itguyj_sl-america
asked on
Processing Group Policy fails reading Sysvol on PDC EVID: 1058 E-code: 64 W2k8 server?
My server is dropping its network shares every couple of hours and as frequently as 5 - 20 minutes after startup now. I migrated from another 2003 Server machine to this 2008 server 32bit machine last July. Recently and becoming more frequently (Now just 5 to 20 minutes after a restart) I am getting the following error:
Log Name: System
Source: Microsoft-Windows-GroupPol icy
Date: 8/13/2010 3:12:19 PM
Event ID: 1058
Task Category: None
Level: Error
Keywords:
User: SYSTEM
Computer: SLMISERVER.SLMI
Description:
The processing of Group Policy failed. Windows attempted to read the file \\SLMI\sysvol\SLMI\Policie s\{31B2F34 0-016D-11D 2-945F-00C 04FB984F9} \gpt.ini from a domain controller and was not successful. Group Policy settings may not be applied until this event is resolved. This issue may be transient and could be caused by one or more of the following:
a) Name Resolution/Network Connectivity to the current domain controller.
b) File Replication Service Latency (a file created on another domain controller has not replicated to the current domain controller).
c) The Distributed File System (DFS) client has been disabled.
Event Xml:
<Event xmlns="http://schemas.microsoft.com/win/2004/08/events/event">
<System>
<Provider Name="Microsoft-Windows-Gr oupPolicy" Guid="{aea1b4fa-97d1-45f2- a64c-4d69f ffd92c9}" />
<EventID>1058</EventID>
<Version>0</Version>
<Level>2</Level>
<Task>0</Task>
<Opcode>1</Opcode>
<Keywords>0x80000000000000 00</Keywor ds>
<TimeCreated SystemTime="2010-08-13T19: 12:19.593Z " />
<EventRecordID>90849</Even tRecordID>
<Correlation ActivityID="{A4D1CA92-87D7 -4BBA-9F26 -76F05F750 FB4}" />
<Execution ProcessID="1044" ThreadID="3652" />
<Channel>System</Channel>
<Computer>SLMISERVER.SLMI< /Computer>
<Security UserID="S-1-5-18" />
</System>
<EventData>
<Data Name="SupportInfo1">4</Dat a>
<Data Name="SupportInfo2">840</D ata>
<Data Name="ProcessingMode">0</D ata>
<Data Name="ProcessingTimeInMill iseconds"> 74802</Dat a>
<Data Name="ErrorCode">64</Data>
<Data Name="ErrorDescription">Th e specified network name is no longer available. </Data>
<Data Name="DCName">SLMISERVER</ Data>
<Data Name="GPOCNName">CN={31B2F 340-016D-1 1D2-945F-0 0C04FB984F 9},CN=Poli cies,CN=Sy stem,DC=SL MI</Data>
<Data Name="FilePath">\\SLMI\sys vol\SLMI\P olicies\{3 1B2F340-01 6D-11D2-94 5F-00C04FB 984F9}\gpt .ini</Data >
</EventData>
</Event>
Following this error all my network shares drop and no one can access shared folders on this server or network priinters attached to this server. The strange thing is this server is also the PDC for the domain. Can someone please help me with this? People using this server are becoming increasingly frustrated because they keep loosing access to their network folders. I am frustrated as well because the only way to restore access is to restart the server. Thanks in advance for your help.
SLMI-PDC-dcdiag-on-GPO-errors.txt
Log Name: System
Source: Microsoft-Windows-GroupPol
Date: 8/13/2010 3:12:19 PM
Event ID: 1058
Task Category: None
Level: Error
Keywords:
User: SYSTEM
Computer: SLMISERVER.SLMI
Description:
The processing of Group Policy failed. Windows attempted to read the file \\SLMI\sysvol\SLMI\Policie
a) Name Resolution/Network Connectivity to the current domain controller.
b) File Replication Service Latency (a file created on another domain controller has not replicated to the current domain controller).
c) The Distributed File System (DFS) client has been disabled.
