Quantcast
Channel: VMware Communities : Discussion List - All Communities
Viewing all 178040 articles
Browse latest View live

Excessive login times

$
0
0

We recently created new pools and recomposed all pools to get updated machines rolled out to all users.

After the recompose half the users login fine and other users take up to 10 minutes to login.

I need to determine what is causing such long login times.

Initially in group policy we set outlook to cached mode and have been trying login after cached mode is disabled and still experiencing the same issue.

I have created a test user and the profile loads fine.

CPU/RAM/HDD all look fine during login on Domain controller, view server, vcenter server, and virtual host.

When looking at the login monitor log on the user that takes a long time to load the "logon start to hive loaded time" is over 400 seconds. On the test user this is under 3 seconds.

This log is pulled from the same virtual machine using two different users:

 

TestUser:

2018-10-01T13:52:07.301 TRACE (08fc-19cc) [VMWLogSettings] Log Level: 0x1F

2018-10-01T13:52:07.301 TRACE (08fc-19cc) [VMWLogSettings] Log History Depth: 10

2018-10-01T13:52:07.301 TRACE (08fc-19cc) [VMWLogSettings] Log Path: \\?\C:\ProgramData\VMWare\VMware Logon Monitor\Logs

2018-10-01T13:52:07.301 TRACE (08fc-19cc) [VMWLogSettings] Main Log Path: \\?\C:\ProgramData\VMWare\VMware Logon Monitor\Logs\vmlm.txt

2018-10-01T13:52:07.301 TRACE (08fc-19cc) [VMWLogSettings] Main Log Max Size: 100000000

2018-10-01T13:52:07.301 TRACE (08fc-19cc) [VMWLogSettings] Main Log Keep Days: 7

2018-10-01T13:52:07.301 TRACE (08fc-19cc) [VMWLogSettings] Remote Log Path:

2018-10-01T13:52:07.301 TRACE (08fc-19cc) [VMWLogSettings] Data Dir: \\?\C:\ProgramData\VMWare\VMware Logon Monitor\Data

2018-10-01T13:52:07.301 TRACE (08fc-19cc) [VMWLogSettings] Flags: 0x3

2018-10-01T13:52:07.301 TRACE (08fc-19cc) [VMWLogSettings] Computer Name: Company-CNCG-BK2

2018-10-01T13:52:07.301 TRACE (08fc-19cc) [VMWLogSettings] FQDN: Company-CNCG-BK2.ad.Company.org

2018-10-01T13:52:07.301 INFO (08fc-19cc) [VMWLogIpAddresses] Friendly Name: Local Area Connection

2018-10-01T13:52:07.301 INFO (08fc-19cc) [VMWLogIpAddresses] IP Address: 10.10.10.155

2018-10-01T13:52:07.301 INFO (08fc-19cc) [VMWLogIpAddresses] Dns Server Address[0]: 10.10.10.10

2018-10-01T13:52:07.333 TRACE (08fc-19cc) [LogonMonitor::StartWMIEventSink] CPU monitoring is not enabled

2018-10-01T13:52:07.333 TRACE (08fc-19cc) [LogonMonitor::StartWMIEventSink] Memory monitoring is not enabled

2018-10-01T13:52:07.348 TRACE (08fc-19cc) [LogonMonitor::StartWMIEventSink] Registered For Process Creation Events

2018-10-01T13:52:07.364 TRACE (08fc-19cc) [LogonMonitor::StartWMIEventSink] Registered For Process Termination Events

2018-10-01T13:52:07.364 TRACE (08fc-19cc) [LogonMonitor::StartWMIEventSink] WMI Event Sink Started Successfully: Session: 16

2018-10-01T13:52:07.442 TRACE (08fc-19cc) [LogonMonitor::StartSensEventSink] SENS Event Sink Started Successfully, Session: 16

2018-10-01T13:52:07.458 TRACE (08fc-19cc) [LogonMonitor::IsUserAlreadyLoggedOn] Failed to query user token for session: 0x800703F0, Session: 0

2018-10-01T13:52:07.458 TRACE (08fc-19cc) [LogonMonitor::IsUserAlreadyLoggedOn] Failed to query user token for session: 0x80070002, Session: 65536

2018-10-01T13:52:07.458 TRACE (08fc-19cc) [LogonMonitor::UpdateSessionContext] AuthId: (0x0,0x132BB11F). Session: 16

2018-10-01T13:52:07.458 TRACE (08fc-19cc) [LogonMonitor::IsRemoteSessionShellExplorer] Session is local,  SessionGuid: 706fdb44-d0c0-47e3-bbf0-7bc69dfa5f4c, Session: 16

2018-10-01T13:52:07.458 TRACE (08fc-19cc) [LogonMonitor::StartShellLoadMonitor] Shell Load Monitor Started. Session: 16

2018-10-01T13:52:07.458 INFO (08fc-19cc) [LogonMonitor::Logon] LOGON: User: Company\Working, Session: 16

2018-10-01T13:52:10.333 TRACE (08fc-1a84) [LogonMonitor::ProcessLogonEvent] Event Id: 1, Session: 16

2018-10-01T13:52:10.333 TRACE (08fc-1a84) [LogonMonitor::ProcessLogonEvent] Profile Started. Session: 16

2018-10-01T13:52:10.333 TRACE (08fc-1a84) [LogonMonitor::ProcessLogonEvent] Event Id: 6, Session: 16

2018-10-01T13:52:10.333 TRACE (08fc-1a84) [LogonMonitor::ProcessLogonEvent] Profile Sync Started. Session: 16

2018-10-01T13:52:10.333 INFO (08fc-1a84) [LogonMonitor::MatchUserPolicyEvent] Assigned User Policy ActivityID {66AC35A1-01A5-45AD-95B9-A09506F7D934} to Session 16

2018-10-01T13:52:10.333 TRACE (08fc-1a84) [LogonMonitor::ProcessGroupPolicyEvent] Event Id: 4001, ActivityID: {66AC35A1-01A5-45AD-95B9-A09506F7D934}, Account: Company\Working, Session: 16

2018-10-01T13:52:10.333 TRACE (08fc-1a84) [LogonMonitor::ProcessGroupPolicyEvent] Event Id: 5326, ActivityID: {66AC35A1-01A5-45AD-95B9-A09506F7D934}, Account: , Session: 16

2018-10-01T13:52:10.333 INFO (08fc-1a84) [LogonMonitor::ProcessGroupPolicyEvent] Domain Controller Discovery Time: 0.50 seconds, Error Code: 0

2018-10-01T13:52:10.333 TRACE (08fc-1a84) [LogonMonitor::ProcessLogonEvent] Event Id: 2, Session: 16

2018-10-01T13:52:10.333 TRACE (08fc-1a84) [LogonMonitor::ProcessLogonEvent] Profile Finished. Session: 16

2018-10-01T13:52:10.333 TRACE (08fc-1a84) [LogonMonitor::ProcessLogonEvent] Event Id: 7, Session: 16

2018-10-01T13:52:10.333 TRACE (08fc-1a84) [LogonMonitor::ProcessLogonEvent] Profile Sync Finished. Session: 16

2018-10-01T13:52:10.333 TRACE (08fc-1a84) [LogonMonitor::ProcessLogonEvent] Event Id: 5, Session: 16

2018-10-01T13:52:10.333 INFO (08fc-1a84) [LogonMonitor::GetLogonStartTimeToHiveLoadedTime] Logon Start To Hive Loaded Time: 2.23 seconds. Session: 16

2018-10-01T13:52:10.333 INFO (08fc-1a84) [LogonMonitor::ProcessLogonEvent] Hive Loaded: File: C:\Users\Working\ntuser.dat, Key S-1-5-21-722834037-3924613360-632120474-3849. Session: 16

2018-10-01T13:52:10.333 TRACE (08fc-0a7c) [LogonMonitor::ProcessLogonEvent] Event Id: 5, Session: 16

2018-10-01T13:52:10.333 INFO (08fc-0a7c) [LogonMonitor::GetLogonStartTimeToClassesHiveLoadedTime] Logon Start To Classes Hive Loaded Time: 2.31 seconds. Session: 16

2018-10-01T13:52:10.333 INFO (08fc-0a7c) [LogonMonitor::ProcessLogonEvent] Classes Hive Loaded: File: C:\Users\Working\AppData\Local\Microsoft\Windows\\UsrClass.dat, Key S-1-5-21-722834037-3924613360-632120474-3849_Classes. Session: 16

2018-10-01T13:52:12.192 TRACE (08fc-1fe8) [SensSink::ProcessLogonEvent] Received Sens Logon: Username: Company\Working, Session: 16

2018-10-01T13:52:12.208 TRACE (08fc-1fe8) [LogonMonitor::SetShellLoadStartTime] Set Shell Load Start Time. Sessiond Id: 16

