This article describes information that may be collected from a computer that is running the Exchange Server 2003 Diagnostic.
Typically, the output file name contains a prefix. This prefix includes the name of the item for which the output was generated. For example, the prefix may contain the computer name, the cluster name, the storage group name, or the database name.
Information that is collectedNote In these tables,
{prefix} is a placeholder for the name of the item for which the output was generated.
Exchange Server and organization baselineDescription | File name |
---|
Exchange Best Practices Analyzer Health Check including Organization, Administrative Groups, and local Exchange Server in run-scope through the exbpacmd.exe utility | {prefix}_ExBPA.xml |
Log from Exchange Best Practices Analyzer Health Check | {prefix}_ExBPA.xml.log |
Exchange organization, configuration, and permissions information through the exchdump.exe utility | {prefix}_ExchDump_<date>_<time> .HTM and .XML |
Exchange Server Setup Progress log from %SystemDrive% | {prefix}_Exchange Server Setup Progress.log |
Exchange Server Deployment Tools logs from %SystemDrive%\ExDepl~1\*.* | {prefix}_<ExDeploy Log Name> |
Information store function call logging file | {prefix}_store.fcl |
File version information from Exchange\*.exe, *.dll | {prefix}_sym_Exchange_EXE_DLL.* |
HKLM\SOFTWARE\Microsoft\Exchange | {prefix}_reg_Exchange.TXT |
HKLM\System\CurrentControlSet\Services: MSExchangeActiveSyncNotify MSExchangeADDXA MSExchangeAL MSExchangeDSAccess MSExchangeES MSExchangeFBPublish MSExchangeIS MSExchangeMGMT MSExchangeMTA MSExchangeMU MSExchangeOMA MSExchangeSA MSExchangeSenderID MSExchangeTransport MSExchangeUCF MSExchangeWEB | {prefix}_reg_Exchange.TXT |
HKLM\Software\Microsoft\MosTrace\CurrentVersion\DebugAsyncTrace | {prefix}_reg_Exchange.TXT |
HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\STORE.EXE | {prefix}_reg_Exchange.TXT |
Event logsDescription | File name |
---|
Event log � Application � text, csv, and evt formats | {prefix}_evt_Application.* |
Event log � System � text, csv, and evt formats | {prefix}_evt_System.* |
Event logs � Windows PowerShell � text, csv, and evt formats | {prefix}_evt_*PowerShell*.* |
File version informationDescription | File name |
---|
File version information from %windir%\cluster\*.* | {prefix}_sym_Cluster.* |
File version information from %windir%\system32\inetsrv\*.exe, *.dll | {prefix}_sym_InetSrv_EXE_DLL.* |
File version information from %windir%\system32\drivers\*.* | {prefix}_sym_Drivers.* |
File version information from {Program Files}\Microsoft iSNS Server\*.* and %windir%\system32\iscsi*.* | {prefix}_sym_MS_Iscsi.* |
File version information from all drivers that are currently running on computer | {prefix}_sym_RunningDrivers.* |
File version information from all processes that are currently running on computer | {prefix}_sym_Process.* |
Registry keys and valuesDescription | File name |
---|
HKLM\Software\Microsoft\Windows NT\CurrentVersion
HKLM\Software\Microsoft\Windows\CurrentVersion | {prefix}_reg_CurrentVersion.TXT |
HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall | {prefix}_reg_Uninstall.TXT |
HKLM\SYSTEM\CurrentControlSet\Control\ProductOptions | {prefix}_reg_ProductOptions.TXT |
HKLM\System\MountedDevices | {prefix}_reg_MountedDevices.* |
HKLM\System\CurrentControlSet\Control\CrashControl HKLM\System\CurrentControlSet\Control\Session Manager HKLM\System\CurrentControlSet\Control\Session Manager\Memory Management HKLM\Software\Microsoft\Windows NT\CurrentVersion\AeDebug HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options HKLM\Software\Microsoft\Windows\Windows Error Reporting HKLM\Software\Policies\Microsoft\Windows\Windows Error Reporting | {prefix}_reg_Recovery.TXT |