Event Xml:
<Event xmlns="http://schemas.microsoft.com/win/2004/08/events/event">
<System>
<Provider Name="Microsoft-Windows-Gr
<EventID>1058</EventID>
<Version>0</Version>
<Level>2</Level>
<Task>0</Task>
<Opcode>1</Opcode>
<Keywords>0x80000000000000
<TimeCreated SystemTime="2010-08-13T19:
<EventRecordID>90849</Even
<Correlation ActivityID="{A4D1CA92-87D7
<Execution ProcessID="1044" ThreadID="3652" />
<Channel>System</Channel>
<Computer>SLMISERVER.SLMI<
<Security UserID="S-1-5-18" />
</System>
<EventData>
<Data Name="SupportInfo1">4</Dat
<Data Name="SupportInfo2">840</D
<Data Name="ProcessingMode">0</D
<Data Name="ProcessingTimeInMill
<Data Name="ErrorCode">64</Data>
<Data Name="ErrorDescription">Th
<Data Name="DCName">SLMISERVER</
<Data Name="GPOCNName">CN={31B2F
<Data Name="FilePath">\\SLMI\sys
</EventData>
</Event>
Following this error all my network shares drop and no one can access shared folders on this server or network priinters attached to this server. The strange thing is this server is also the PDC for the domain. Can someone please help me with this? People using this server are becoming increasingly frustrated because they keep loosing access to their network folders. I am frustrated as well because the only way to restore access is to restart the server. Thanks in advance for your help.
SLMI-PDC-dcdiag-on-GPO-errors.txt
ASKER
I have about 48GB out of 68GB free on C drive.
I am getting this Netlogin error around that time but it is involving a domain trust with another server on another domain:
Log Name: System
Source: NETLOGON
Date: 8/13/2010 4:01:05 PM
Event ID: 5783
Task Category: None
Level: Error
Keywords: Classic
User: N/A
Computer: SLMISERVER.SLMI
Description:
The session setup to the Windows NT or Windows 2000 Domain Controller \\sl_tnserver.SLTN.LLC for the domain SLTN is not responsive. The current RPC call from Netlogon on \\SLMISERVER to \\sl_tnserver.SLTN.LLC has been cancelled.
Event Xml:
<Event xmlns="http://schemas.microsoft.com/win/2004/08/events/event">
<System>
<Provider Name="NETLOGON" />
<EventID Qualifiers="0">5783</Event ID>
<Level>2</Level>
<Task>0</Task>
<Keywords>0x80000000000000 </Keywords >
<TimeCreated SystemTime="2010-08-13T20: 01:05.000Z " />
<EventRecordID>90859</Even tRecordID>
<Channel>System</Channel>
<Computer>SLMISERVER.SLMI< /Computer>
<Security />
</System>
<EventData>
<Data>\\sl_tnserver.SLTN.L LC</Data>
<Data>SLTN</Data>
<Data>SLMISERVER</Data>
</EventData>
</Event>
I am also getting this SLC error around the same time:
Log Name: Application
Source: Microsoft-Windows-Security -Licensing -SLC
Date: 8/13/2010 4:13:25 PM
Event ID: 12293
Task Category: None
Level: Error
Keywords: Classic
User: N/A
Computer: SLMISERVER.SLMI
Description:
Publishing the Key Management Service (KMS) to DNS in the 'SLMI' domain failed.
Info:
hr=0x800705B4
Event Xml:
<Event xmlns="http://schemas.microsoft.com/win/2004/08/events/event">
<System>
<Provider Name="Microsoft-Windows-Se curity-Lic ensing-SLC " Guid="{1FD7C1D2-D037-4620- 8D29-B2C7E 5FCC13A}" EventSourceName="Software Licensing Service" />
<EventID Qualifiers="16384">12293</ EventID>
<Version>0</Version>
<Level>2</Level>
<Task>0</Task>
<Opcode>0</Opcode>
<Keywords>0x80000000000000 </Keywords >
<TimeCreated SystemTime="2010-08-13T20: 13:25.000Z " />
<EventRecordID>40195</Even tRecordID>
<Correlation />
<Execution ProcessID="0" ThreadID="0" />
<Channel>Application</Chan nel>
<Computer>SLMISERVER.SLMI< /Computer>
<Security />
</System>
<EventData>
<Data>hr=0x800705B4</Data>
<Data>SLMI</Data>
</EventData>
</Event>
I get this DHCP error around the same time:
Log Name: System
Source: Service Control Manager
Date: 8/13/2010 2:21:35 PM
Event ID: 7031
Task Category: None
Level: Error
Keywords: Classic
User: N/A
Computer: SLMISERVER.SLMI
Description:
The DHCP Server service terminated unexpectedly. It has done this 1 time(s). The following corrective action will be taken in 120000 milliseconds: Restart the service.