2018-10-01T13:52:12.301 INFO (08fc-1fe8) [SensSink::ProcessPostShellEvent] Received Sens PostShell: Username: Company\Working, Session: 16

2018-10-01T13:52:12.380 TRACE (08fc-0a7c) [LogonMonitor::ProcessGroupPolicyEvent] Event Id: 5327, ActivityID: {66AC35A1-01A5-45AD-95B9-A09506F7D934}, Account: , Session: 16

2018-10-01T13:52:12.380 INFO (08fc-0a7c) [LogonMonitor::ProcessGroupPolicyEvent] Network Bandwidth On One Connection: 0 kbps

2018-10-01T13:52:12.380 TRACE (08fc-0a7c) [LogonMonitor::ProcessGroupPolicyEvent] Event Id: 5314, ActivityID: {66AC35A1-01A5-45AD-95B9-A09506F7D934}, Account: , Session: 16

2018-10-01T13:52:12.380 INFO (08fc-0a7c) [LogonMonitor::ProcessGroupPolicyEvent] Network Bandwidth: 644598 kbps, Slow link Threshold: 500 kbps, Slow Link: False

2018-10-01T13:52:12.380 TRACE (08fc-0a7c) [LogonMonitor::ProcessGroupPolicyEvent] Event Id: 4016, ActivityID: {66AC35A1-01A5-45AD-95B9-A09506F7D934}, Account: , Session: 16

2018-10-01T13:52:12.380 TRACE (08fc-0a7c) [LogonMonitor::ProcessGroupPolicyEvent] Event Id: 5016, ActivityID: {66AC35A1-01A5-45AD-95B9-A09506F7D934}, Account: , Session: 16

2018-10-01T13:52:12.380 TRACE (08fc-0a7c) [LogonMonitor::ProcessGroupPolicyEvent] Event Id: 8001, ActivityID: {66AC35A1-01A5-45AD-95B9-A09506F7D934}, Account: Company\Working, Session: 16

2018-10-01T13:52:12.380 TRACE (08fc-0a7c) [LogonMonitor::ProcessUserPolicyEvent] User Policy Worker Started. Session: 16

2018-10-01T13:52:12.395 TRACE (08fc-0a7c) [LogonMonitor::ProcessGroupPolicyEvent] Event Id: 5327, ActivityID: {66AC35A1-01A5-45AD-95B9-A09506F7D934}, Account: , Session: 16

2018-10-01T13:52:12.395 INFO (08fc-0a7c) [LogonMonitor::ProcessGroupPolicyEvent] Network Bandwidth On One Connection: 644598 kbps

2018-10-01T13:52:12.395 TRACE (08fc-1f24) [LogonMonitor::UserPolicyEventWorker] About To Wait for Profile Load Event

2018-10-01T13:52:12.395 TRACE (08fc-1f24) [LogonMonitor::UserPolicyEventWorker] Wait for Profile Load Event Returned

2018-10-01T13:52:12.395 TRACE (08fc-1f24) [LogonMonitor::UserPolicyEventWorker] About To Wait for Shell Loaded Event

2018-10-01T13:52:12.395 TRACE (08fc-0a7c) [LogonMonitor::ProcessGroupPolicyEvent] Event Id: 4016, ActivityID: {66AC35A1-01A5-45AD-95B9-A09506F7D934}, Account: , Session: 16

2018-10-01T13:52:12.395 TRACE (08fc-0a7c) [LogonMonitor::ProcessGroupPolicyEvent] Event Id: 4016, ActivityID: {66AC35A1-01A5-45AD-95B9-A09506F7D934}, Account: , Session: 16

2018-10-01T13:52:12.395 TRACE (08fc-0a7c) [LogonMonitor::ProcessGroupPolicyEvent] Event Id: 4016, ActivityID: {66AC35A1-01A5-45AD-95B9-A09506F7D934}, Account: , Session: 16

2018-10-01T13:52:12.395 TRACE (08fc-0a7c) [LogonMonitor::ProcessGroupPolicyEvent] Event Id: 4016, ActivityID: {66AC35A1-01A5-45AD-95B9-A09506F7D934}, Account: , Session: 16

2018-10-01T13:52:12.395 TRACE (08fc-0a7c) [LogonMonitor::ProcessGroupPolicyEvent] Event Id: 4016, ActivityID: {66AC35A1-01A5-45AD-95B9-A09506F7D934}, Account: , Session: 16

2018-10-01T13:52:12.395 TRACE (08fc-0a7c) [LogonMonitor::ProcessGroupPolicyEvent] Event Id: 5016, ActivityID: {66AC35A1-01A5-45AD-95B9-A09506F7D934}, Account: , Session: 16

2018-10-01T13:52:12.395 TRACE (08fc-0a7c) [LogonMonitor::ProcessGroupPolicyEvent] Event Id: 5016, ActivityID: {66AC35A1-01A5-45AD-95B9-A09506F7D934}, Account: , Session: 16

2018-10-01T13:52:12.395 TRACE (08fc-0a7c) [LogonMonitor::ProcessGroupPolicyEvent] Event Id: 5016, ActivityID: {66AC35A1-01A5-45AD-95B9-A09506F7D934}, Account: , Session: 16

2018-10-01T13:52:12.395 TRACE (08fc-0a7c) [LogonMonitor::ProcessGroupPolicyEvent] Event Id: 5016, ActivityID: {66AC35A1-01A5-45AD-95B9-A09506F7D934}, Account: , Session: 16

2018-10-01T13:52:12.426 TRACE (08fc-0c48) [WMIEventSink::HandleProcessCreation] Process Started: Name: taskhost.exe, Process Id: 2924, Parent Process Id: 512, Session: 16

2018-10-01T13:52:12.442 TRACE (08fc-0c48) [WMIEventSink::HandleProcessCreation] Process Started: Name: TPAutoConnect.exe, Process Id: 4716, Parent Process Id: 1464, Session: 16

2018-10-01T13:52:12.442 TRACE (08fc-0c48) [WMIEventSink::HandleProcessCreation] Process Started: Name: EOSNotify.exe, Process Id: 4720, Parent Process Id: 512, Session: 16

2018-10-01T13:52:12.442 TRACE (08fc-0c48) [WMIEventSink::HandleProcessCreation] Process Started: Name: conhost.exe, Process Id: 5400, Parent Process Id: 4884, Session: 16

2018-10-01T13:52:12.442 TRACE (08fc-0c48) [WMIEventSink::HandleProcessCreation] Process Started: Name: taskeng.exe, Process Id: 6752, Parent Process Id: 972, Session: 16

2018-10-01T13:52:13.301 TRACE (08fc-0c64) [LogonMonitor::ShellLoadWorker] Found Taskbar. Session: 16

2018-10-01T13:52:13.301 TRACE (08fc-0c64) [LogonMonitor::SetShellLoadEndTime] Set Shell Load End Time. Session: 16

2018-10-01T13:52:13.301 TRACE (08fc-1f24) [LogonMonitor::UserPolicyEventWorker] Wait for Shell Loaded Event Returned

2018-10-01T13:52:13.301 TRACE (08fc-0c64) [LogonMonitor::GetUserProfileType] User Profile Type (2): Roaming. Session: 16

2018-10-01T13:52:13.301 TRACE (08fc-0c64) [LogonMonitor::GetUserProfilePath] Local Profile Path: C:\Users\Working. Session: 16

2018-10-01T13:52:13.301 TRACE (08fc-0c64) [LogonMonitor::GetUserProfilePath] Key Path: SOFTWARE\Microsoft\Windows NT\CurrentVersion\ProfileList\S-1-5-21-722834037-3924613360-632120474-3849. Session: 16

2018-10-01T13:52:13.301 TRACE (08fc-0c64) [LogonMonitor::GetUserProfilePath] Romaing Profile Path: \\Company-VSRV-DC\Personas\Working.Company.V2. Session: 16

2018-10-01T13:52:13.301 TRACE (08fc-1f24) [LogonMonitor::StopWMIEventSink] WMI Event Sink Stopped, Session: 16

2018-10-01T13:52:13.426 TRACE (08fc-1f24) [LogonMonitor::StopSensEventSink] SENS Event Sink Stopped, Session: 16

2018-10-01T13:52:13.426 TRACE (08fc-1f24) [LogonMonitor::SetLogonEndTime] Set Logon End Time. Session: 16

2018-10-01T13:52:13.426 INFO (08fc-1f24) [LogonMonitor::GetSessionStartToLogonStartTime] Session Start To Logon Time: 21.22 seconds, Session: 16

2018-10-01T13:52:13.426 INFO (08fc-1f24) [LogonMonitor::GetShellLoadTime] Shell Load Time: 1.09 seconds. Session: 16

