Essentials Health Service Wont Stay Running

Steve Naylor 1 Reputation point
2021-03-23T19:59:10.453+00:00

After installing the 3/21 security patch for 2016, the health service won't stay started. It runs for about 30 seconds, and then aborts. The most interesting error I see is "General: Failed to open ADTestHook registry key." but I haven't seen too much on that. Any thoughts? This is the health service log. --------------------------------------------------------- [9004] 210322.221520.7446: SharedServiceHost: Information: [0] : ========================================================== [9004] 210322.221520.7908: SharedServiceHost: Information: [0] : "C:\Windows\System32\Essentials\SharedServiceHost.exe" C:\Windows\System32\Essentials\HealthServiceConfig [9004] 210322.221520.7918: SharedServiceHost: Information: [0] : Loading service information from "C:\Windows\System32\Essentials\HealthServiceConfig". [12420] 210322.221520.8058: Services: Information: [0] : OnStart: service "WseHealthSvc" starting up. [12420] 210322.221520.8078: AlertFramework: Subcomponent: ServerService > Starting ServerHealthActivity [12420] 210322.221520.8078: AlertFramework: Subcomponent: ServerService > Building AlertProviderServiceContext [12420] 210322.221520.9271: PfBinding: Information: [0] : Adding service dns identity [DIAMOND] in proxy endpoint. [12420] 210322.221520.9863: Notifications: Information: [0] : Assigning name "LNx01" to node with self-designated name "Local-DIAMOND:SharedServiceHost.exe:p2096:mt5:1". [12420] 210322.221520.9873: Notifications: Information: [0] : Assigning name "NPCx02" to node with self-designated name "WCF-to-Local-DIAMOND:SharedServiceHost.exe:p2096:mt5:1". [12420] 210322.221520.9883: Notifications: Information: [0] : Attempting initial connection to notification system. [12420] 210322.221520.9993: Notifications: Information: [0] : LNx01: Source "notifier:SharedServiceHost.exe:p2096:mt5:1" wants to Connect. [12420] 210322.221521.0003: Notifications: Information: [0] : Assigning name "SNx03" to node with self-designated name "notifier:SharedServiceHost.exe:p2096:mt5:1". [12420] 210322.221521.0113: AlertFramework: Subcomponent: ServerService > Loading AlertAgentProviderService [12420] 210322.221521.0144: AlertFramework: Subcomponent: ServerService > Loading AlertMgmtandSynchProviderService [7100] 210322.221521.0384: Notifications: Information: [0] : NPCx02: Initiating connection to upstream service. [11448] 210322.221521.0424: DevicesProvider: Connection Opened to Devices provider [12900] 210322.221521.0525: Notifications: Information: [0] : NPCx02: Remote node requested connect. (AdminOnly-WCF-to-Provider-DIAMOND:SharedServiceHost.exe:p5900:mt11:1) [12900] 210322.221521.0545: Notifications: Information: [0] : Assigning name "RNx04" to node with self-designated name "AdminOnly-WCF-to-Provider-DIAMOND:SharedServiceHost.exe:p5900:mt11:1". [12900] 210322.221521.0575: Notifications: Information: [0] : LNx01: Neighbor "RNx04" wants to Connect, and is interested in categories: "IDENTITY.USER". [12900] 210322.221521.0665: Notifications: Information: [0] : LNx01: _GrowFilters(): m_allFilters is now: IDENTITY.USER (1) [12900] 210322.221521.0725: Notifications: Information: [0] : LNx01: We will tell neighbor RNx04 that we are interested in the following categories: "". [12900] 210322.221521.0735: Notifications: Information: [0] : NPCx02: We were the initiator, so not returning the Connect(). [12420] 210322.221521.0735: Services: Information: [0] : OnStart: service "WseHealthSvc" ProviderServiceBase.OnStart