Diagnose Computer Message Log
A computer’s message log can provide you with important diagnostics information in case the computer isn’t behaving as expected.
To view the message log, select ANALYZE > Computers > Computer Search, and search for a computer. Then, in the search results, click the name of the required computer, and then select the Message Log tab.
When you analyze a computer’s message log, you may find it helpful to know some log messages that relate to typical problems, and what you can do to solve those problems. The component that logs each message is shown in bold.
First chance failure detected with ‘Maximum agent size exceeded’
Section titled “First chance failure detected with ‘Maximum agent size exceeded’”The PerformanceGuard agent regularly checks how much of the computer’s memory it uses. If the agent uses more than 60 MB of private memory, it sends the reports it has collected, waits a few seconds, and then restarts itself so that it doesn’t use excessive amounts of the computer’s memory.
This message from the SelfSurveillance component marks the start of that restart. It includes the agent’s memory usage as Private Bytes (kB). When the agent has started again, you’ll see the message Agent restart caused by : Agent memory size exceeded (described in the following).
Solution: If the message occurs rarely, you can safely ignore it. If the message occurs often, report it to CapaSystems support.
Agent restart caused by : Agent memory size exceeded
Section titled “Agent restart caused by : Agent memory size exceeded”This message from the InitApplication component is logged when the agent starts again after it restarted itself because it used more than 60 MB of private memory. The message shows the amount of memory (in KB) that the agent used before it was restarted.
Solution: If the message occurs rarely, you can safely ignore it. If the message occurs often, report it to CapaSystems support.
Could not create custom counter
Section titled “Could not create custom counter”This message from the E2ECustomCounters component occurs if the syntax in a custom performance counter isn’t valid. The message includes the counter in question.
The message also occurs if the syntax is valid, but the PerformanceGuard agent on the computer can’t find the information that the custom counter asks for. For example, if the custom counter asks the agent to collect information about the D: drive on a computer that doesn’t have a D: drive.
Solution: Verify that the custom counter syntax is valid, and that the custom counter is relevant for the computer in question. If no counters work on the computer, see Custom Counters with No Data.
Could not set timing mode
Section titled “Could not set timing mode”This message from the npf.sys or pgnpf.sys component occurs if the PerformanceGuard agent can’t write the timing setting to the registry key of the packet capture driver.
This is an information message. The packet capture driver uses its default timing method instead.
Solution: If the message occurs rarely, you can safely ignore it. If the message occurs often, report it to CapaSystems support.
Get Login time via Wmi failed. Using alternative
Section titled “Get Login time via Wmi failed. Using alternative”This message from the PSystemInfo component occurs if the agent can’t get the computer’s boot time through WMI.
This isn’t a serious problem. The agent uses another method to find the boot time, and that’s what causes the message.
Solution: Ignore the message.
No adapter found to capture from
Section titled “No adapter found to capture from”This message from the E2ENetPacketDispatcher component typically occurs if the computer that runs the PerformanceGuard agent doesn’t have a working network connection. The agent then reports Winpcap Driver Could not initialize in the computer’s agent information.
If you get this message from an agent on a computer that does have a working network connection, there’s a problem with connecting the packet capture driver with the network interface. This can happen if the computer has a complex setup, for example with teamed network adapters or locally installed firewall software that’s not fully NDIS compliant.
Finally, the message may also be caused if any of the agent’s packet capture components have become corrupt, or if an old WinPcap version is installed on the computer. If a separate WinPcap installation is present, the agent uses it instead of its own packet capture driver.
The message is typically followed by a Configuration failed message.
Solution: First check if the computer has a working network connection. Next, find out if someone has installed non-NDIS compliant firewall software or an old WinPcap version on the computer. To check the agent’s packet capture driver, see WinPcap Packet-Capture Driver. If you’re stuck, report the problem to CapaSystems support.
Configuration failed
Section titled “Configuration failed”When this message comes from the E2ENetPacketDispatcher component, the agent couldn’t set up network capture. This happens if the computer doesn’t have a working network connection, or if there’s a problem with connecting the packet capture driver with the network interface. See No adapter found to capture from in the previous section.
When the message comes from the component that collects performance data, look for a Could not connect to performance counter message just before it. See Agent Doesn’t Report Properly.