2018-10-01T13:52:13.426 INFO (08fc-1f24) [LogonMonitor::GetWFRApplyTime] Windows Folder Redirection Apply Time: 0.00 seconds. Session: 16

2018-10-01T13:52:13.426 INFO (08fc-1f24) [LogonMonitor::GetProfileSyncTime] Profile Sync Time: 0.00 seconds. Session: 16

2018-10-01T13:52:13.426 INFO (08fc-1f24) [LogonMonitor::GetMachineGPOTime] Machine Policy Time: 0 seconds. Session: 16

2018-10-01T13:52:13.426 INFO (08fc-1f24) [LogonMonitor::GetUserGPOTime] Group Policy Software Installation Processing Asynchronous: True, Sessiond: 16

2018-10-01T13:52:13.426 INFO (08fc-1f24) [LogonMonitor::GetUserGPOTime] GPO List Changed: False, Session: 16

2018-10-01T13:52:13.426 INFO (08fc-1f24) [LogonMonitor::GetUserGPOTime] Group Policy Software Installation Time: 0.14 seconds, Error Code: 0, Session: 16

2018-10-01T13:52:13.426 INFO (08fc-1f24) [LogonMonitor::GetUserGPOTime] User Policy Time: 2 seconds. Session: 16

2018-10-01T13:52:13.426 TRACE (08fc-1f24) [LogonMonitor::IsGPLogonScriptSynchronous] Computer: Run these programs at user logon: Not Configured

2018-10-01T13:52:13.426 TRACE (08fc-1f24) [LogonMonitor::IsGPLogonScriptSynchronous] User: Run these programs at user logon: Not Configured

2018-10-01T13:52:13.426 INFO (08fc-1f24) [LogonMonitor::IsGPLogonScriptSynchronous] Group Policy Logon Scripts Are Asynchronous

2018-10-01T13:52:13.426 INFO (08fc-1f24) [LogonMonitor::GetGPLogonScriptTime] Group Policy Logon Script Time: 0.00 Seconds

2018-10-01T13:52:13.426 INFO (08fc-1f24) [LogonMonitor::GetGPLogonScriptTime] Group Policy PowerShell Logon Script Time: 0.00 Seconds

2018-10-01T13:52:13.426 INFO (08fc-1f24) [LogonMonitor::GetGPLogonScriptTime] Total Group Policy Logon Script Time: 0.00 Seconds

2018-10-01T13:52:13.426 INFO (08fc-1f24) [LogonMonitor::CheckGroupPolicySettings] Always wait for the network at computer start and logon: Not Configured

2018-10-01T13:52:13.426 INFO (08fc-1f24) [LogonMonitor::CheckGroupPolicySettings] Machine: Run these programs at user logon: Not Configured

2018-10-01T13:52:13.426 INFO (08fc-1f24) [LogonMonitor::CheckGroupPolicySettings] User: Run these programs at user logon: Not Configured

2018-10-01T13:52:13.426 INFO (08fc-1f24) [LogonMonitor::CheckGroupPolicySettings] Wait for remote user profile: Not Configured

2018-10-01T13:52:13.426 INFO (08fc-1f24) [LogonMonitor::CheckGroupPolicySettings] Set maximum wait time for network if a user has a roaming profile or remote home directory: Not Configured

2018-10-01T13:52:13.426 INFO (08fc-1f24) [LogonMonitor::CheckGroupPolicySettings] Specify network directories to sync at logon, logoff time only: Not Configured

2018-10-01T13:52:13.426 TRACE (08fc-1f24) [LogonMonitor::UserPolicyEventWorker] About to Wait For Shell Load Worker

2018-10-01T13:52:14.029 INFO (08fc-0c64) [LogonMonitor::LogProfileSize] Profile Size: 97.40MB, Files: 687, Folders: 482. Session: 16

2018-10-01T13:52:14.029 INFO (08fc-0c64) [LogonMonitor::LogProfileSize] File Size Distribution For Session 16:

2018-10-01T13:52:14.029 INFO (08fc-0c64) [LogonMonitor::LogProfileSize]   0 to < 1MB: 666

2018-10-01T13:52:14.029 INFO (08fc-0c64) [LogonMonitor::LogProfileSize]   1MB to < 10MB: 20

2018-10-01T13:52:14.029 INFO (08fc-0c64) [LogonMonitor::LogProfileSize]   10MB to < 100MB: 1

2018-10-01T13:52:14.029 INFO (08fc-0c64) [LogonMonitor::LogProfileSize]   100MB to < 1GB: 0

2018-10-01T13:52:14.029 INFO (08fc-0c64) [LogonMonitor::LogProfileSize]   1GB to < 10GB: 0

2018-10-01T13:52:14.029 INFO (08fc-0c64) [LogonMonitor::LogProfileSize]   >= 10GB: 0

2018-10-01T13:52:14.030 INFO (08fc-0c64) [LogonMonitor::GetDiskMetrics] Disk Space Metrics For User Profile Volume:

2018-10-01T13:52:14.030 INFO (08fc-0c64) [LogonMonitor::GetDiskMetrics] Disk Space Available To User: 91 GB

2018-10-01T13:52:14.030 INFO (08fc-0c64) [LogonMonitor::GetDiskMetrics] Free Disk Space: 91 GB

2018-10-01T13:52:14.030 INFO (08fc-0c64) [LogonMonitor::GetDiskMetrics] Total Disk Space: 119 GB

2018-10-01T13:52:14.030 TRACE (08fc-0c64) [LogonMonitor::ShellLoadWorker] Shell Load Monitor Exiting. Session: 16

2018-10-01T13:52:14.030 TRACE (08fc-1f24) [LogonMonitor::UserPolicyEventWorker] Wait for Shell Load Worker Returned

2018-10-01T13:52:14.031 INFO (08fc-1f24) [LogonMonitor::GetLogonTime] Logon Time: 6.13 seconds, Session: 16

2018-10-01T13:52:14.043 DEBUG (08fc-1f24) [LogonMonitor::PostToView] Broadcast timings to View Agent, SessionId: 16

2018-10-01T13:52:14.043 INFO (08fc-1f24) [LogonMonitor::LogSummary] ****************** Session Summary (User: Company\Working, Session: 16) *****************

2018-10-01T13:52:14.043 INFO (08fc-1f24) [LogonMonitor::LogSummary] Logon Time: 6.13 seconds

2018-10-01T13:52:14.043 INFO (08fc-1f24) [LogonMonitor::LogSummary] Logon Start To Hive Loaded Time: 2.23 seconds

2018-10-01T13:52:14.043 INFO (08fc-1f24) [LogonMonitor::LogSummary] Logon Start To Classes Hive Loaded Time: 2.31 seconds

2018-10-01T13:52:14.043 INFO (08fc-1f24) [LogonMonitor::LogSummary] Profile Sync Time: 0.00 seconds

2018-10-01T13:52:14.043 INFO (08fc-1f24) [LogonMonitor::LogSummary] Windows Folder Redirection Apply Time: 0.00 seconds

2018-10-01T13:52:14.043 INFO (08fc-1f24) [LogonMonitor::LogSummary] Shell Load Time: 1.09 seconds

2018-10-01T13:52:14.043 INFO (08fc-1f24) [LogonMonitor::LogSummary] Total Logon Script Time: 0.00 seconds

2018-10-01T13:52:14.043 INFO (08fc-1f24) [LogonMonitor::LogSummary] User Policy Apply Time: 2 seconds

2018-10-01T13:52:14.043 INFO (08fc-1f24) [LogonMonitor::LogSummary] Machine Policy Apply Time: 0 seconds

2018-10-01T13:52:14.044 INFO (08fc-1f24) [LogonMonitor::LogSummary] Group Policy Software Install Time: 0.14 seconds

2018-10-01T13:52:14.044 INFO (08fc-1f24) [LogonMonitor::LogSummary] Free Disk Space Available To User: 91 GB

2018-10-01T13:52:14.044 INFO (08fc-1f24) [LogonMonitor::LogSummary] ***********************************************************************************

 

 

 

 

 

Affected User:

2018-10-01T13:36:05.332 TRACE (08fc-1ab4) [VMWLogSettings] Log Level: 0x1F

2018-10-01T13:36:05.332 TRACE (08fc-1ab4) [VMWLogSettings] Log History Depth: 10

2018-10-01T13:36:05.332 TRACE (08fc-1ab4) [VMWLogSettings] Log Path: \\?\C:\ProgramData\VMWare\VMware Logon Monitor\Logs

2018-10-01T13:36:05.332 TRACE (08fc-1ab4) [VMWLogSettings] Main Log Path: \\?\C:\ProgramData\VMWare\VMware Logon Monitor\Logs\vmlm.txt