finished. (ExitCode 0) [8304] 210322.221521.0986: DevicesProvider: Device DIAMOND:S-1-5-21-4047155118-1370865027-4003916951-1001 is added [8304] 210322.221521.1016: AlertFramework: GetLocalMachineSID: The local machine Sid is S-1-5-21-4047155118-1370865027-4003916951-1001 [8304] 210322.221521.1036: DevicesProvider: Device ASSISTANT:S-1-5-21-4047155118-1370865027-4003916951-1125 is added [8304] 210322.221521.1036: DevicesProvider: Device CEO:S-1-5-21-4047155118-1370865027-4003916951-1116 is added [8304] 210322.221521.1036: DevicesProvider: Device RECEPTIONIST:S-1-5-21-4047155118-1370865027-4003916951-1124 is added [8304] 210322.221521.1036: DevicesProvider: Device MEMBERSHIP:S-1-5-21-4047155118-1370865027-4003916951-1127 is added [9628] 210322.221523.6433: AlertFramework: InitializeCallback: Registered IAlertProviderCallback [12900] 210322.221523.6444: AlertFramework: InitializeCallback: Registered IAlertProviderCallback [9628] 210322.221523.6504: AlertFramework: Subcomponent: ClearCurrentCommand > Clearing alert that does not exist: Key=S-1-5-21-4047155118-1370865027-4003916951-1001$ServerBackupFeature$ServerBackupPolicyNotConfigured [9628] 210322.221523.6504: AlertFramework: Subcomponent: AlertAgentProviderService > ClearAlert: error=Clearing alert that does not exist: Key=S-1-5-21-4047155118-1370865027-4003916951-1001$ServerBackupFeature$ServerBackupPolicyNotConfigured [13140] 210322.221523.6504: AlertFramework: Subcomponent: ClearCurrentCommand > Clearing alert that does not exist: Key=S-1-5-21-4047155118-1370865027-4003916951-1001$ServerBackupFeature$BackupTargetMediaFull [13140] 210322.221523.6504: AlertFramework: Subcomponent: AlertAgentProviderService > ClearAlert: error=Clearing alert that does not exist: Key=S-1-5-21-4047155118-1370865027-4003916951-1001$ServerBackupFeature$BackupTargetMediaFull [8304] 210322.221523.6514: AlertFramework: Subcomponent: ClearCurrentCommand > Clearing alert that does not exist: Key=S-1-5-21-4047155118-1370865027-4003916951-1001$ClientBackup$ConsistencyError [8304] 210322.221523.6514: AlertFramework: Subcomponent: AlertAgentProviderService > ClearAlert: error=Clearing alert that does not exist: Key=S-1-5-21-4047155118-1370865027-4003916951-1001$ClientBackup$ConsistencyError [3848] 210322.221523.6544: AlertFramework: Subcomponent: ClearCurrentCommand > Clearing alert that does not exist: Key=S-1-5-21-4047155118-1370865027-4003916951-1001$ServerBackupFeature$BackupTargetNotFound [3848] 210322.221523.6544: AlertFramework: Subcomponent: AlertAgentProviderService > ClearAlert: error=Clearing alert that does not exist: Key=S-1-5-21-4047155118-1370865027-4003916951-1001$ServerBackupFeature$BackupTargetNotFound [3396] 210322.221523.6554: AlertFramework: Subcomponent: ClearCurrentCommand > Clearing alert that does not exist: Key=S-1-5-21-4047155118-1370865027-4003916951-1001$ServerBackupFeature$ScheduledBackupFailed [3396] 210322.221523.6554: AlertFramework: Subcomponent: AlertAgentProviderService > ClearAlert: error=Clearing alert that does not exist: Key=S-1-5-21-4047155118-1370865027-4003916951-1001$ServerBackupFeature$ScheduledBackupFailed [5992] 210322.221523.6564: AlertFramework: Subcomponent: ClearCurrentCommand > Clearing alert that does not exist: Key=S-1-5-21-4047155118-1370865027-4003916951-1001$ClientBackup$DBIsOldError [5992] 210322.221523.6564: AlertFramework: Subcomponent: AlertAgentProviderService > ClearAlert: error=Clearing alert that does not exist: Key=S-1-5-21-4047155118-1370865027-4003916951-1001$ClientBackup$DBIsOldError [9568] 