Event Xml:
<Event xmlns="http://schemas.microsoft.com/win/2004/08/events/event">
<System>
<Provider Name="Service Control Manager" Guid="{555908D1-A6D7-4695- 8E1E-26931 D2012F4}" EventSourceName="Service Control Manager" />
<EventID Qualifiers="49152">7031</E ventID>
<Version>0</Version>
<Level>2</Level>
<Task>0</Task>
<Opcode>0</Opcode>
<Keywords>0x80000000000000 </Keywords >
<TimeCreated SystemTime="2010-08-13T18: 21:35.000Z " />
<EventRecordID>90802</Even tRecordID>
<Correlation />
<Execution ProcessID="0" ThreadID="0" />
<Channel>System</Channel>
<Computer>SLMISERVER.SLMI< /Computer>
<Security />
</System>
<EventData>
<Data Name="param1">DHCP Server</Data>
<Data Name="param2">1</Data>
<Data Name="param3">120000</Data >
<Data Name="param4">1</Data>
<Data Name="param5">Restart the service</Data>
</EventData>
</Ev
Here's yet another error SCM:
Log Name: System
Source: Service Control Manager
Date: 8/13/2010 3:31:51 PM
Event ID: 7011
Task Category: None
Level: Error
Keywords: Classic
User: N/A
Computer: SLMISERVER.SLMI
Description:
A timeout (30000 milliseconds) was reached while waiting for a transaction response from the service.
Event Xml:
<Event xmlns="http://schemas.microsoft.com/win/2004/08/events/event">
<System>
<Provider Name="Service Control Manager" Guid="{555908D1-A6D7-4695- 8E1E-26931 D2012F4}" EventSourceName="Service Control Manager" />
<EventID Qualifiers="49152">7011</E ventID>
<Version>0</Version>
<Level>2</Level>
<Task>0</Task>
<Opcode>0</Opcode>
<Keywords>0x80000000000000 </Keywords >
<TimeCreated SystemTime="2010-08-13T19: 31:51.000Z " />
<EventRecordID>90855</Even tRecordID>
<Correlation />
<Execution ProcessID="0" ThreadID="0" />
<Channel>System</Channel>
<Computer>SLMISERVER.SLMI< /Computer>
<Security />
</System>
<EventData>
<Data Name="param1">30000</Data>
<Data Name="param2">
</Data>
</EventData>
</Event>
and of course I am getting this ESM warning:
Log Name: System
Source: Server Administrator
Date: 8/13/2010 2:21:59 PM
Event ID: 1553
Task Category: Instrumentation Service
Level: Warning
Keywords: Classic
User: N/A
Computer: SLMISERVER.SLMI
Description:
Log size is near or at capacity
Log type: ESM
Event Xml:
<Event xmlns="http://schemas.microsoft.com/win/2004/08/events/event">
<System>
<Provider Name="Server Administrator" />
<EventID Qualifiers="0">1553</Event ID>
<Level>3</Level>
<Task>2</Task>
<Keywords>0x80000000000000 </Keywords >
<TimeCreated SystemTime="2010-08-13T18: 21:59.000Z " />
<EventRecordID>90829</Even tRecordID>
<Channel>System</Channel>
<Computer>SLMISERVER.SLMI< /Computer>
<Security />
</System>
<EventData>
<Data>Log size is near or at capacity
Log type: ESM</Data>
</EventData>
</Event>
Sorry about all the error listings, I just wanted to be thorough. Thanks again.