2018-10-01T13:36:05.332 TRACE (08fc-1ab4) [VMWLogSettings] Main Log Max Size: 100000000

2018-10-01T13:36:05.332 TRACE (08fc-1ab4) [VMWLogSettings] Main Log Keep Days: 7

2018-10-01T13:36:05.332 TRACE (08fc-1ab4) [VMWLogSettings] Remote Log Path:

2018-10-01T13:36:05.332 TRACE (08fc-1ab4) [VMWLogSettings] Data Dir: \\?\C:\ProgramData\VMWare\VMware Logon Monitor\Data

2018-10-01T13:36:05.332 TRACE (08fc-1ab4) [VMWLogSettings] Flags: 0x3

2018-10-01T13:36:05.332 TRACE (08fc-1ab4) [VMWLogSettings] Computer Name: Company-CNCG-BK2

2018-10-01T13:36:05.332 TRACE (08fc-1ab4) [VMWLogSettings] FQDN: Company-CNCG-BK2.ad.Company.org

2018-10-01T13:36:05.332 INFO (08fc-1ab4) [VMWLogIpAddresses] Friendly Name: Local Area Connection

2018-10-01T13:36:05.332 INFO (08fc-1ab4) [VMWLogIpAddresses] IP Address: 10.10.10.155

2018-10-01T13:36:05.332 INFO (08fc-1ab4) [VMWLogIpAddresses] Dns Server Address[0]: 10.10.10.10

2018-10-01T13:36:05.363 TRACE (08fc-1ab4) [LogonMonitor::StartWMIEventSink] CPU monitoring is not enabled

2018-10-01T13:36:05.363 TRACE (08fc-1ab4) [LogonMonitor::StartWMIEventSink] Memory monitoring is not enabled

2018-10-01T13:36:05.379 TRACE (08fc-1ab4) [LogonMonitor::StartWMIEventSink] Registered For Process Creation Events

2018-10-01T13:36:05.394 TRACE (08fc-1ab4) [LogonMonitor::StartWMIEventSink] Registered For Process Termination Events

2018-10-01T13:36:05.394 TRACE (08fc-1ab4) [LogonMonitor::StartWMIEventSink] WMI Event Sink Started Successfully: Session: 15

2018-10-01T13:36:05.488 TRACE (08fc-1ab4) [LogonMonitor::StartSensEventSink] SENS Event Sink Started Successfully, Session: 15

2018-10-01T13:36:05.488 TRACE (08fc-1ab4) [LogonMonitor::IsUserAlreadyLoggedOn] Failed to query user token for session: 0x800703F0, Session: 0

2018-10-01T13:36:05.488 TRACE (08fc-1ab4) [LogonMonitor::IsUserAlreadyLoggedOn] Failed to query user token for session: 0x80070002, Session: 65536

2018-10-01T13:36:05.488 TRACE (08fc-1ab4) [LogonMonitor::UpdateSessionContext] AuthId: (0x0,0x123FE54B). Session: 15

2018-10-01T13:36:05.488 TRACE (08fc-1ab4) [LogonMonitor::IsRemoteSessionShellExplorer] Session is local,  SessionGuid: 39abee6d-96b9-4694-a001-e2cea6d02a63, Session: 15

2018-10-01T13:36:05.488 TRACE (08fc-1ab4) [LogonMonitor::StartShellLoadMonitor] Shell Load Monitor Started. Session: 15

2018-10-01T13:36:05.488 INFO (08fc-1ab4) [LogonMonitor::Logon] LOGON: User: Company\affected, Session: 15

2018-10-01T13:43:33.331 INFO (08fc-1e44) [LogonMonitor::MatchUserPolicyEvent] Assigned User Policy ActivityID {529C4488-CFD4-4B3F-BBF7-213A33324D3B} to Session 15

2018-10-01T13:43:33.331 TRACE (08fc-1b84) [LogonMonitor::ProcessLogonEvent] Event Id: 1, Session: 15

2018-10-01T13:43:33.331 TRACE (08fc-1b84) [LogonMonitor::ProcessLogonEvent] Profile Started. Session: 15

2018-10-01T13:43:33.331 TRACE (08fc-1e44) [LogonMonitor::ProcessGroupPolicyEvent] Event Id: 4001, ActivityID: {529C4488-CFD4-4B3F-BBF7-213A33324D3B}, Account: Company\affected, Session: 15

2018-10-01T13:43:33.331 TRACE (08fc-1b84) [LogonMonitor::ProcessLogonEvent] Event Id: 6, Session: 15

2018-10-01T13:43:33.331 TRACE (08fc-1b84) [LogonMonitor::ProcessLogonEvent] Profile Sync Started. Session: 15

2018-10-01T13:43:33.331 TRACE (08fc-1a00) [LogonMonitor::ProcessGroupPolicyEvent] Event Id: 5326, ActivityID: {529C4488-CFD4-4B3F-BBF7-213A33324D3B}, Account: , Session: 15

2018-10-01T13:43:33.331 INFO (08fc-1a00) [LogonMonitor::ProcessGroupPolicyEvent] Domain Controller Discovery Time: 0.50 seconds, Error Code: 0

2018-10-01T13:43:33.331 TRACE (08fc-1b84) [LogonMonitor::ProcessLogonEvent] Event Id: 5, Session: 15

2018-10-01T13:43:33.331 INFO (08fc-1b84) [LogonMonitor::GetLogonStartTimeToHiveLoadedTime] Logon Start To Hive Loaded Time: 446.94 seconds. Session: 15

2018-10-01T13:43:33.331 INFO (08fc-1b84) [LogonMonitor::ProcessLogonEvent] Hive Loaded: File: C:\Users\affected\ntuser.dat, Key S-1-5-21-722834037-3924613360-632120474-1406. Session: 15

2018-10-01T13:43:33.331 TRACE (08fc-1a00) [LogonMonitor::ProcessLogonEvent] Event Id: 2, Session: 15

2018-10-01T13:43:33.331 TRACE (08fc-1a00) [LogonMonitor::ProcessLogonEvent] Profile Finished. Session: 15

2018-10-01T13:43:33.331 TRACE (08fc-1e44) [LogonMonitor::ProcessLogonEvent] Event Id: 7, Session: 15

2018-10-01T13:43:33.331 TRACE (08fc-1e44) [LogonMonitor::ProcessLogonEvent] Profile Sync Finished. Session: 15

2018-10-01T13:43:33.331 TRACE (08fc-1a00) [LogonMonitor::ProcessLogonEvent] Event Id: 5, Session: 15

2018-10-01T13:43:33.331 INFO (08fc-1a00) [LogonMonitor::GetLogonStartTimeToClassesHiveLoadedTime] Logon Start To Classes Hive Loaded Time: 446.98 seconds. Session: 15

2018-10-01T13:43:33.331 INFO (08fc-1a00) [LogonMonitor::ProcessLogonEvent] Classes Hive Loaded: File: C:\Users\affected\AppData\Local\Microsoft\Windows\\UsrClass.dat, Key S-1-5-21-722834037-3924613360-632120474-1406_Classes. Session: 15

2018-10-01T13:43:34.831 TRACE (08fc-1958) [SensSink::ProcessLogonEvent] Received Sens Logon: Username: Company\affected, Session: 15

2018-10-01T13:43:34.831 TRACE (08fc-1958) [LogonMonitor::SetShellLoadStartTime] Set Shell Load Start Time. Sessiond Id: 15

2018-10-01T13:43:34.847 INFO (08fc-1c3c) [SensSink::ProcessPostShellEvent] Received Sens PostShell: Username: Company\affected, Session: 15

2018-10-01T13:43:35.316 TRACE (08fc-1a00) [LogonMonitor::ProcessGroupPolicyEvent] Event Id: 5327, ActivityID: {529C4488-CFD4-4B3F-BBF7-213A33324D3B}, Account: , Session: 15

2018-10-01T13:43:35.316 INFO (08fc-1a00) [LogonMonitor::ProcessGroupPolicyEvent] Network Bandwidth On One Connection: 0 kbps

2018-10-01T13:43:35.316 TRACE (08fc-1b6c) [LogonMonitor::ProcessGroupPolicyEvent] Event Id: 5314, ActivityID: {529C4488-CFD4-4B3F-BBF7-213A33324D3B}, Account: , Session: 15

2018-10-01T13:43:35.316 INFO (08fc-1b6c) [LogonMonitor::ProcessGroupPolicyEvent] Network Bandwidth: 402128 kbps, Slow link Threshold: 500 kbps, Slow Link: False

2018-10-01T13:43:35.316 TRACE (08fc-16dc) [LogonMonitor::ProcessGroupPolicyEvent] Event Id: 5016, ActivityID: {529C4488-CFD4-4B3F-BBF7-213A33324D3B}, Account: , Session: 15