HKCU\Software\Microsoft\Windows\CurrentVersion\Run HKCU\Software\Microsoft\Windows\CurrentVersion\Runonce HKCU\Software\Microsoft\Windows\CurrentVersion\RunonceEx HKCU\Software\Microsoft\Windows\CurrentVersion\RunServices HKCU\Software\Microsoft\Windows\CurrentVersion\RunServicesOnce HKLM\Software\Microsoft\Windows\CurrentVersion\Policies\Explorer\Run HKLM\ Software\Microsoft\Windows\CurrentVersion\Run HKLM\Software\Microsoft\Windows\CurrentVersion\Runonce HKLM\Software\Microsoft\Windows\CurrentVersion\RunonceEx HKLM\Software\Microsoft\Windows\CurrentVersion\RunServices HKLM\Software\Microsoft\Windows\CurrentVersion\RunServicesOnce HKLM\Software\Microsoft\Windows\CurrentVersion\ShellServiceObjectDelayLoad HKCU\Software\Microsoft\Windows NT\CurrentVersion\Load HKCU\Software\Microsoft\Windows NT\CurrentVersion\Windows\Run HKCU\Software\Microsoft\Windows\CurrentVersion\Policies\Explorer\Run HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon\UserInit | {prefix}_reg_Startup.TXT |
HKLM\SYSTEM\CurrentControlSet\Control\Print | {prefix}_reg_Print.hiv |
HKCU\Software\Policies HKLM\Software\Policies HKCU\Software\Microsoft\Windows\CurrentVersion\Policies HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Policies | {prefix}_reg_Policies.txt |
HKLM\SYSTEM\CurrentControlSet\Control\TimeZoneInformation HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Time Zones | {prefix}_reg_TimeZone.txt |
HKLM\SYSTEM\CurrentControlSet\Control\Terminal Server HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Terminal Server HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Terminal Server Web Access HKLM\SYSTEM\CurrentControlSet\Services\TermService HKLM\SYSTEM\CurrentControlSet\Services\TermDD | {prefix}_reg_TermServices.txt |
HKLM\SYSTEM\CurrentControlSet\Services\LanmanServer HKLM\SYSTEM\CurrentControlSet\Services\LanmanWorkstation HKLM\SYSTEM\CurrentControlSet\Services\MRxSmb HKLM\SYSTEM\CurrentControlSet\Services\SMB HKLM\SYSTEM\CurrentControlSet\Services\MRxSmb10 HKLM\SYSTEM\CurrentControlSet\Services\MRxSmb20 | {prefix}_reg_SMB.txt |
HKLM\SYSTEM\CurrentControlSet\Services\Tcpip\Parameters | {prefix}_reg_TCPIPParameters |
HKLM\SYSTEM\CurrentControlSet\Services\VSS | {prefix}_reg_VSS.TXT |
HKLM\SYSTEM\CurrentControlSet\Services\iScsiPrt HKLM\SOFTWARE\Microsoft\iSCSI Target HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\iSCSI | {prefix}_reg_iSCSI.TXT |
HKLM\System\CurrentControlSet\Control\MPDev HKLM\System\CurrentControlSet\Control\iSCSIPrt HKLM\System\CurrentControlSet\Services\MSiSCSI HKLM\System\CurrentControlSet\Services\MSDsm HKLM\System\CurrentControlSet\Services\MPIO HKLM\System\CurrentControlSet\Control\Class\{4d36e97b-e325-11ce-bfc1-08002be10318} HKLM\System\CurrentControlSet\Services\Tcpip | {prefix}_reg_Storage.TXT |
Networking informationDescription | File name |
---|
Output from the netdiag.exe utility | {prefix}_netdiag.txt |
DNS client information from ipconfig displaydns | {prefix}_DnsClient-DnsCache.TXT |
DNS server information from dnscmd /info | {prefix}_DnsServer-DnsCmd.TXT |
Firewall information from netsh firewall | (prefix}_Firewall-Netsh-Fw.TXT |
Ipsec information from netsh ipsec | {prefix}_Ipsec-Netsh.TXT |
Network configuration information from netsh dump | {prefix}_Netsh-Dump.TXT |
Basic IP networking configuration information, such as Tcp/ip registry key, ipconfig, netstat, nbtstat, and netsh output | {prefix}_TcpIp-Info.txt |