I am getting this Netlogin error around that time but it is involving a domain trust with another server on another domain:
Log Name: System
Source: NETLOGON
Date: 8/13/2010 4:01:05 PM
Event ID: 5783
Task Category: None
Level: Error
Keywords: Classic
User: N/A
Computer: SLMISERVER.SLMI
Description:
The session setup to the Windows NT or Windows 2000 Domain Controller \\sl_tnserver.SLTN.LLC for the domain SLTN is not responsive. The current RPC call from Netlogon on \\SLMISERVER to \\sl_tnserver.SLTN.LLC has been cancelled.
Event Xml:
<Event xmlns="http://schemas.microsoft.com/win/2004/08/events/event">
<System>
<Provider Name="NETLOGON" />
<EventID Qualifiers="0">5783</Event
<Level>2</Level>
<Task>0</Task>
<Keywords>0x80000000000000
<TimeCreated SystemTime="2010-08-13T20:
<EventRecordID>90859</Even
<Channel>System</Channel>
<Computer>SLMISERVER.SLMI<
<Security />
</System>
<EventData>
<Data>\\sl_tnserver.SLTN.L
<Data>SLTN</Data>
<Data>SLMISERVER</Data>
</EventData>
</Event>
I am also getting this SLC error around the same time:
Log Name: Application
Source: Microsoft-Windows-Security
Date: 8/13/2010 4:13:25 PM
Event ID: 12293
Task Category: None
Level: Error
Keywords: Classic
User: N/A
Computer: SLMISERVER.SLMI
Description:
Publishing the Key Management Service (KMS) to DNS in the 'SLMI' domain failed.
Info:
hr=0x800705B4
Event Xml:
<Event xmlns="http://schemas.microsoft.com/win/2004/08/events/event">
<System>
<Provider Name="Microsoft-Windows-Se
<EventID Qualifiers="16384">12293</
<Version>0</Version>
<Level>2</Level>
<Task>0</Task>
<Opcode>0</Opcode>
<Keywords>0x80000000000000
<TimeCreated SystemTime="2010-08-13T20:
<EventRecordID>40195</Even
<Correlation />
<Execution ProcessID="0" ThreadID="0" />
<Channel>Application</Chan
<Computer>SLMISERVER.SLMI<
<Security />
</System>
<EventData>
<Data>hr=0x800705B4</Data>
<Data>SLMI</Data>
</EventData>
</Event>
I get this DHCP error around the same time:
Log Name: System
Source: Service Control Manager
Date: 8/13/2010 2:21:35 PM
Event ID: 7031
Task Category: None
Level: Error
Keywords: Classic
User: N/A
Computer: SLMISERVER.SLMI
Description:
The DHCP Server service terminated unexpectedly. It has done this 1 time(s). The following corrective action will be taken in 120000 milliseconds: Restart the service.
Event Xml:
<Event xmlns="http://schemas.microsoft.com/win/2004/08/events/event">
<System>
<Provider Name="Service Control Manager" Guid="{555908D1-A6D7-4695-
<EventID Qualifiers="49152">7031</E
<Version>0</Version>
<Level>2</Level>
<Task>0</Task>
<Opcode>0</Opcode>
<Keywords>0x80000000000000
<TimeCreated SystemTime="2010-08-13T18:
<EventRecordID>90802</Even
<Correlation />
<Execution ProcessID="0" ThreadID="0" />
<Channel>System</Channel>
<Computer>SLMISERVER.SLMI<
<Security />
</System>
<EventData>
<Data Name="param1">DHCP Server</Data>
<Data Name="param2">1</Data>
<Data Name="param3">120000</Data
<Data Name="param4">1</Data>
<Data Name="param5">Restart the service</Data>
</EventData>
</Ev
Here's yet another error SCM:
Log Name: System
Source: Service Control Manager
Date: 8/13/2010 3:31:51 PM
Event ID: 7011
Task Category: None
Level: Error
Keywords: Classic
User: N/A
Computer: SLMISERVER.SLMI
Description:
A timeout (30000 milliseconds) was reached while waiting for a transaction response from the service.