2018-10-01T13:43:35.316 TRACE (08fc-1e44) [LogonMonitor::ProcessGroupPolicyEvent] Event Id: 8001, ActivityID: {529C4488-CFD4-4B3F-BBF7-213A33324D3B}, Account: Company\affected, Session: 15

2018-10-01T13:43:35.316 TRACE (08fc-1e44) [LogonMonitor::ProcessUserPolicyEvent] User Policy Worker Started. Session: 15

2018-10-01T13:43:35.316 TRACE (08fc-1b84) [LogonMonitor::ProcessGroupPolicyEvent] Event Id: 4016, ActivityID: {529C4488-CFD4-4B3F-BBF7-213A33324D3B}, Account: , Session: 15

2018-10-01T13:43:35.409 TRACE (08fc-0ca8) [LogonMonitor::UserPolicyEventWorker] About To Wait for Profile Load Event

2018-10-01T13:43:35.409 TRACE (08fc-0ca8) [LogonMonitor::UserPolicyEventWorker] Wait for Profile Load Event Returned

2018-10-01T13:43:35.409 TRACE (08fc-0ca8) [LogonMonitor::UserPolicyEventWorker] About To Wait for Shell Loaded Event

2018-10-01T13:43:35.425 TRACE (08fc-1b84) [LogonMonitor::ProcessGroupPolicyEvent] Event Id: 5327, ActivityID: {529C4488-CFD4-4B3F-BBF7-213A33324D3B}, Account: , Session: 15

2018-10-01T13:43:35.425 INFO (08fc-1b84) [LogonMonitor::ProcessGroupPolicyEvent] Network Bandwidth On One Connection: 402128 kbps

2018-10-01T13:43:35.456 TRACE (08fc-1b84) [LogonMonitor::ProcessGroupPolicyEvent] Event Id: 5016, ActivityID: {529C4488-CFD4-4B3F-BBF7-213A33324D3B}, Account: , Session: 15

2018-10-01T13:43:35.456 TRACE (08fc-1b84) [LogonMonitor::ProcessGroupPolicyEvent] Event Id: 5016, ActivityID: {529C4488-CFD4-4B3F-BBF7-213A33324D3B}, Account: , Session: 15

2018-10-01T13:43:35.456 TRACE (08fc-1b84) [LogonMonitor::ProcessGroupPolicyEvent] Event Id: 5016, ActivityID: {529C4488-CFD4-4B3F-BBF7-213A33324D3B}, Account: , Session: 15

2018-10-01T13:43:35.456 TRACE (08fc-1b84) [LogonMonitor::ProcessGroupPolicyEvent] Event Id: 5016, ActivityID: {529C4488-CFD4-4B3F-BBF7-213A33324D3B}, Account: , Session: 15

2018-10-01T13:43:35.456 TRACE (08fc-1e44) [LogonMonitor::ProcessGroupPolicyEvent] Event Id: 4016, ActivityID: {529C4488-CFD4-4B3F-BBF7-213A33324D3B}, Account: , Session: 15

2018-10-01T13:43:35.456 TRACE (08fc-1e44) [LogonMonitor::ProcessGroupPolicyEvent] Event Id: 4016, ActivityID: {529C4488-CFD4-4B3F-BBF7-213A33324D3B}, Account: , Session: 15

2018-10-01T13:43:35.456 TRACE (08fc-1e44) [LogonMonitor::ProcessGroupPolicyEvent] Event Id: 4016, ActivityID: {529C4488-CFD4-4B3F-BBF7-213A33324D3B}, Account: , Session: 15

2018-10-01T13:43:35.456 TRACE (08fc-1e44) [LogonMonitor::ProcessGroupPolicyEvent] Event Id: 4016, ActivityID: {529C4488-CFD4-4B3F-BBF7-213A33324D3B}, Account: , Session: 15

2018-10-01T13:43:35.472 TRACE (08fc-1c1c) [WMIEventSink::HandleProcessCreation] Process Started: Name: TPAutoConnect.exe, Process Id: 3892, Parent Process Id: 1464, Session: 15

2018-10-01T13:43:35.472 TRACE (08fc-1c1c) [WMIEventSink::HandleProcessCreation] Process Started: Name: conhost.exe, Process Id: 6472, Parent Process Id: 4380, Session: 15

2018-10-01T13:43:35.472 TRACE (08fc-1c1c) [WMIEventSink::HandleProcessCreation] Process Started: Name: taskhost.exe, Process Id: 6916, Parent Process Id: 512, Session: 15

2018-10-01T13:43:35.472 TRACE (08fc-1c1c) [WMIEventSink::HandleProcessCreation] Process Started: Name: taskeng.exe, Process Id: 8040, Parent Process Id: 972, Session: 15

2018-10-01T13:43:51.802 TRACE (08fc-1c1c) [WMIEventSink::HandleProcessCreation] Process Started: Name: vmlm_helper.exe, Process Id: 1636, Parent Process Id: 6692, Session: 15

2018-10-01T13:43:51.802 TRACE (08fc-1c1c) [WMIEventSink::HandleProcessCreation] Process Started: Name: vmwAgent.exe, Process Id: 3460, Parent Process Id: 416, Session: 15

2018-10-01T13:43:51.802 TRACE (08fc-1c1c) [WMIEventSink::HandleProcessCreation] Process Started: Name: explorer.exe, Process Id: 4372, Parent Process Id: 7360, Session: 15

2018-10-01T13:43:51.802 TRACE (08fc-1c1c) [WMIEventSink::HandleProcessCreation] Process Started: Name: conhost.exe, Process Id: 4532, Parent Process Id: 4380, Session: 15

2018-10-01T13:43:51.802 TRACE (08fc-1c1c) [WMIEventSink::HandleProcessCreation] Process Started: Name: wssm.exe, Process Id: 6092, Parent Process Id: 6692, Session: 15

2018-10-01T13:43:51.802 TRACE (08fc-1c1c) [WMIEventSink::HandleProcessCreation] Process Started: Name: userinit.exe, Process Id: 7360, Parent Process Id: 6692, Session: 15

2018-10-01T13:43:51.849 TRACE (08fc-15b4) [LogonMonitor::ShellLoadWorker] Found Taskbar. Session: 15

2018-10-01T13:43:51.849 TRACE (08fc-15b4) [LogonMonitor::SetShellLoadEndTime] Set Shell Load End Time. Session: 15

2018-10-01T13:43:51.849 TRACE (08fc-15b4) [LogonMonitor::GetUserProfileType] User Profile Type (2): Roaming. Session: 15

2018-10-01T13:43:51.849 TRACE (08fc-15b4) [LogonMonitor::GetUserProfilePath] Local Profile Path: C:\Users\affected. Session: 15

2018-10-01T13:43:51.849 TRACE (08fc-15b4) [LogonMonitor::GetUserProfilePath] Key Path: SOFTWARE\Microsoft\Windows NT\CurrentVersion\ProfileList\S-1-5-21-722834037-3924613360-632120474-1406. Session: 15

2018-10-01T13:43:51.849 TRACE (08fc-15b4) [LogonMonitor::GetUserProfilePath] Romaing Profile Path: \\Company-VSRV-DC\Personas\affected.Company.V2. Session: 15

2018-10-01T13:43:51.849 TRACE (08fc-0ca8) [LogonMonitor::UserPolicyEventWorker] Wait for Shell Loaded Event Returned

2018-10-01T13:43:51.849 TRACE (08fc-0ca8) [LogonMonitor::StopWMIEventSink] WMI Event Sink Stopped, Session: 15

2018-10-01T13:43:51.974 TRACE (08fc-0ca8) [LogonMonitor::StopSensEventSink] SENS Event Sink Stopped, Session: 15

2018-10-01T13:43:51.974 TRACE (08fc-0ca8) [LogonMonitor::SetLogonEndTime] Set Logon End Time. Session: 15

2018-10-01T13:43:51.974 INFO (08fc-0ca8) [LogonMonitor::GetSessionStartToLogonStartTime] Session Start To Logon Time: 30.89 seconds, Session: 15

2018-10-01T13:43:51.974 INFO (08fc-0ca8) [LogonMonitor::GetShellLoadTime] Shell Load Time: 17.02 seconds. Session: 15

2018-10-01T13:43:51.974 INFO (08fc-0ca8) [LogonMonitor::GetWFRApplyTime] Windows Folder Redirection Apply Time: 0.00 seconds. Session: 15

2018-10-01T13:43:51.974 INFO (08fc-0ca8) [LogonMonitor::GetProfileSyncTime] Profile Sync Time: 0.00 seconds. Session: 15

2018-10-01T13:43:51.974 INFO (08fc-0ca8) [LogonMonitor::GetMachineGPOTime] Machine Policy Time: 0 seconds. Session: 15