TCPIP offload and configuration information, such as Tcp/ip parameters registry key, netstat, and netsh output | {prefix}_TCPIP-Info-OFFLOAD.TXT |
Netsh information for IPv4 | {prefix}_TCPIP-Netsh-IPv4.TXT |
Netsh information for IPv6 | {prefix}_TCPIP-Netsh-IPv6.TXT |
Netsh information for TCP global and chimney | {prefix}_TCPIP-Netsh-TCP.TXT |
Active Directory and policy informationDescription | File
name |
---|
Resultant
Set of Policy (RSoP) information through gpresult.exe | {prefix}_GPResult.* |
Security templates that are currently cached on the system | {prefix}_AppliedSecTempl.txt |
Report of user rights and privileges on the local computer | {prefix}_USERRIGHTS.TXT |
FSMO role owner information through netdom | {prefix}_netdomfsmo.txt |
Output from DCDiag.exe diagnostic utility | {prefix}_dcdiag.txt |
Output from RepAdmin.exe diagnostic utility | {prefix}_repadmin.txt |
Output from Group Policy Consistency Checker (GPOTool.exe) | {prefix}_gpotool.txt |
Cluster informationDescription | File name |
---|
Cluster Configuration information | {prefix}_CLUSTER_MPS_INFORMATION.TXT |
File version information from %windir%\cluster\*.* | {prefix}_sym_Cluster.* or {prefix}_CLUSTER_DIR.TXT |
Cluster resource properties | {prefix}_CLUSTER_RES_PROPERTIES_ALL.TXT |
List of cluster resources | {prefix}_CLUSTER_RESOURCES.TXT |
Files from %windir%\cluster\*chkdsk* | {prefix}_*chkdsk* |
Copy of cluster configuration log file, ClCfgSrv.log | {prefix}_ClCfgSrv.log |
Copy of cluster.log file | {prefix}_Cluster.log |
Copy of the file %windir%\cluster\ClusPrepCfg.xml that is used to customize validation | {prefix}_CLusPrepCfg.xml |
HKLM\System\CurrentControlSet\Services\clusdisk | {prefix}_Clusdisk.txt |
HKLM\System\CurrentControlSet\Services\clussvc | {prefix}_ClussvcRegistry.txt |
HKEY_LOCAL_MACHINE\Cluster in .txt and .hiv formats | {prefix}_ClusterRegistry.* |
Hotfixes and updatesDescription | File name |
---|
Installed updates and hotfixes | {prefix}_Hotfixes .HTM and .TXT |
WindowsUpdate.log file, located in the Windows folder | {prefix}_WindowsUpdate.log |
Storage and disk informationDescription | File name |
---|
iSCSI related information that is generated by the iscsicli.exe utility | {prefix}_ISCSI*.txt |
Fibre Channel Information through the FCInfo.exe utility | {prefix}_FCInfo.txt |
Volume Shadow Copy Service (VSS) information | {prefix}_VSSAdmin.txt |
OtherDescription | File name |
---|
System information output through msinfo32.exe | {prefix}_msinfo.* |
Copy of metabase.xml | {prefix}_metabase.xml |
Process and threads information through pstat.exe | {prefix}_PSTAT.txt |
Operating system Boot options file (Boot.ini) | {prefix}_BOOT.INI |
Output from Driver Verifier Manager (verifier.exe) utility | {prefix}_Verifier.txt |
Report of all tasks that are scheduled on the local computer | {prefix}_schtasks.* |
Additionally, this troubleshooter can detect one or more of the following situations:
- Computer is running under a hardware virtualization environment
- Presence of computer memory dumps in the past 30 days
- Presence of user mode memory dumps in the past 30 days
- Configuration or services that could prevent a memory dump file from being generated
- Unexpected shutdown event logs in the System log from the past 30 days
- Computer memory dump-related event logs in the System log from past 30 days
- Processes that have a high number of handles
- A low number of System Page Table entries (PTEs)
- Low available memory condition
- Any Kernel pool memory tag that uses more than 60 percent of all allocated memory
- Unsupported version of a service pack
- Unsupported operating system version