locked
SCOM warnings and errors; event id 4503, 10703. 1103 and 10102

    Question

  •  

    Hi,

    I have several warnings and errors on servers in the Operations
    Manager event log:

     

    Error
    Source: HealthService
    Event ID: 4503
    A module reported an error 0x80070057 from a callback which was
    running as part of rule .....
    or
    A module reported an error 0x80004005 from a callback which was
    running as part of rule ......

     

    Example:
    A module reported an error 0x80070057 from a callback which was
    running as part of rule "TCP_Query_Received_Sec_1_2_Rule" running for
    instance
    "Microsoft.Windows.Server.DNS.Microsoft_Windows_2003_DNS_Servers_Installati­on"
    with id:"{A8EEBEB0-3FA7-2823-2039-18C4B1BA80BF}" in management group
    "MG01".
    or
    A module reported an error 0x80004005 from a callback which was
    running as part of rule "Microsoft.Exchange.ServerRole.
    2003.ClientRPCFailed.Collection" running for instance "ER080MEXCH11"
    with id:"{03A0A4A3-EE4A-703E-0971-66B15D293C2A}" in management group
    "MG01".

     

    Error
    Source: Health Service Modules
    Event ID: 10703
    An error occurred while executing response
    'MOM2005ResponseContextMapper'. Response tried to set 'PerfData
    SourceComputer' to a undefined value: Null

     

    Error
    Source: Health Service Modules
    Event ID: 10102
    In PerfDataSource, could not resolve counter ........ Module will be
    unloaded.

    One or more workflows were affected by this.

    Workflow name: ....

     

    Example:
    In PerfDataSource, could not resolve counter ASP.NET Applications,
    Errors Total/Sec, __Total__. Module will be unloaded.

    One or more workflows were affected by this.

    Workflow name: Microsoft.Windows.InternetInformationServices.
    2003.WebServer.ASP.NETApplicationsErrorsTotalSec.Monitor.BaselineCollection
    Instance name: IIS Web Server
    Instance ID: {CDD0CC2F-F6F5-5053-6A4A-E59B20D841E6}
    Management group: MG01

     

    All errors followed with next warning:

    Warning
    Source: HealthService
    Event ID: 1103
    Summary: 1 rule(s)/monitor(s) failed and got unloaded, 1 of them
    reached the failure limit that prevents automatic reload. Management
    group "MG01". This is summary only event, please see other events with
    descriptions of unloaded rule(s)/monitor(s).

     

    Does anyone knows what the solution is and/or why these errors are
    generated?

     

    Thanks,
    Jolanda

    Friday, January 04, 2008 12:56 PM

All replies

  • Jolanda,

     

    Have you been able to solve this ?  I'm having similar issues (event ID 4503)

     

    thanks

     

    c

    Monday, February 18, 2008 3:04 PM
  • No, not yet. Microsoft is looking in to it.

     

    Monday, February 18, 2008 3:38 PM
  • Is there a solution to this error event? 

    Tuesday, February 26, 2008 1:21 AM
  • Error

    Source: Health Service Modules

    Event ID: 10102

    In PerfDataSource, could not resolve counter ........ Module will be

    unloaded.


    Check
    HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\<SomeService>\Performance
    Disable Performance Counters
    If "Disable Performance Counters"=1 then change 1 to 0 (enable perf counters).
    A module reported an error 0x80004005 from a callback which was

    running as part of rule ......


    Check rule settings. It seems like a wrong or mistyped parameter in rule.


    Tuesday, February 26, 2008 6:52 AM
  •  

    I installed SCOM sp1 RTM and events 4503 and 10703 are solved.

     

     

     

    Tuesday, February 26, 2008 8:22 AM
  •  

    I got 1103 and 10102 in a row on a few web servers but not all, hope someone shines a light on it,

    Thanks,

     

    Manjun

    Tuesday, April 01, 2008 3:48 PM
  •  

    I also get 1103 and 10102 in a row on a few servers. This one server has SQL and IIS. At present nothing is on this server but it slated to be my ACS Server. It is actually running 64 bit o/s Windows 2003.

     

    Event ID: 1103

    Summary: 1 rule(s)/monitor(s) failed and got unloaded, 1 of them reached the failure limit that prevents automatic reload. Management group "groupname". This is summary only event, please see other events with descriptions of unloaded rule(s)/monitor(s).

     

    Event ID: 10102

    In PerfDataSource, could not resolve counter SQLSERVER:Buffer Manager, Buffer cache hit ratio, . Module will be unloaded.

    One or more workflows were affected by this.

    Workflow name: Microsoft.SQLServer.2005.BufferCacheHitRatio

    Instance name: MSSQLSERVER

    Instance ID: {9D6DCC09-23DF-35CE-9F38-2143C0AEA4FC}

    Management group: groupname

    For more information, see Help and Support Center at http://go.microsoft.com/fwlink/events.asp.

     

    In addition I also get

     

    Source OpsMgr Connector

    Event IFD: 20046

     

     

    The health service on (RMS Server).ca is attempting to communicate with a management group that does not exist on this server.  The management group Id the agent is requesting is 274ec568-eb53-eb67-7455-60acbf4f3130.  Please verify that the management group specified on the agent and server is correct.

