I can't find much online about this with websearch.
Log Name: Application
Source: FfoSystemProbe
Date: 12/23/2014 10:05:53 AM
Event ID: 1006
Task Category: General
Level: Warning
Keywords: Classic
User: N/A
Computer: myserver.mydomain.local
Description:
System Probe configuration. The logging directory was not specified in the registry and system probe will not be enabled on this server.
Event Xml:
<Event xmlns="http://schemas.microsoft.com/win/2004/08/events/event">
<System>
<Provider Name="FfoSystemProbe" />
<EventID Qualifiers="32768">1006</EventID>
<Level>3</Level>
<Task>1</Task>
<Keywords>0x80000000000000</Keywords>
<TimeCreated SystemTime="2014-12-23T17:05:53.000000000Z" />
<EventRecordID>10531</EventRecordID>
<Channel>Application</Channel>
<Computer>myserver.mydomain.local</Computer>
<Security />
</System>
<EventData>
</EventData>
</Event>
A quick registry search does find a key:
[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Services\EventLog\Application\FfoSystemProbe]
"EventMessageFile"="C:\\Program Files\\Microsoft\\Exchange Server\\V15\\Bin\\Microsoft.Exchange.SystemProbeMsg.dll"
"CategoryMessageFile"="C:\\Program Files\\Microsoft\\Exchange Server\\V15\\Bin\\Microsoft.Exchange.SystemProbeMsg.dll"
"TypesSupported"=dword:00000007
"CategoryCount"=dword:00000001
A quick look at the Bin folder under Exchange installation shows the dll file exists and permissions on it seem to match similar files in the same folder.
Duplicate registry entries exist also with identical subkeys:
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet002\Services\EventLog\Application\FfoSystemProbe
HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\EventLog\Application\FfoSystemProbe
- Edited by MnM Show Tuesday, December 23, 2014 6:03 PM