Event Xml:
<Event xmlns="http://schemas.microsoft.com/win/2004/08/events/event">
<System>
<Provider Name="Service Control Manager" Guid="{555908D1-A6D7-4695-
<EventID Qualifiers="49152">7011</E
<Version>0</Version>
<Level>2</Level>
<Task>0</Task>
<Opcode>0</Opcode>
<Keywords>0x80000000000000
<TimeCreated SystemTime="2010-08-13T19:
<EventRecordID>90855</Even
<Correlation />
<Execution ProcessID="0" ThreadID="0" />
<Channel>System</Channel>
<Computer>SLMISERVER.SLMI<
<Security />
</System>
<EventData>
<Data Name="param1">30000</Data>
<Data Name="param2">
</Data>
</EventData>
</Event>
and of course I am getting this ESM warning:
Log Name: System
Source: Server Administrator
Date: 8/13/2010 2:21:59 PM
Event ID: 1553
Task Category: Instrumentation Service
Level: Warning
Keywords: Classic
User: N/A
Computer: SLMISERVER.SLMI
Description:
Log size is near or at capacity
Log type: ESM
Event Xml:
<Event xmlns="http://schemas.microsoft.com/win/2004/08/events/event">
<System>
<Provider Name="Server Administrator" />
<EventID Qualifiers="0">1553</Event
<Level>3</Level>
<Task>2</Task>
<Keywords>0x80000000000000
<TimeCreated SystemTime="2010-08-13T18:
<EventRecordID>90829</Even
<Channel>System</Channel>
<Computer>SLMISERVER.SLMI<
<Security />
</System>
<EventData>
<Data>Log size is near or at capacity
Log type: ESM</Data>
</EventData>
</Event>
Sorry about all the error listings, I just wanted to be thorough. Thanks again.
ASKER
OK, I just did this dcdiag 5 minutes ago and it looks much better. Not sure why. It will likely drop out in just a few minutes. Please see attached dcdiag test.
SLMI-PDC-dcdiag-better.txt
SLMI-PDC-dcdiag-better.txt
ASKER
OK, just checked the server and it's failing again. See attached file. Checked the performance monitor and the CPU is at 25 percent with the Windows NT Distributed File System service.
Here's the latest GP processing error regarding the failure reading Sysvol:
Log Name: System
Source: Microsoft-Windows-GroupPol icy
Date: 8/13/2010 6:06:37 PM
Event ID: 1058
Task Category: None
Level: Error
Keywords:
User: SYSTEM
Computer: SLMISERVER.SLMI
Description:
The processing of Group Policy failed. Windows attempted to read the file \\SLMI\sysvol\SLMI\Policie s\{31B2F34 0-016D-11D 2-945F-00C 04FB984F9} \gpt.ini from a domain controller and was not successful. Group Policy settings may not be applied until this event is resolved. This issue may be transient and could be caused by one or more of the following:
a) Name Resolution/Network Connectivity to the current domain controller.
b) File Replication Service Latency (a file created on another domain controller has not replicated to the current domain controller).
c) The Distributed File System (DFS) client has been disabled.
