Event ID's 4254, 4255, and 4256 are all part of the Event Filtering feature released in version 10.0.3.
Event filtering will periodically provide a summary report on events that have been suppressed (every 15 minutes by default). The event ID and severity of the summary event depends upon the severity of the event suppressed. The text for all three events, 4254, 4255, and 4256 are identical and logged to both the Enterprise Vault and Application event logs
An example of Event 4255 is in the screenshot below.
- If errors are suppressed, error 4254 is logged
- If warnings are suppressed, warning 4255 is logged
- If informational logs are suppressed, informational 4256 is logged
To identify the underlying issue, refer to the actual Event ID that is in the body of one of the three events listed above. In the example above, the actual Event ID to review is 8229.
Open the Enterprise Vault logs and filter on 8229 to begin troubleshooting.
For additional information and registry keys related to Event Filtering, refer to DOC6303 below under Related Articles.