eG Monitoring
 

Measures reported by KeyMgmtEvtLogTest

The Key Management Service (KMS) activates computers on a local network, eliminating the need for individual computers to connect to Microsoft. To do this, KMS uses a client–server topology. KMS client computers can locate KMS host computers by using Domain Name System (DNS) or a static configuration. KMS clients contact the KMS host by using remote procedure call (RPC). A KMS host responds to each valid activation request from a KMS client with the count of how many computers have contacted the KMS host for activation. Clients that receive a count below their activation threshold are not activated. If a computer running Windows Server 2008 or Windows Server 2008 R2 receives an activation count that is ≥5, it is activated. If a computer running Windows 7 receives an activation count ≥25, it is activated.

If users to a Windows server are having trouble logging on, administrators may want to check the Key Management Service event log to see if it is owing to an issue with KMS. This event log tracks events related to Kerberos key distribution, when a server functions as a key distribution center. To enable administrators to rapidly capture error/warning events captured by this event log and troubleshoot logon issues that occur, administrators can run the KeyMgmtEvtLogTest test. This test monitors the Key Management Service event log and reports the count and details of errors and warning events captured by that log.

The measures made by this test are as follows:

Measurement Description Measurement Unit Interpretation
Information_count This refers to the number of information events that were captured by the Key Management Service log during the test's last execution. Number A change in value of this measure may indicate infrequent but successful operations.

Please check the Key Management Service log in the Event Log Viewer for more details.
Warning_count This refers to the number of warning events captured by the Key Management Service log during the test's last execution. Number A high value of this measure indicates problems that may not have an immediate impact, but may cause future problems.

Please check the Key Management Service log in the Event Log Viewer for more details.
Error_count This refers to the number of error events captured by the Key Management Service log during the test's last execution. Number A very low value (zero) is desired for this measure, as it indicates good health.

An increasing trend or a high value indicates the existence of problems.

Please check the Key Management Service log in the Event Log Viewer for more details.
Critical_count Indicates the number of critical events that were generated when the test was last executed. Number A critical event is one that the KMS cannot automatically recover from.

This measure is applicable only for Windows 2008/Windows Vista/Windows 7 systems.

A very low value (zero) indicates that the service is in a healthy state and is running smoothly without any potential problems.

An increasing trend or high value indicates the existence of fatal/irrepairable problems.

The detailed diagnosis of this measure describes all the critical events captured by the Key Management Service log during the last measurement period.

Please check the Key Management Service log in the Event Log Viewer for more details.
Verbose_count Indicates the number of verbose events that were generated when the test was last executed. Number Verbose logging provides more details in the log entry, which will enable you to troubleshoot issues better.

This measure is applicable only for Windows 2008/Windows Vista/Windows 7 systems.

The detailed diagnosis of this measure describes all the verbose events that were captured by the Key Management Service log during the last measurement period.

Please check the Key Management Service log in the Event Log Viewer for more details.