Notice: This website is an unofficial Microsoft Knowledge Base (hereinafter KB) archive and is intended to provide a reliable access to deleted content from Microsoft KB. All KB articles are owned by Microsoft Corporation. Read full disclaimer for more details.

[SDP 3][c9b66651-9b8f-40b7-9c2a-985c79c26b62] Microsoft Exchange Server 2003 Diagnostic


View products that this article applies to.

Summary

The Microsoft Exchange Server 2003 Diagnostic Tool collects a comprehensive set of information for troubleshooting Exchange Server 2003 issues.

↑ Back to the top


More information

This article describes information that may be collected from a computer that is running the Exchange Server 2003 Diagnostic.

Typically, the output file name contains a prefix. This prefix includes the name of the item for which the output was generated. For example, the prefix may contain the computer name, the cluster name, the storage group name, or the database name.

Information that is collected

Note In these tables, {prefix} is a placeholder for the name of the item for which the output was generated.

Exchange Server and organization baseline
DescriptionFile name
Exchange Best Practices Analyzer Health Check including Organization, Administrative Groups, and local Exchange Server in run-scope through the exbpacmd.exe utility{prefix}_ExBPA.xml
Log from Exchange Best Practices Analyzer Health Check{prefix}_ExBPA.xml.log
Exchange organization, configuration, and permissions information through the exchdump.exe utility{prefix}_ExchDump_<date>_<time>
.HTM and .XML
Exchange Server Setup Progress log from %SystemDrive%{prefix}_Exchange Server Setup Progress.log
Exchange Server Deployment Tools logs from %SystemDrive%\ExDepl~1\*.*{prefix}_<ExDeploy Log Name>
Information store function call logging file{prefix}_store.fcl
File version information from Exchange\*.exe, *.dll{prefix}_sym_Exchange_EXE_DLL.*
HKLM\SOFTWARE\Microsoft\Exchange{prefix}_reg_Exchange.TXT
HKLM\System\CurrentControlSet\Services:
MSExchangeActiveSyncNotify
MSExchangeADDXA
MSExchangeAL
MSExchangeDSAccess
MSExchangeES
MSExchangeFBPublish
MSExchangeIS
MSExchangeMGMT
MSExchangeMTA
MSExchangeMU
MSExchangeOMA
MSExchangeSA
MSExchangeSenderID
MSExchangeTransport
MSExchangeUCF
MSExchangeWEB
{prefix}_reg_Exchange.TXT
HKLM\Software\Microsoft\MosTrace\CurrentVersion\DebugAsyncTrace
{prefix}_reg_Exchange.TXT
HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\STORE.EXE
{prefix}_reg_Exchange.TXT

Event logs
DescriptionFile name
Event log � Application � text, csv, and evt formats{prefix}_evt_Application.*
Event log � System � text, csv, and evt formats{prefix}_evt_System.*
Event logs � Windows PowerShell � text, csv, and evt formats{prefix}_evt_*PowerShell*.*

File version information
DescriptionFile name
File version information from %windir%\cluster\*.*{prefix}_sym_Cluster.*
File version information from %windir%\system32\inetsrv\*.exe, *.dll{prefix}_sym_InetSrv_EXE_DLL.*
File version information from %windir%\system32\drivers\*.*{prefix}_sym_Drivers.*
File version information from {Program Files}\Microsoft iSNS Server\*.* and %windir%\system32\iscsi*.*{prefix}_sym_MS_Iscsi.*
File version information from all drivers that are currently running on computer{prefix}_sym_RunningDrivers.*
File version information from all processes that are currently running on computer{prefix}_sym_Process.*

Registry keys and values
DescriptionFile name
HKLM\Software\Microsoft\Windows NT\CurrentVersion