     

    Source Health Service Modules

    Event IFD: 10103

     

    Any help is much appreciated

     

    • Proposed as answer by JCarson Wednesday, July 15, 2009 3:29 AM
    Monday, June 02, 2008 6:18 PM
  • Hi all, my english its not the best...

    Im with the same issue with our SCOM agents:

    21 Servers (with W2k3sp1, W2k3sp2 and W2ksp4 - Exchange, IIS or many other apps) writing 3000 (event avg) each 30 minutes:

     

    1206

    Tipo de suceso: Información
    Origen del suceso: HealthService
    Categoría del suceso: Health Service
    Id. suceso: 1206
    Fecha:  04/09/2008
    Hora:  10:58:36 a.m.
    Usuario:  No disponible
    Equipo: XXXXXXX
    Descripción:
    Rule/Monitor "Microsoft.Windows.Server.2003.LogicalDisk.FreeMB.Collection", running for instance "C:" with id:"{CA7DE954-86DF-2A1F-703B-FBFCFE5556C3}" failed, got unloaded and reached the failure limit that prevents automatic reload. Management group "XXXXXX".

     

    1103

    Tipo de suceso: Advertencia
    Origen del suceso: HealthService
    Categoría del suceso: Health Service
    Id. suceso: 1103
    Fecha:  04/09/2008
    Hora:  10:58:36 a.m.
    Usuario:  No disponible
    Equipo: XXXXXXX
    Descripción:
    Summary: 1 rule(s)/monitor(s) failed and got unloaded, 1 of them reached the failure limit that prevents automatic reload. Management group "XXXXX". This is summary only event, please see other events with descriptions of unloaded rule(s)/monitor(s).


    10102

    Tipo de suceso: Error
    Origen del suceso: Health Service Modules
    Categoría del suceso: Ninguno
    Id. suceso: 10102
    Fecha:  04/09/2008
    Hora:  10:58:36 a.m.
    Usuario:  No disponible
    Equipo: XXXXXXX
    Descripción:
    In PerfDataSource, could not resolve counter LogicalDisk, Disk Writes/sec, C:. Module will be unloaded.

    One or more workflows were affected by this. 

    Workflow name: Microsoft.Windows.Server.2003.LogicalDisk.DiskWritesPerSec.Collection
    Instance name: C:
    Instance ID: {CA7DE954-86DF-2A1F-703B-FBFCFE5556C3}
    Management group: XXXXXXX

     

    Thanks in advance

    ElCai, Argentina.

    Thursday, September 04, 2008 2:28 PM
  • I am seeing some of the same issues and it is causing me A LOT of grief.  All Exchange clustered nodes are reporting 10102,1103, and 1207 events.
    Monday, September 08, 2008 7:55 PM
  • Hi everyone,

     

    I have been able to resolve Event ID: 4503 / 1103  by reloading the missing or corrupt performance counters on affected servers, I do not know what causes the Perf Counters to unload or become corrupt, perhaps someone from Microsoft can answer this question?

     

    You need to exam Event Description to work out which Counters are missing and use the lodctr util to reload the appropriate INI file. Here are some useful KB articles which assisted me to work out what INI files needed to be reloaded.

     

    Operating System http://support.microsoft.com/kb/300956

    Exchange Specific http://support.microsoft.com/kb/307613

     

    I recommended testing this procedure on non production  first.

     

    good luck!

     

     

    Wednesday, September 17, 2008 4:06 AM
  • In Regards To The Above "

    Source OpsMgr Connector

    Event IFD: 20046

     

     

    The health service on (RMS Server).ca is attempting to communicate with a management group that does not exist on this server.  The management group Id the agent is requesting is 274ec568-eb53-eb67-7455-60acbf4f3130.  Please verify that the management group specified on the agent and server is correct

    "

    You Must Verify That The Value In The Registry Key

    [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Microsoft Operations Manager\3.0\Agent Management Groups]

    Refers To The Name Of The Management Group To Which The Server Is Connecting.  If There Are Multiple Values (Due To Rebuild\Reinstall Of SCOM), Then Delete The Additional Keys.

    • Proposed as answer by JCarson Wednesday, July 15, 2009 3:33 AM
    Wednesday, July 15, 2009 3:33 AM
  • Hi Mr.JCarson,

    I got the Same issue like ,The health service on (RMS Server).ca is attempting to communicate with a management group that does not exist on this server.  The management group Id the agent is requesting is 274ec568-eb53-eb67-7455-60acbf4f3130.  Please verify that the management group specified on the agent and server is correct

    I found multiple entries in registry and deleted old entires. But still showing issue exists.

     

     

    • Proposed as answer by S.Vijay Kumar Thursday, February 02, 2017 7:11 PM
    Tuesday, July 13, 2010 11:28 AM
  • The Solution for such cases:

    1. stop the healthservice on the agent.
    2. Clear the HealthService queue and config (manually). browse to the following directory “C:\Program Files\System Center Operations Manager 2007\Health Service State” and delete all folders and files in that directory
    3. start the healthservice on the agent.

    Sunday, December 14, 2014 9:53 AM
  • Thank you Ibrahim.
    • Proposed as answer by S.Vijay Kumar Thursday, June 16, 2016 5:52 PM
    Thursday, June 16, 2016 5:52 PM