210322.221523.6564: AlertFramework: Subcomponent: ClearCurrentCommand > Clearing alert that does not exist: Key=S-1-5-21-4047155118-1370865027-4003916951-1001$ClientBackup$DBIsNewError [9568] 210322.221523.6564: AlertFramework: Subcomponent: AlertAgentProviderService > ClearAlert: error=Clearing alert that does not exist: Key=S-1-5-21-4047155118-1370865027-4003916951-1001$ClientBackup$DBIsNewError [3848] 210322.221523.6604: AlertFramework: Subcomponent: ClearCurrentCommand > Clearing alert that does not exist: Key=S-1-5-21-4047155118-1370865027-4003916951-1001$ClientBackup$CleanupOverdue [3848] 210322.221523.6604: AlertFramework: Subcomponent: AlertAgentProviderService > ClearAlert: error=Clearing alert that does not exist: Key=S-1-5-21-4047155118-1370865027-4003916951-1001$ClientBackup$CleanupOverdue [3396] 210322.221523.6604: AlertFramework: Subcomponent: ClearCurrentCommand > Clearing alert that does not exist: Key=S-1-5-21-4047155118-1370865027-4003916951-1001$ClientBackup$BackupService [3396] 210322.221523.6614: AlertFramework: Subcomponent: AlertAgentProviderService > ClearAlert: error=Clearing alert that does not exist: Key=S-1-5-21-4047155118-1370865027-4003916951-1001$ClientBackup$BackupService [5992] 210322.221523.6614: AlertFramework: Subcomponent: ClearCurrentCommand > Clearing alert that does not exist: Key=S-1-5-21-4047155118-1370865027-4003916951-1001$ServerBackupFeature$BackupCompletedWithWarnings [5992] 210322.221523.6614: AlertFramework: Subcomponent: AlertAgentProviderService > ClearAlert: error=Clearing alert that does not exist: Key=S-1-5-21-4047155118-1370865027-4003916951-1001$ServerBackupFeature$BackupCompletedWithWarnings [3848] 210322.221523.6614: AlertFramework: Subcomponent: ClearCurrentCommand > Clearing alert that does not exist: Key=S-1-5-21-4047155118-1370865027-4003916951-1001$ServerBackupFeature$AsyncOperationAlreadyInProgress [3848] 210322.221523.6614: AlertFramework: Subcomponent: AlertAgentProviderService > ClearAlert: error=Clearing alert that does not exist: Key=S-1-5-21-4047155118-1370865027-4003916951-1001$ServerBackupFeature$AsyncOperationAlreadyInProgress [3396] 210322.221523.6614: AlertFramework: Subcomponent: ClearCurrentCommand > Clearing alert that does not exist: Key=S-1-5-21-4047155118-1370865027-4003916951-1001$ServerBackupFeature$VSSOutOfMemoryError [3396] 210322.221523.6614: AlertFramework: Subcomponent: AlertAgentProviderService > ClearAlert: error=Clearing alert that does not exist: Key=S-1-5-21-4047155118-1370865027-4003916951-1001$ServerBackupFeature$VSSOutOfMemoryError [12900] 210322.221523.6644: General: Failed to open ADTestHook registry key. [12900] 210322.221523.6644: General: Failed to open ADTestHook registry key. [12900] 210322.221523.7246: AlertFramework: GetNetworkHealthAdminGroupSID: The network health admin group Sid is S-1-5-21-4047155118-1370865027-4003916951-1111 [12900] 210322.221523.7306: AlertFramework: Subcomponent: AlertMgmtandSynchProviderService > GetAllNetworkAlerts: chunk.HasMore=False, count=22 [8304] 210322.221523.7326: AlertFramework: InitializeCallback: Registered IAlertProviderCallback [8304] 210322.221523.7336: AlertFramework: Subcomponent: AlertAgentProviderService > GetAllNetworkAlerts: chunk.HasMore=False, count=6 [12740] 210322.221551.0152: NetworkHealthEngine: EngineSettingsFactoryImp: sm_cleanupTimerPeriod=00:05:00 [12740] 210322.221551.0162: NetworkHealthEngine: EngineSettingsFactoryImp: sm_forceGCAfterCleanup=False [12740] 210322.221551.0182: NetworkHealthEngine: Start Loading Features [12740] 