HKLM\Software\Microsoft\Windows\CurrentVersion
{prefix}_reg_CurrentVersion.TXT
HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall{prefix}_reg_Uninstall.TXT
HKLM\SYSTEM\CurrentControlSet\Control\ProductOptions{prefix}_reg_ProductOptions.TXT
HKLM\System\MountedDevices{prefix}_reg_MountedDevices.*
HKLM\System\CurrentControlSet\Control\CrashControl
HKLM\System\CurrentControlSet\Control\Session Manager
HKLM\System\CurrentControlSet\Control\Session Manager\Memory Management
HKLM\Software\Microsoft\Windows NT\CurrentVersion\AeDebug
HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options
HKLM\Software\Microsoft\Windows\Windows Error Reporting
HKLM\Software\Policies\Microsoft\Windows\Windows Error Reporting
{prefix}_reg_Recovery.TXT
HKCU\Software\Microsoft\Windows\CurrentVersion\Run
HKCU\Software\Microsoft\Windows\CurrentVersion\Runonce
HKCU\Software\Microsoft\Windows\CurrentVersion\RunonceEx
HKCU\Software\Microsoft\Windows\CurrentVersion\RunServices
HKCU\Software\Microsoft\Windows\CurrentVersion\RunServicesOnce
HKLM\Software\Microsoft\Windows\CurrentVersion\Policies\Explorer\Run
HKLM\ Software\Microsoft\Windows\CurrentVersion\Run
HKLM\Software\Microsoft\Windows\CurrentVersion\Runonce
HKLM\Software\Microsoft\Windows\CurrentVersion\RunonceEx
HKLM\Software\Microsoft\Windows\CurrentVersion\RunServices
HKLM\Software\Microsoft\Windows\CurrentVersion\RunServicesOnce
HKLM\Software\Microsoft\Windows\CurrentVersion\ShellServiceObjectDelayLoad
HKCU\Software\Microsoft\Windows NT\CurrentVersion\Load
HKCU\Software\Microsoft\Windows NT\CurrentVersion\Windows\Run
HKCU\Software\Microsoft\Windows\CurrentVersion\Policies\Explorer\Run
HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon\UserInit
{prefix}_reg_Startup.TXT
HKLM\SYSTEM\CurrentControlSet\Control\Print{prefix}_reg_Print.hiv
HKCU\Software\Policies
HKLM\Software\Policies
HKCU\Software\Microsoft\Windows\CurrentVersion\Policies
HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Policies
{prefix}_reg_Policies.txt
HKLM\SYSTEM\CurrentControlSet\Control\TimeZoneInformation
HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Time Zones
{prefix}_reg_TimeZone.txt
HKLM\SYSTEM\CurrentControlSet\Control\Terminal Server
HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Terminal Server
HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Terminal Server Web Access
HKLM\SYSTEM\CurrentControlSet\Services\TermService
HKLM\SYSTEM\CurrentControlSet\Services\TermDD
{prefix}_reg_TermServices.txt
HKLM\SYSTEM\CurrentControlSet\Services\LanmanServer
HKLM\SYSTEM\CurrentControlSet\Services\LanmanWorkstation
HKLM\SYSTEM\CurrentControlSet\Services\MRxSmb
HKLM\SYSTEM\CurrentControlSet\Services\SMB
HKLM\SYSTEM\CurrentControlSet\Services\MRxSmb10
HKLM\SYSTEM\CurrentControlSet\Services\MRxSmb20
{prefix}_reg_SMB.txt
HKLM\SYSTEM\CurrentControlSet\Services\Tcpip\Parameters{prefix}_reg_TCPIPParameters
HKLM\SYSTEM\CurrentControlSet\Services\VSS{prefix}_reg_VSS.TXT
HKLM\SYSTEM\CurrentControlSet\Services\iScsiPrt
HKLM\SOFTWARE\Microsoft\iSCSI Target
HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\iSCSI
{prefix}_reg_iSCSI.TXT
HKLM\System\CurrentControlSet\Control\MPDev
HKLM\System\CurrentControlSet\Control\iSCSIPrt
HKLM\System\CurrentControlSet\Services\MSiSCSI
HKLM\System\CurrentControlSet\Services\MSDsm
HKLM\System\CurrentControlSet\Services\MPIO
HKLM\System\CurrentControlSet\Control\Class\{4d36e97b-e325-11ce-bfc1-08002be10318}
HKLM\System\CurrentControlSet\Services\Tcpip
{prefix}_reg_Storage.TXT

Networking information
DescriptionFile name
Output from the netdiag.exe utility{prefix}_netdiag.txt
DNS client information from ipconfig displaydns{prefix}_DnsClient-DnsCache.TXT
DNS server information from dnscmd /info{prefix}_DnsServer-DnsCmd.TXT
Firewall information from netsh firewall(prefix}_Firewall-Netsh-Fw.TXT
Ipsec information from netsh ipsec{prefix}_Ipsec-Netsh.TXT
Network configuration information from netsh dump{prefix}_Netsh-Dump.TXT
Basic IP networking configuration information, such as Tcp/ip registry key, ipconfig, netstat, nbtstat, and netsh output{prefix}_TcpIp-Info.txt
TCPIP offload and configuration information, such as Tcp/ip parameters registry key, netstat, and netsh output{prefix}_TCPIP-Info-OFFLOAD.TXT
Netsh information for IPv4{prefix}_TCPIP-Netsh-IPv4.TXT
Netsh information for IPv6{prefix}_TCPIP-Netsh-IPv6.TXT
Netsh information for TCP global and chimney{prefix}_TCPIP-Netsh-TCP.TXT