Event Xml:
<Event xmlns="http://schemas.microsoft.com/win/2004/08/events/event">
<System>
<Provider Name="Microsoft-Windows-Gr oupPolicy" Guid="{aea1b4fa-97d1-45f2- a64c-4d69f ffd92c9}" />
<EventID>1058</EventID>
<Version>0</Version>
<Level>2</Level>
<Task>0</Task>
<Opcode>1</Opcode>
<Keywords>0x80000000000000 00</Keywor ds>
<TimeCreated SystemTime="2010-08-13T22: 06:37.643Z " />
<EventRecordID>91031</Even tRecordID>
<Correlation ActivityID="{E9A22C9E-BE74 -4C90-9BA4 -8A7981F47 9D6}" />
<Execution ProcessID="1044" ThreadID="3872" />
<Channel>System</Channel>
<Computer>SLMISERVER.SLMI< /Computer>
<Security UserID="S-1-5-18" />
</System>
<EventData>
<Data Name="SupportInfo1">4</Dat a>
<Data Name="SupportInfo2">840</D ata>
<Data Name="ProcessingMode">0</D ata>
<Data Name="ProcessingTimeInMill iseconds"> 265389</Da ta>
<Data Name="ErrorCode">64</Data>
<Data Name="ErrorDescription">Th e specified network name is no longer available. </Data>
<Data Name="DCName">SLMISERVER</ Data>
<Data Name="GPOCNName">CN={31B2F 340-016D-1 1D2-945F-0 0C04FB984F 9},CN=Poli cies,CN=Sy stem,DC=SL MI</Data>
<Data Name="FilePath">\\SLMI\sys vol\SLMI\P olicies\{3 1B2F340-01 6D-11D2-94 5F-00C04FB 984F9}\gpt .ini</Data >
</EventData>
</Event>
SLMI-PDC-dcdiag-failing-again.txt
Here's the latest GP processing error regarding the failure reading Sysvol:
Log Name: System
Source: Microsoft-Windows-GroupPol
Date: 8/13/2010 6:06:37 PM
Event ID: 1058
Task Category: None
Level: Error
Keywords:
User: SYSTEM
Computer: SLMISERVER.SLMI
Description:
The processing of Group Policy failed. Windows attempted to read the file \\SLMI\sysvol\SLMI\Policie
a) Name Resolution/Network Connectivity to the current domain controller.
b) File Replication Service Latency (a file created on another domain controller has not replicated to the current domain controller).
c) The Distributed File System (DFS) client has been disabled.
Event Xml:
<Event xmlns="http://schemas.microsoft.com/win/2004/08/events/event">
<System>
<Provider Name="Microsoft-Windows-Gr
<EventID>1058</EventID>
<Version>0</Version>
<Level>2</Level>
<Task>0</Task>
<Opcode>1</Opcode>
<Keywords>0x80000000000000
<TimeCreated SystemTime="2010-08-13T22:
<EventRecordID>91031</Even
<Correlation ActivityID="{E9A22C9E-BE74
<Execution ProcessID="1044" ThreadID="3872" />
<Channel>System</Channel>
<Computer>SLMISERVER.SLMI<
<Security UserID="S-1-5-18" />
</System>
<EventData>
<Data Name="SupportInfo1">4</Dat
<Data Name="SupportInfo2">840</D
<Data Name="ProcessingMode">0</D
<Data Name="ProcessingTimeInMill
<Data Name="ErrorCode">64</Data>
<Data Name="ErrorDescription">Th
<Data Name="DCName">SLMISERVER</
<Data Name="GPOCNName">CN={31B2F
<Data Name="FilePath">\\SLMI\sys
</EventData>
</Event>
SLMI-PDC-dcdiag-failing-again.txt
SOLUTION
membership
This solution is only available to members.
To access this solution, you must be a member of Experts Exchange.
ASKER
I tried all the suggestions previously mentioned. I do have it where I am not getting any GP SYVOL read errros now. One of the possible fixes was getting rid of Symantec NTP and PTP. However, I am still having some residual effects I think. Some people still cannot use a network shared printer through this server and some are still having trouble accessing network shared folders on this server. I am getting the following errror:
Log Name: System
Source: Microsoft-Windows-DHCP-Ser ver
Date: 8/17/2010 7:28:02 AM
Event ID: 1070
Task Category: None
Level: Error
Keywords: Classic
User: N/A
Computer: SLMISERVER.SLMI
Description:
Iashlpr initialization failed: 1060, so DHCP server cannot talk to NPS server. It could be that IAS service is not started.