2018-10-01T13:43:51.974 INFO (08fc-0ca8) [LogonMonitor::GetUserGPOTime] Group Policy Software Installation Processing Asynchronous: True, Sessiond: 15

2018-10-01T13:43:51.974 INFO (08fc-0ca8) [LogonMonitor::GetUserGPOTime] GPO List Changed: False, Session: 15

2018-10-01T13:43:51.974 INFO (08fc-0ca8) [LogonMonitor::GetUserGPOTime] Group Policy Software Installation Time: 0.13 seconds, Error Code: 0, Session: 15

2018-10-01T13:43:51.974 INFO (08fc-0ca8) [LogonMonitor::GetUserGPOTime] User Policy Time: 2 seconds. Session: 15

2018-10-01T13:43:51.974 TRACE (08fc-0ca8) [LogonMonitor::IsGPLogonScriptSynchronous] Computer: Run these programs at user logon: Not Configured

2018-10-01T13:43:51.974 TRACE (08fc-0ca8) [LogonMonitor::IsGPLogonScriptSynchronous] User: Run these programs at user logon: Not Configured

2018-10-01T13:43:51.974 INFO (08fc-0ca8) [LogonMonitor::IsGPLogonScriptSynchronous] Group Policy Logon Scripts Are Asynchronous

2018-10-01T13:43:51.974 INFO (08fc-0ca8) [LogonMonitor::GetGPLogonScriptTime] Group Policy Logon Script Time: 0.00 Seconds

2018-10-01T13:43:51.974 INFO (08fc-0ca8) [LogonMonitor::GetGPLogonScriptTime] Group Policy PowerShell Logon Script Time: 0.00 Seconds

2018-10-01T13:43:51.974 INFO (08fc-0ca8) [LogonMonitor::GetGPLogonScriptTime] Total Group Policy Logon Script Time: 0.00 Seconds

2018-10-01T13:43:51.974 INFO (08fc-0ca8) [LogonMonitor::CheckGroupPolicySettings] Always wait for the network at computer start and logon: Not Configured

2018-10-01T13:43:51.974 INFO (08fc-0ca8) [LogonMonitor::CheckGroupPolicySettings] Machine: Run these programs at user logon: Not Configured

2018-10-01T13:43:51.974 INFO (08fc-0ca8) [LogonMonitor::CheckGroupPolicySettings] User: Run these programs at user logon: Not Configured

2018-10-01T13:43:51.974 INFO (08fc-0ca8) [LogonMonitor::CheckGroupPolicySettings] Wait for remote user profile: Not Configured

2018-10-01T13:43:51.974 INFO (08fc-0ca8) [LogonMonitor::CheckGroupPolicySettings] Set maximum wait time for network if a user has a roaming profile or remote home directory: Not Configured

2018-10-01T13:43:51.974 INFO (08fc-0ca8) [LogonMonitor::CheckGroupPolicySettings] Specify network directories to sync at logon, logoff time only: Not Configured

2018-10-01T13:43:51.974 TRACE (08fc-0ca8) [LogonMonitor::UserPolicyEventWorker] About to Wait For Shell Load Worker

2018-10-01T13:43:53.028 INFO (08fc-15b4) [LogonMonitor::LogProfileSize] Profile Size: 698.44MB, Files: 44827, Folders: 901. Session: 15

2018-10-01T13:43:53.028 INFO (08fc-15b4) [LogonMonitor::LogProfileSize] File Size Distribution For Session 15:

2018-10-01T13:43:53.028 INFO (08fc-15b4) [LogonMonitor::LogProfileSize]   0 to < 1MB: 44712

2018-10-01T13:43:53.028 INFO (08fc-15b4) [LogonMonitor::LogProfileSize]   1MB to < 10MB: 112

2018-10-01T13:43:53.028 INFO (08fc-15b4) [LogonMonitor::LogProfileSize]   10MB to < 100MB: 3

2018-10-01T13:43:53.028 INFO (08fc-15b4) [LogonMonitor::LogProfileSize]   100MB to < 1GB: 0

2018-10-01T13:43:53.028 INFO (08fc-15b4) [LogonMonitor::LogProfileSize]   1GB to < 10GB: 0

2018-10-01T13:43:53.028 INFO (08fc-15b4) [LogonMonitor::LogProfileSize]   >= 10GB: 0

2018-10-01T13:43:53.029 INFO (08fc-15b4) [LogonMonitor::GetDiskMetrics] Disk Space Metrics For User Profile Volume:

2018-10-01T13:43:53.029 INFO (08fc-15b4) [LogonMonitor::GetDiskMetrics] Disk Space Available To User: 91 GB

2018-10-01T13:43:53.029 INFO (08fc-15b4) [LogonMonitor::GetDiskMetrics] Free Disk Space: 91 GB

2018-10-01T13:43:53.029 INFO (08fc-15b4) [LogonMonitor::GetDiskMetrics] Total Disk Space: 119 GB

2018-10-01T13:43:53.029 TRACE (08fc-15b4) [LogonMonitor::ShellLoadWorker] Shell Load Monitor Exiting. Session: 15

2018-10-01T13:43:53.029 TRACE (08fc-0ca8) [LogonMonitor::UserPolicyEventWorker] Wait for Shell Load Worker Returned

2018-10-01T13:43:53.029 INFO (08fc-0ca8) [LogonMonitor::GetLogonTime] Logon Time: 466.64 seconds, Session: 15

2018-10-01T13:43:53.041 DEBUG (08fc-0ca8) [LogonMonitor::PostToView] Broadcast timings to View Agent, SessionId: 15

2018-10-01T13:43:53.041 INFO (08fc-0ca8) [LogonMonitor::LogSummary] ****************** Session Summary (User: Company\affected, Session: 15) *****************

2018-10-01T13:43:53.041 INFO (08fc-0ca8) [LogonMonitor::LogSummary] Logon Time: 466.64 seconds

2018-10-01T13:43:53.041 INFO (08fc-0ca8) [LogonMonitor::LogSummary] Logon Start To Hive Loaded Time: 446.94 seconds

2018-10-01T13:43:53.041 INFO (08fc-0ca8) [LogonMonitor::LogSummary] Logon Start To Classes Hive Loaded Time: 446.98 seconds

2018-10-01T13:43:53.041 INFO (08fc-0ca8) [LogonMonitor::LogSummary] Profile Sync Time: 0.00 seconds

2018-10-01T13:43:53.041 INFO (08fc-0ca8) [LogonMonitor::LogSummary] Windows Folder Redirection Apply Time: 0.00 seconds

2018-10-01T13:43:53.041 INFO (08fc-0ca8) [LogonMonitor::LogSummary] Shell Load Time: 17.02 seconds

2018-10-01T13:43:53.041 INFO (08fc-0ca8) [LogonMonitor::LogSummary] Total Logon Script Time: 0.00 seconds

2018-10-01T13:43:53.041 INFO (08fc-0ca8) [LogonMonitor::LogSummary] User Policy Apply Time: 2 seconds

2018-10-01T13:43:53.041 INFO (08fc-0ca8) [LogonMonitor::LogSummary] Machine Policy Apply Time: 0 seconds

2018-10-01T13:43:53.041 INFO (08fc-0ca8) [LogonMonitor::LogSummary] Group Policy Software Install Time: 0.13 seconds

2018-10-01T13:43:53.041 INFO (08fc-0ca8) [LogonMonitor::LogSummary] Free Disk Space Available To User: 91 GB

2018-10-01T13:43:53.041 INFO (08fc-0ca8) [LogonMonitor::LogSummary] ************************************************************************************

 

 

Thank you for your help!


ESXI 6.5 Loss of all networking connection (hardware install)

$
0
0

Hey

 

I have an ESXi 6.5 install that works just fine, but sometimes it just kicks me out of the web client and I can't even ping the box until I restart from the hardware. This event seems to happen when I am changing network settings for VMs, I am not changing any network settings that would impair connection to my ESXi box.

 

I have also had this same problem happen on a completely different install and hardware.

 

any help would be appreciated.

HAproxy loadbalancer and View 6.1.1

$
0
0

Hi All,

 

I'm running 2 Vmware View connection servers and 2 HAproxy's (version 1.5.15)  as loadbalancer in high availability.

Are there any members on this community know how i can redirect HTTPS correct thru HAproxy ?

 

When I use the balance option : balance source

No problems what so ever, but then the load isn't shared like round robin.

 

But when i choose as balance option: round robin

we notice error upon connecting to the connection servers: Your session has expired. Please re-connect the server.

 

This is due to session sticky i can't get to work.

All I want is to redirect the traffic TCP based (straight redirection) and the connections evenly directed based like round robin.