Active Directory and policy information
DescriptionFile name
Resultant Set of Policy (RSoP) information through gpresult.exe{prefix}_GPResult.*
Security templates that are currently cached on the system{prefix}_AppliedSecTempl.txt
Report of user rights and privileges on the local computer{prefix}_USERRIGHTS.TXT
FSMO role owner information through netdom{prefix}_netdomfsmo.txt
Output from DCDiag.exe diagnostic utility{prefix}_dcdiag.txt
Output from RepAdmin.exe diagnostic utility{prefix}_repadmin.txt
Output from Group Policy Consistency Checker (GPOTool.exe) {prefix}_gpotool.txt

Cluster information
DescriptionFile name
Cluster Configuration information{prefix}_CLUSTER_MPS_INFORMATION.TXT
File version information from %windir%\cluster\*.*{prefix}_sym_Cluster.* or {prefix}_CLUSTER_DIR.TXT
Cluster resource properties{prefix}_CLUSTER_RES_PROPERTIES_ALL.TXT
List of cluster resources{prefix}_CLUSTER_RESOURCES.TXT
Files from %windir%\cluster\*chkdsk*{prefix}_*chkdsk*
Copy of cluster configuration log file, ClCfgSrv.log{prefix}_ClCfgSrv.log
Copy of cluster.log file{prefix}_Cluster.log
Copy of the file %windir%\cluster\ClusPrepCfg.xml that is used to customize validation{prefix}_CLusPrepCfg.xml
HKLM\System\CurrentControlSet\Services\clusdisk{prefix}_Clusdisk.txt
HKLM\System\CurrentControlSet\Services\clussvc{prefix}_ClussvcRegistry.txt
HKEY_LOCAL_MACHINE\Cluster in .txt and .hiv formats{prefix}_ClusterRegistry.*

Hotfixes and updates
DescriptionFile name
Installed updates and hotfixes{prefix}_Hotfixes .HTM and .TXT
WindowsUpdate.log file, located in the Windows folder{prefix}_WindowsUpdate.log

Storage and disk information
DescriptionFile name
iSCSI related information that is generated by the iscsicli.exe utility{prefix}_ISCSI*.txt
Fibre Channel Information through the FCInfo.exe utility{prefix}_FCInfo.txt
Volume Shadow Copy Service (VSS) information{prefix}_VSSAdmin.txt

Other
DescriptionFile name
System information output through msinfo32.exe{prefix}_msinfo.*
Copy of metabase.xml{prefix}_metabase.xml
Process and threads information through pstat.exe{prefix}_PSTAT.txt
Operating system Boot options file (Boot.ini){prefix}_BOOT.INI
Output from Driver Verifier Manager (verifier.exe) utility{prefix}_Verifier.txt
Report of all tasks that are scheduled on the local computer{prefix}_schtasks.*

Additionally, this troubleshooter can detect one or more of the following situations:
  • Computer is running under a hardware virtualization environment
  • Presence of computer memory dumps in the past 30 days
  • Presence of user mode memory dumps in the past 30 days
  • Configuration or services that could prevent a memory dump file from being generated
  • Unexpected shutdown event logs in the System log from the past 30 days
  • Computer memory dump-related event logs in the System log from past 30 days
  • Processes that have a high number of handles
  • A low number of System Page Table entries (PTEs)
  • Low available memory condition
  • Any Kernel pool memory tag that uses more than 60 percent of all allocated memory
  • Unsupported version of a service pack
  • Unsupported operating system version

↑ Back to the top


References

For more information about Microsoft Automated Troubleshooting Services (MATS) and about Support Diagnostic Platform (SDP), click the following article number to view the article in the Microsoft Knowledge Base:
2598970 Information about the Microsoft Automated Troubleshooting Services and Support Diagnostic Platform

↑ Back to the top


Keywords: KB2132080, kbtshoot, kbsurveynew

↑ Back to the top

Article Info
Article ID : 2132080
Revision : 5
Created on : 6/14/2012
Published on : 6/14/2012
Exists online : False
Views : 513