Event Xml:
<Event xmlns="http://schemas.microsoft.com/win/2004/08/events/event">
<System>
<Provider Name="Microsoft-Windows-DH CP-Server" Guid="{6D64F02C-A125-4DAC- 9A01-F0555 B41CA84}" EventSourceName="DhcpServe r" />
<EventID Qualifiers="0">1070</Event ID>
<Version>0</Version>
<Level>2</Level>
<Task>0</Task>
<Opcode>0</Opcode>
<Keywords>0x80000000000000 </Keywords >
<TimeCreated SystemTime="2010-08-17T11: 28:02.000Z " />
<EventRecordID>128216</Eve ntRecordID >
<Correlation />
<Execution ProcessID="0" ThreadID="0" />
<Channel>System</Channel>
<Computer>SLMISERVER.SLMI< /Computer>
<Security />
</System>
<EventData>
<Data>1060</Data>
<Binary>24040000</Binary>
</EventData>
</Event>
Any Ideas how to get rid of this error or is it unrelated? I am also including a recent dcidiag.
SLMI-PDC-dcdiag-8-17-10.txt
Log Name: System
Source: Microsoft-Windows-DHCP-Ser
Date: 8/17/2010 7:28:02 AM
Event ID: 1070
Task Category: None
Level: Error
Keywords: Classic
User: N/A
Computer: SLMISERVER.SLMI
Description:
Iashlpr initialization failed: 1060, so DHCP server cannot talk to NPS server. It could be that IAS service is not started.
Event Xml:
<Event xmlns="http://schemas.microsoft.com/win/2004/08/events/event">
<System>
<Provider Name="Microsoft-Windows-DH
<EventID Qualifiers="0">1070</Event
<Version>0</Version>
<Level>2</Level>
<Task>0</Task>
<Opcode>0</Opcode>
<Keywords>0x80000000000000
<TimeCreated SystemTime="2010-08-17T11:
<EventRecordID>128216</Eve
<Correlation />
<Execution ProcessID="0" ThreadID="0" />
<Channel>System</Channel>
<Computer>SLMISERVER.SLMI<
<Security />
</System>
<EventData>
<Data>1060</Data>
<Binary>24040000</Binary>
</EventData>
</Event>
Any Ideas how to get rid of this error or is it unrelated? I am also including a recent dcidiag.
SLMI-PDC-dcdiag-8-17-10.txt
Disable IPv6
restart DHCP and DNS.
check this out.
http://technet.microsoft.com/en-us/library/cc726931(WS.10).aspx
restart DHCP and DNS.
check this out.
http://technet.microsoft.com/en-us/library/cc726931(WS.10).aspx
ASKER CERTIFIED SOLUTION
membership
This solution is only available to members.
To access this solution, you must be a member of Experts Exchange.
ASKER
I had run cleanwipe earlier and removed SEP and things were running much better. After reading on several Forums inclduding this one that SEP can play havic with Network shares. As this is my main file server as well, I kind of wanted some Virus protection on it. I heard that NTP and PTP are likely the main culprits with SEP. So, I setup a new policy on the servers that only installed the Virus protection which seemed to be working until this afternoon when I started getting GP SYSVOL errors again.
A noteworthy observation is that the dfssvc.exe file hogging about 75% of my servers CPU. When I ended task on that service my Network shares and printers came back. This is definately tied to the overall problem. Looks like I will have to do what you have suggested and fully remove SEP with cleanwipe again in order to get this thing stabilized long term. Thanks for everyone's suggestions. If anyone has any ideas about the high CPU usage with dfssvc.exe outside the SEP issue, please let me know. Otherwise, I will assume it is a side affect of the overall SEP issue.
A noteworthy observation is that the dfssvc.exe file hogging about 75% of my servers CPU. When I ended task on that service my Network shares and printers came back. This is definately tied to the overall problem. Looks like I will have to do what you have suggested and fully remove SEP with cleanwipe again in order to get this thing stabilized long term. Thanks for everyone's suggestions. If anyone has any ideas about the high CPU usage with dfssvc.exe outside the SEP issue, please let me know. Otherwise, I will assume it is a side affect of the overall SEP issue.
You can try to run SEP with the most updated version of SEP but SEP still causing problems I now use McAfee.
ASKER
Thanks I appreciate all your good advice dariusq. Thanks again for eveyone's assistance.
Also, check the remaining free space on the C: drive of the server.