 

The config for HTTPS in HAproxy is:

 

 

listen https ***SOME VIRTUAL IP***:443

        mode tcp

        option tcplog

        option ssl-hello-chk

        balance roundrobin stick store-request src

        stick-table type ip size 200k expire 30m

        option srvtcpka

        server SERVERNAME1 IP1:443 check

        server SERVERNAME2 IP2:443 check

 

Cant find any solution regarding HAproxy and round robin. Anyone succeeded this ?

Also posted this on HAproxy forums but was wondering had this working correct.

 

Thank you in advance,

 

Sander

Is there such a thing as Workstation Player for Mac?

$
0
0

Hello,

 

I'm looking for an App for my Mac for Virtual Machines, but I don't have money to buy Fusion, so is there something like VMWare Workstation Player for Mac?

 

I need it for Personal use, I have already tried VirtualBox, but it doesn't let me install Mac OS on Clients.

 

Thanks.

Certificate issue connecting to VDI.

$
0
0

in a new horizon 7.5 deployment, we have configured load-balanced UAGs for external access pointing to load-balanced connection servers.  All the certs seem to be in place.  I am using split dns, with external pointing at the UAG's, internal pointing at the connection servers.

 

From external, there are no certificate errors when connecting using the view client or html.  Everything works as expected.

 

From internal, there are no certificate errors when using the view client.

 

From internal when using html there are no certificate errors until the deskop is selected.  On initial connection to the vdi it shows the vdi's ip address port 22443.  Since there is no certificate with matching the ip address, there is a certificate error, which can be accepted.  After acceptance, the url flips back to the connection server load-balanced URL (what the user used to connect to horizon) and the cert is accepted.

 

I'm wondering if it is because on the horizon connection server, View Configuration, Servers, Connection Servers, Edit, General Tab, to use the UAG with reverse proxy, I need to uncheck all the external URL boxes.

 

This issue goes away if I point the internal (of the split DNS) to the internal ip of the UAG Load-balancer but I am concerned about traffic and sending internal traffic to the dmz to come back in.

 

All certs used are public and there is no internal CA.

Shared Windows server running vCenter 5.5 to VCSA 6.5

$
0
0

Hello,

 

The current vCenter 5.5 services are running on a physical windows server that is also running a few other IT services. We are looking to upgrade & migrate vCenter to VCSA 6.5. Unfortunately, because the windows server also hosts other services the VCSA can't simply take over the physical server. Is there a documented upgrade/migrations strategy in this scenario?

 

My thoughts, but not sure if correct:

 

1. Use the vCenter Migrate function to upgrade from Windows vCenter 5.5 to the VCSA 6.5 appliance.

2. Rename, re-IP the newly created appliance after migration has completed (ie /opt/vmware/share/vami/vami_config_net)

3. Restart the Windows server under the original name & IP address.

 

Anyone have any experience or suggestions if there's a supported path?

 

Thanks in advance.

How to get default protocol set on VMware horizon server

$
0
0

Hello all,

Please suggest me, How would I get which protocol is set as a default desktop protocol on my VMware horizon server, through command line from Linux machine.

Skyline hung at web GUI after reboot

$
0
0

I have installed Skyline collector 1.4 but after reboot the it is hung at web GUI.

After providing the credentials and clicking on login it does not go further.

 

Any idea guys??


Vcenter Upgrade from 5.5 to 6.5u2 vcsa

$
0
0

I am planning to upgrade my vcenter server from 5.5 to 6.5 vcsa. What impact will the upgrade cause to my vcenter server and the database associated with it. I have Veeam backup in my infrastructure what impact will it have on the backups running in my infrastructure? I would also like to know that just taking a snapshot of the vcenter server enough for backup or do I need to do something else ?   Please let me know as soon as possible

No puedo configurar mi vswitch

$
0
0

buen día, hace unos días tuve un problema de corriente eléctrica y revisando el inventario de mi Data Center me encuentro con un detalle del Vsphere Standar Switch el cual me dice que una de las vmnic que tengo agregadas, esta sin conexión o no configurada, que problema podría tener en este caso.

ESXi hyperthreading

$
0
0

I enabled hyperthreading on UCS and the ESXi 6.0, but it’s still showing “inactive” on the ESXi.  Anyone have seen this before ? attachment included

Virtuelle Maschine mit Portgruppe verbinden

$
0
0

Hallo Zusammen,

 

ich verwende ESXI 6.5 und habe einen virtuellen Switch erstellt der mit einer Portgruppe verbunden ist. Leider kann ich diese selbst erstellte Portgruppe im Drop Down Menu beim erstellen einer virtuellen Maschine nicht auswählen sondern nur das Standard VM Network. Wie kann ich meine eigene Portgruppe auswählen?

Upgrade 5.1 to 6

$
0
0

Hello, we're looking to upgrade a vCenter 5.1 U3b with VMware Horizon 5.1.2 to 6.0 U3. Based on what I could find it appears the upgrade for each piece is as listed below. Looking for input if this appears to be the correct order. I have reviewed the hardware 6.0 U3 compatibility list to ensure our hosts and SAN are covered.

 

Once the view connection server/security servers are upgraded will the VDI guests continue to work or will they become non-functional until the upgrade is complete?

 

1. upgrade view connection server

2. upgrade security server (resides in DMZ)

3. upgrade vcenter

4. upgrade esxi hosts

     a. upgrade virtual machines to hardware version 10 or higher

5. upgrade view manager

6. upgrade view agent

7. upgrade view composer desktop pool

8. upgrade view client app

Impossible de mettre à jour de 6.0U3 7967664 vers 9313334

$
0
0

Bonjour.

Je rencontre un problème lors de la mise à jour de mes 3 hôtes ESXI de 6.0U3 7967664 vers 6.0U3 9313334.

J'ai le même message d'erreur sur les 3 :

Cannot merge VIBs MEL_bootbank_nmlx5-core_4.15.10.3-1OEM.600.0.0.2768847, MEL_bootbank_nmlx5-core_4.15.10.3-1OEM.600.0.0.2768847 with unequal acceptancelevel attributes: (certified, partner)

Ce sont des serveurs DELL et j'utilise l'image DELL customized.

Jusqu'à présent, je n'ai jamais eu ce problème.

Merci d'avance pour votre aide.

Why does VMRC sometimes open as a very small window

$
0
0

Sometimes when I open a new console window VMRC starts a a very small window, much smaller than the resolution of the VM. It also doesn't have any scroll bars. Why does this happen? Is there a way to prevent this behavior.


Hosts have HA issues after ESXI upgrade

$
0
0

After upgrading ESXi hosts from 6.5 build 5969303 to 6.5 7388607 the HA agents have issues.  Windows vCenter Server 6.7 

 

vSphere HA agent for this host has an error.  The vSphere HA agent is not reachable from vCenter server.

 

They were fine before the host upgrade as well as during the upgrade.  It wasn't until the 4th host was put into maintenance mode that this happened and the running vms couldn't evacuate because the remaining 3 hosts in the cluster had HA errors. 

 

Does anyone know what I can look at to see what caused this?  I  do not want to just reconfigure for HA, but would like to know if this can be avoided.  This happened three different times. 

I have been all over the logs for a few days now and don't really see much.  Maybe I don't know what to look for. 

 

Thank You for any help you can provide.

vCenter 6.7 Appliance upgrade failed "Update failed. Fix and reset banner." is all that's given as a message.

$
0
0

Currently the UI shows the same message "Update failed. Fix and reset banner."

 

The Console shows it below the URL list.

 

There is no KB that I have found.

 

I was trying to use the appliance upgrade page to go from 6.7 GA to current release offering in the Upgrade section.

 

Anyone know of a document that covers diagnosing this sort of thing?

Unable to enable "non-shared" USB passthrough

$
0
0

I am running VMware Fusion Professional 10.1.3 on a MacBook Pro 2017 computer running Mac OS 10.13.4 and Windows 2016 on the guest VM.

I have a Yubikey 4 device (firmware 4.2.8) which I need to configure as a smartcard for interactive logon access to the Windows 2016 guest VM.

 

To access the Yubikey on the Windows 2016 guest, the USB port on my Mac needs to passthrough to the guest as a “non-shared” device.

 

I followed Yubico’s instructions for configuring the VM to enable the USB to passthrough as a “non-shared” device (see https://support.yubico.com/support/solutions/articles/15000008891-troubleshooting-vmware-workstation-device-passthrough). However, it does not work. This is what I see in the VM:

Screen Shot 2018-09-30 at 6.06.13 PM.png

 

As a comparison, this worked on my MacBook Pro 2015 running Mac OS 10.11.6 and VMware Fusion Professional Version 8.5.8 and Windows 2012R2 guest, after configuring the vmx file as per the Yubico website above. This is what I see in the VM:

Screen Shot 2018-09-27 at 11.55.21 AM.png

Yubico support thinks this is an issue with the VM. Any suggestions on what changes I need to make to the VM?