210322.221551.0924: NetworkHealthEngine: Finish Loading Features [2184] 210322.221551.0964: NetworkHealthEngine: Feature DomainManagementFeature: Start RunFilter [10596] 210322.221551.0964: NetworkHealthEngine: Feature OPEServerAlert: Start RunFilter [7672] 210322.221551.0964: NetworkHealthEngine: Feature ServerBackupFeature: Start RunFilter [12376] 210322.221551.0964: NetworkHealthEngine: Feature MicrosoftServicing: Start RunFilter [8064] 210322.221551.0964: NetworkHealthEngine: Feature ConnectivityFeature: Start RunFilter [8480] 210322.221551.0964: NetworkHealthEngine: Feature MicrosoftLicensing: Start RunFilter [2184] 210322.221551.0974: NetworkHealthEngine: ActionProcessorManager.Run: Run the job. Feature=DomainManagementFeature, Definition= [12376] 210322.221551.0974: NetworkHealthEngine: ActionProcessorManager.Run: Run the job. Feature=MicrosoftServicing, Definition= [7672] 210322.221551.0974: NetworkHealthEngine: ActionProcessorManager.Run: Run the job. Feature=ServerBackupFeature, Definition= [8064] 210322.221551.0974: NetworkHealthEngine: ActionProcessorManager.Run: Run the job. Feature=ConnectivityFeature, Definition= [8480] 210322.221551.0974: NetworkHealthEngine: ActionProcessorManager.Run: Run the job. Feature=MicrosoftLicensing, Definition= [6744] 210322.221551.0974: NetworkHealthEngine: Feature WebApiHealthFeature: Start RunFilter [6744] 210322.221551.0974: NetworkHealthEngine: ActionProcessorManager.Run: Run the job. Feature=WebApiHealthFeature, Definition= [10596] 210322.221551.0984: NetworkHealthEngine: ActionProcessorManager.Run: Run the job. Feature=OPEServerAlert, Definition= [6744] 210322.221551.1355: NetworkHealthEngine: CreateFeatureAppDomain: Created AppDomain. name=WebApiHealthFeature, id=4. [8480] 210322.221551.1365: NetworkHealthEngine: CreateFeatureAppDomain: Created AppDomain. name=MicrosoftLicensing, id=7. [12376] 210322.221551.1375: NetworkHealthEngine: CreateFeatureAppDomain: Created AppDomain. name=MicrosoftServicing, id=2. [7672] 210322.221551.1375: NetworkHealthEngine: CreateFeatureAppDomain: Created AppDomain. name=ServerBackupFeature, id=5. [8064] 210322.221551.1385: NetworkHealthEngine: CreateFeatureAppDomain: Created AppDomain. name=ConnectivityFeature, id=6. [10596] 210322.221551.1385: NetworkHealthEngine: CreateFeatureAppDomain: Created AppDomain. name=OPEServerAlert, id=3. [2184] 210322.221551.1425: NetworkHealthEngine: CreateFeatureAppDomain: Created AppDomain. name=DomainManagementFeature, id=8. [10596] 210322.221551.1736: NetworkHealthEngine: ActionProcessorManager.Run: Run the job. Feature=AzureServiceAlerts, Definition=AzureSiteRecoveryAuthenticationFailed [8480] 210322.221551.1736: NetworkHealthEngine: ActionProcessorManager.Run: Run the job. Feature=ClientBackup, Definition=MaxClient [7672] 210322.221551.1736: NetworkHealthEngine: ActionProcessorManager.Run: Run the job. Feature=MicrosoftBase, Definition=RenewServerCertificate [6744] 210322.221551.1736: NetworkHealthEngine: ActionProcessorManager.Run: Run the job. Feature=MicrosoftBase, Definition=CheckEssentialsSKUUsersLimit [12376] 210322.221551.1736: NetworkHealthEngine: ActionProcessorManager.Run: Run the job. Feature=AzureServiceAlerts, Definition=AzureVirtualNetworkAuthenticationFailed [8064] 210322.221551.1736: NetworkHealthEngine: ActionProcessorManager.Run: Run the job. Feature=MicrosoftBase, Definition=Restart [2184] 210322.221551.1746: NetworkHealthEngine: ActionProcessorManager.Run: Run the job. Feature=ClientBackup, Definition=BackupService [7672] 210322.221551.1987: NetworkHealthEngine: CreateFeatureAppDomain: Created AppDomain. name=MicrosoftBase, id=11. [8480] 210322.221551.2027: NetworkHealthEngine: CreateFeatureAppDomain: Created AppDomain. name=ClientBackup, id=10. [10596] 210322.221551.2127: NetworkHealthEngine: CreateFeatureAppDomain: Created AppDomain. name=AzureServiceAlerts, id=9. [7672] 210322.221551.2157: NetworkHealthEngine: ActionProcessorManager.Run: Run the job. Feature=MicrosoftBase, Definition=AutoStartServicesServerOS [6744] 210322.221551.2157: NetworkHealthEngine: ActionProcessorManager.Run: Run the job. Feature=MicrosoftBase, Definition=AutoStartServicesSecondServerOS [7672] 210322.221551.2157: NetworkHealthEngine: ActionProcessorManager.Run: Run the job. Feature=MicrosoftBase, Definition=AutoStartServicesClientOS [6744] 210322.221551.2157: NetworkHealthEngine: ActionProcessorManager.Run: Run the job. Feature=MicrosoftBase, Definition=DesignatedActiveDirectoryServerDown [8064] 210322.221551.2157: NetworkHealthEngine: ActionProcessorManager.Run: Run the job. Feature=MicrosoftBase, Definition=OtherActiveDirectoryServerDown [6744] 210322.221551.2157: NetworkHealthEngine: ActionProcessorManager.Run: Run the job. Feature=MicrosoftBase, Definition=CriticalLowDiskSpace [10596] 210322.221551.2157: NetworkHealthEngine: ActionProcessorManager.Run: Run the job. Feature=MicrosoftBase, Definition=GracePeriodExpiredEVAL [8064] 210322.221551.2167: NetworkHealthEngine: ActionProcessorManager.Run: Run the job. Feature=MicrosoftBase, Definition=GracePeriodAboutToExpireEVAL [7672] 210322.221551.2157: NetworkHealthEngine: ActionProcessorManager.Run: Run the job. Feature=MicrosoftBase, Definition=StorageServiceNotRunning [12376] 210322.221551.2167: NetworkHealthEngine: ActionProcessorManager.Run: Run the job. Feature=MicrosoftBase, Definition=GracePeriodExpiredNoRearmEVAL [6744] 210322.221551.2167: NetworkHealthEngine: ActionProcessorManager.Run: Run the job. Feature=MicrosoftBase, Definition=GracePeriodAboutToExpireNoRearmEVAL [7672] 210322.221551.2167: NetworkHealthEngine: ActionProcessorManager.Run: Run the job. Feature=MicrosoftBase, Definition=GracePeriodExpiredRetail [8064] 210322.221551.2167: NetworkHealthEngine: ActionProcessorManager.Run: Run the job. Feature=MicrosoftBase, Definition=GracePeriodAboutToExpireRetail [12376] 210322.221551.2167: NetworkHealthEngine: ActionProcessorManager.Run: Run the job. Feature=CorenetFeature, Definition=FirewallServiceSecondServer [7672] 210322.221551.2167: NetworkHealthEngine: ActionProcessorManager.Run: Run the job. Feature=DeviceProviderReporting, Definition=WindowsDefenderStatus [8064] 210322.221551.2167: NetworkHealthEngine: ActionProcessorManager.Run: Run the job. Feature=HostedEmailAlerts, Definition=AuthenticationFailed [10596] 210322.221551.2167: NetworkHealthEngine: ActionProcessorManager.Run: Run the job. Feature=MicrosoftBase, Definition=DomainDnsFailure [10596] 210322.221551.2177: NetworkHealthEngine: ActionProcessorManager.Run: Run the job. Feature=O365Alerts, Definition=SubscriptionExpired [6744] 210322.221551.2167: NetworkHealthEngine: ActionProcessorManager.Run: Run the job. Feature=CorenetFeature, Definition=FirewallService [8480] 210322.221551.2197: NetworkHealthEngine: ActionProcessorManager.Run: Run the job. Feature=O365Alerts, Definition=AuthenticationFailed [2184] 210322.221551.2197: NetworkHealthEngine: ActionProcessorManager.Run: Run the job. Feature=O365Alerts, Definition=PasswordLengthConflict [7672] 210322.221551.2448: NetworkHealthEngine: CreateFeatureAppDomain: Created AppDomain. name=DeviceProviderReporting, id=13. [8064] 