator>
<ValueExpression>
<Value>Windows SharePoint Services 3</Value>
</ValueExpression>
</SimpleExpression>
</Expression>
</And>
</Expression>
</DataSource>
</DataSources>
<WriteActions>
<WriteAction ID="CollectData" TypeID="SystemCenter!Microsoft.SystemCenter.CollectEvent"/>
<WriteAction ID="DataWarehousePublishData" TypeID="SCDW!Microsoft.SystemCenter.DataWarehouse.PublishEventData"/>
<WriteAction ID="WSS.GenerateAlert" TypeID="Health!System.Health.GenerateAlert">
<Priority>1</Priority>
<Severity>1</Severity>
<AlertMessageId>$MPElement[Name="Microsoft.Windows.SharePoint.Services.3.0.Unable_to_write_to_trace_log.AlertMessageID"]$</AlertMessageId>
<AlertParameters>
<AlertParameter1>$Data/EventDisplayNumber$</AlertParameter1>
<AlertParameter2>$Data/EventDescription$</AlertParameter2>
<AlertParameter3>$Data/PublisherName$</AlertParameter3>
<AlertParameter4>$Target/Host/Property[Type="MSWL!Microsoft.Windows.Computer"]/NetworkName$</AlertParameter4>
</AlertParameters>
<Suppression>
<SuppressionValue>$Data/EventDisplayNumber$</SuppressionValue>
<SuppressionValue>$Data/PublisherName$</SuppressionValue>
<SuppressionValue>$Data/LoggingComputer$</SuppressionValue>
<SuppressionValue>$Data/EventDescription$</SuppressionValue>
</Suppression>
</WriteAction>
</WriteActions>
</Rule>