How to upgrade a persistent Full clone pool?

$
0
0

We need to upgrade about 200 persistent full clone vm's, is it possible to change the master image to update the pool without the risk of delete the user files and config? If so, whats the procedure?

VMware Horizon Agent installation fails

$
0
0

I'm trying to update the VMware Horizon Agent on a VM, and it's consistently failing.  I've tried 7.4, 7.51 and 7.6.

 

vmware.jpg

 

Relevant part of the log here:

 

Action 15:03:51: VM_InstVmwvudpd_RB.74877121_F78E_4CE3_BA9A_CAE53AC366FE.

MSI (s) (98:74) [15:03:51:421]: Executing op: CustomActionSchedule(Action=VM_InstVmwvudpd_RB.74877121_F78E_4CE3_BA9A_CAE53AC366FE,ActionType=3393,Source=BinaryData,Target=VMUninstallWdfNonPnpDriver,CustomActionData=WFPCALLOUTS;C:\Program Files\VMware\VMware View\Agent\bin\drivers\vmwvudpd\Win7\;vmwvudpd.inf;vmwvudpd.cat;vmwvudpd.sys;vmwvudpd;C:\Program Files\VMware\VMware View\Agent\bin\drivers\vmwvudpd\Win7\WdfCoInstaller01009.dll;_VMWVUdpd_Install.NT.Wdf;5)

MSI (s) (98:74) [15:03:51:421]: Executing op: ActionStart(Name=VM_InstVmwvudpd.74877121_F78E_4CE3_BA9A_CAE53AC366FE,,)

Action 15:03:51: VM_InstVmwvudpd.74877121_F78E_4CE3_BA9A_CAE53AC366FE.

MSI (s) (98:74) [15:03:51:421]: Executing op: CustomActionSchedule(Action=VM_InstVmwvudpd.74877121_F78E_4CE3_BA9A_CAE53AC366FE,ActionType=3073,Source=BinaryData,Target=VMInstallWdfNonPnpDriver,CustomActionData=WFPCALLOUTS;C:\Program Files\VMware\VMware View\Agent\bin\drivers\vmwvudpd\Win7\;vmwvudpd.inf;vmwvudpd.cat;vmwvudpd.sys;vmwvudpd;C:\Program Files\VMware\VMware View\Agent\bin\drivers\vmwvudpd\Win7\WdfCoInstaller01009.dll;_VMWVUdpd_Install.NT.Wdf;5)

MSI (s) (98:68) [15:03:51:437]: Invoking remote custom action. DLL: C:\Windows\Installer\MSIC890.tmp, Entrypoint: VMInstallWdfNonPnpDriver

CustomAction VM_InstVmwvudpd.74877121_F78E_4CE3_BA9A_CAE53AC366FE returned actual error code 1603 (note this may not be 100% accurate if translation happened inside sandbox)

Action ended 15:03:51: InstallFinalize. Return value 3.

MSI (s) (98:74) [15:03:51:671]: Note: 1: 2265 2:  3: -2147287035

MSI (s) (98:74) [15:03:51:671]: User policy value 'DisableRollback' is 0 MSI (s) (98:74) [15:03:51:671]: Machine policy value 'DisableRollback' is 0

MSI (s) (98:74) [15:03:51:796]: Executing op: Header(Signature=1397708873,Version=500,Timestamp=1295612011,LangId=1033,Platform=589824,ScriptType=2,ScriptMajorVersion=21,ScriptMinorVersion=4,ScriptAttributes=1)

MSI (s) (98:74) [15:03:51:796]: Executing op: DialogInfo(Type=0,Argument=1033)

MSI (s) (98:74) [15:03:51:796]: Executing op: DialogInfo(Type=1,Argument=VMware Horizon Agent)

MSI (s) (98:74) [15:03:51:796]: Executing op: RollbackInfo(,RollbackAction=Rollback,RollbackDescription=Rolling back action:,RollbackTemplate=[1],CleanupAction=RollbackCleanup,CleanupDescription=Removing backup files,CleanupTemplate=File: [1])

MSI (s) (98:74) [15:03:51:796]: Executing op: RegisterBackupFile(File=C:\Config.Msi\11eb88.rbf)

Action 15:03:51: Rollback. Rolling back action: Rollback: VM_InstVmwvudpd.74877121_F78E_4CE3_BA9A_CAE53AC366FE

MSI (s) (98:74) [15:03:51:796]: Executing op: ActionStart(Name=VM_InstVmwvudpd.74877121_F78E_4CE3_BA9A_CAE53AC366FE,,)

MSI (s) (98:74) [15:03:51:796]: Executing op: ProductInfo(ProductKey={3B01A133-6946-4D78-B923-B216E5CE7DE5},ProductName=VMware Horizon Agent,PackageName=VMware-Horizon-Agent-x86_64-7.6.0-9539447.msi,Language=1033,Version=117833728,Assignment=1,ObsoleteArg=0,ProductIcon=arp.ico,,PackageCode={AF9E4F33-ED50-4139-9F6D-9CB2C78C306C},,,InstanceType=0,LUASetting=0,RemoteURTInstalls=0,ProductDeploymentFlags=3) Rollback: VM_InstVmwvudpd_RB.74877121_F78E_4CE3_BA9A_CAE53AC366FE

MSI (s) (98:74) [15:03:51:796]: Executing op: ActionStart(Name=VM_InstVmwvudpd_RB.74877121_F78E_4CE3_BA9A_CAE53AC366FE,,)

MSI (s) (98:74) [15:03:51:796]: Executing op: CustomActionRollback(Action=VM_InstVmwvudpd_RB.74877121_F78E_4CE3_BA9A_CAE53AC366FE,ActionType=3393,Source=BinaryData,Target=VMUninstallWdfNonPnpDriver,CustomActionData=WFPCALLOUTS;C:\Program Files\VMware\VMware View\Agent\bin\drivers\vmwvudpd\Win7\;vmwvudpd.inf;vmwvudpd.cat;vmwvudpd.sys;vmwvudpd;C:\Program Files\VMware\VMware View\Agent\bin\drivers\vmwvudpd\Win7\WdfCoInstaller01009.dll;_VMWVUdpd_Install.NT.Wdf;5)

MSI (s) (98:78) [15:03:51:812]: Invoking remote custom action. DLL: C:\Windows\Installer\MSICA18.tmp, Entrypoint: VMUninstallWdfNonPnpDriver Rollback: VM_OpenFwVDP.782BB9D0_6831_48E2_B1A7_D95F12D03A73

MSI (s) (98:74) [15:03:51:827]: Executing op: ActionStart(Name=VM_OpenFwVDP.782BB9D0_6831_48E2_B1A7_D95F12D03A73,,) Rollback: VM_OpenFwVDP_RB.782BB9D0_6831_48E2_B1A7_D95F12D03A73

MSI (s) (98:74) [15:03:51:827]: Executing op: ActionStart(Name=VM_OpenFwVDP_RB.782BB9D0_6831_48E2_B1A7_D95F12D03A73,,)

MSI (s) (98:74) [15:03:51:827]: Executing op: CustomActionRollback(Action=VM_OpenFwVDP_RB.782BB9D0_6831_48E2_B1A7_D95F12D03A73,ActionType=3393,Source=BinaryData,Target=VMCloseFirewall2,CustomActionData=1000;advfirewall firewall delete rule name="VMware Horizon View Device and Multimedia")

MSI (s) (98:34) [15:03:51:843]: Invoking remote custom action. DLL: C:\Windows\Installer\MSICA28.tmp, Entrypoint: VMCloseFirewall2 Rollback: Installing the VMware Interception driver...

MSI (s) (98:74) [15:03:52:296]: Executing op: ActionStart(Name=VM_InstVmwicpdr.B108C473_5789_4684_888F_4D6CF5C95E62,Description=Installing the VMware Interception driver...,) Rollback: VM_InstVmwicpdr_RB.B108C473_5789_4684_888F_4D6CF5C95E62

MSI (s) (98:74) [15:03:52:312]: Executing op: ActionStart(Name=VM_InstVmwicpdr_RB.B108C473_5789_4684_888F_4D6CF5C95E62,,)

 

Has anyone seen this before?

 

Potentially the driver store on this VM is corrupt, as VMware Tools was also unable to install the SVGA driver.  I got around that by deselecting it.  I really want to avoid rebuilding this VM, so if anyone has a workaround, or a way of fixing the driver store (yes, I've ran "SFC /scanow"), I'd be very grateful!

Viewing all 178040 articles
Browse latest View live


<script src="https://jsc.adskeeper.com/r/s/rssing.com.1596347.js" async> </script>