210322.221551.2458: NetworkHealthEngine: CreateFeatureAppDomain: Created AppDomain. name=HostedEmailAlerts, id=14. [12376] 210322.221551.2468: NetworkHealthEngine: CreateFeatureAppDomain: Created AppDomain. name=CorenetFeature, id=12. [10596] 210322.221551.2478: NetworkHealthEngine: CreateFeatureAppDomain: Created AppDomain. name=O365Alerts, id=15. [8064] 210322.221551.2628: NetworkHealthEngine: ActionProcessorManager.Run: Run the job. Feature=O365Alerts, Definition=PasswordComplexityConflict [10596] 210322.221551.2648: NetworkHealthEngine: ActionProcessorManager.Run: Run the job. Feature=PasswordSyncAlert, Definition=PasswordSyncInvalidPassword [8064] 210322.221551.2648: NetworkHealthEngine: ActionProcessorManager.Run: Run the job. Feature=PasswordSyncAlert, Definition=PasswordSyncOtherFailure [2184] 210322.221551.2648: NetworkHealthEngine: ActionProcessorManager.Run: Run the job. Feature=PasswordSyncAlert, Definition=PasswordSyncRebootPending [8480] 210322.221551.2648: NetworkHealthEngine: ActionProcessorManager.Run: Run the job. Feature=PasswordSyncAlert, Definition=CurrentServerPasswordSyncRebootPending [7672] 210322.221551.2658: NetworkHealthEngine: ActionProcessorManager.Run: Run the job. Feature=PasswordSyncAlert, Definition=PasswordSyncPcnsDisconnected [6744] 210322.221551.2678: NetworkHealthEngine: ActionProcessorManager.Run: Run the job. Feature=PasswordSyncAlert, Definition=PasswordSyncUpdateNeeded [12376] 210322.221551.2709: NetworkHealthEngine: ActionProcessorManager.Run: Run the job. Feature=MicrosoftSecurity, Definition=OnlineServicesPackageRegionChanged [9184] 210322.221551.2719: NetworkHealthEngine: ActionProcessorManager.Run: Run the job. Feature=MicrosoftSecurity, Definition=OnlineServicesPackageUpdate [10596] 210322.221551.2959: NetworkHealthEngine: CreateFeatureAppDomain: Created AppDomain. name=PasswordSyncAlert, id=16. [12376] 210322.221551.3009: NetworkHealthEngine: CreateFeatureAppDomain: Created AppDomain. name=MicrosoftSecurity, id=17. [2184] 210322.221551.3120: NetworkHealthEngine: ActionProcessorManager.Run: Run the job. Feature=MicrosoftSecurity, Definition=AntivirusDisabled [7672] 210322.221551.3130: NetworkHealthEngine: ActionProcessorManager.Run: Run the job. Feature=MicrosoftSecurity, Definition=AntispywareDisabled [6744] 210322.221551.3120: NetworkHealthEngine: ActionProcessorManager.Run: Run the job. Feature=MicrosoftSecurity, Definition=FirewallDisabled [8480] 210322.221551.3130: NetworkHealthEngine: ActionProcessorManager.Run: Run the job. Feature=MicrosoftSecurity, Definition=WindowsDefenderThreat [12740] 210322.221551.3210: NetworkHealthEngine: Try send definition updated notification to all clients [12740] 210322.221551.3822: AlertFramework: Subcomponent: HealthEvaluator > Evaluating Feature: DeviceProviderReporting [12740] 210322.221551.4042: AlertFramework: Subcomponent: HealthEvaluator > Executing Feature: DeviceProviderReporting, Definition: DomainJoinStatusInfo [2184] 210322.221551.4052: NetworkHealthEngine: ActionProcessorManager.Run: Run the job. Feature=DeviceProviderReporting, Definition=DomainJoinStatusInfo [12740] 210322.221551.4333: AlertFramework: Subcomponent: HealthEvaluator > Executing Feature: DeviceProviderReporting, Definition: WindowsDefenderStatus [8480] 210322.221551.4333: NetworkHealthEngine: ActionProcessorManager.Run: Run the job. Feature=DeviceProviderReporting, Definition=WindowsDefenderStatus [2184] 210322.221551.4433: AlertFramework: Subcomponent: HealthEvaluator > Completed executing Feature: DeviceProviderReporting, Definition: DomainJoinStatusInfo, Time elapsed: 0.0381011 sec [12740] 210322.221551.4574: AlertFramework: Subcomponent: HealthEvaluator > Executing Feature: DeviceProviderReporting, Definition: OperatingSystemInfo [10596] 210322.221551.4574: NetworkHealthEngine: ActionProcessorManager.Run: Run the job. Feature=DeviceProviderReporting, Definition=OperatingSystemInfo [12740] 210322.221551.4794: AlertFramework: Subcomponent: HealthEvaluator > Executing Feature: DeviceProviderReporting, Definition: RDPInfo [12376] 210322.221551.4794: NetworkHealthEngine: ActionProcessorManager.Run: Run the job. Feature=DeviceProviderReporting, Definition=RDPInfo [12740] 210322.221551.4965: AlertFramework: Subcomponent: HealthEvaluator > Executing Feature: DeviceProviderReporting, Definition: WindowsUpdateDetailInfo [2184] 210322.221551.4975: NetworkHealthEngine: ActionProcessorManager.Run: Run the job. Feature=DeviceProviderReporting, Definition=WindowsUpdateDetailInfo [10596] 210322.221551.5195: AlertFramework: Subcomponent: HealthEvaluator > Completed executing Feature: DeviceProviderReporting, Definition: OperatingSystemInfo, Time elapsed: 0.0621662 sec [12376] 210322.221551.5436: AlertFramework: Subcomponent: HealthEvaluator > Completed executing Feature: DeviceProviderReporting, Definition: RDPInfo, Time elapsed: 0.0641705 sec [2184] 210322.221555.6044: AlertFramework: Subcomponent: HealthEvaluator > Completed executing Feature: DeviceProviderReporting, Definition: WindowsUpdateDetailInfo, Time elapsed: 4.106926 sec [11880] 210322.221558.2865: AlertFramework: OperationContext.Current.GetCallbackChannel<IAlertProviderCallback> returns null. [1836] 210322.221558.2865: AlertFramework: OperationContext.Current.GetCallbackChannel<IAlertProviderCallback> returns null. [12456] 210322.221558.2885: AlertFramework: OperationContext.Current.GetCallbackChannel<IAlertProviderCallback> returns null. [12456] 210322.221558.2905: AlertFramework: Subcomponent: AlertSynchCallbackRegistry > RegisterCallback: Registered callback for machine S-1-5-21-4047155118-1370865027-4003916951-1124 [11880] 210322.221558.2905: AlertFramework: Subcomponent: AlertSynchCallbackRegistry > RegisterCallback: Registered callback for machine S-1-5-21-4047155118-1370865027-4003916951-1125 [1836] 210322.221558.2905: AlertFramework: Subcomponent: AlertSynchCallbackRegistry > RegisterCallback: Registered callback for machine S-1-5-21-4047155118-1370865027-4003916951-1116 [9012] 210322.221558.3026: AlertFramework: OperationContext.Current.GetCallbackChannel<IAlertProviderCallback> returns null. [9012] 210322.221558.3026: AlertFramework: Subcomponent: AlertSynchCallbackRegistry > RegisterCallback: Registered callback for machine S-1-5-21-4047155118-1370865027-4003916951-1127

Windows Server
Windows Server
A family of Microsoft server operating systems that support enterprise-level management, data storage, applications, and communications.
12,127 questions
0 comments No comments
{count} votes

1 answer

Sort by: Most helpful
  1. Carl Fan 6,836 Reputation points
    2021-03-24T09:28:40.857+00:00

    Hi,
    According to your description, I consider that you could try to use process monitor tool to capture the process when the service start/ stop.
    From the procmon, it could record that the process crashed when accessing some files or registry.
    https://learn.microsoft.com/en-us/sysinternals/downloads/procmon
    Hope this helps and please help to accept as Answer if the response is useful.
    Best Regards,
    Carl

    0 comments No comments