Event ID 5616, 5617, 5783 Netlogon Error 2019 Standard Server

Andrew Musson 1 Reputation point
2022-03-31T19:16:11.38+00:00

I have searched all over for this issue and haven't been able to solve it. Approximately 22 hours after a server reboot we get the Event ID's mentioned above. Once that happens we can no longer login to the machine via RDP or physically at the machine. This server is not local to me, therefore I have to reboot it through powershell. It's becoming a nuisance as I have daily tasks on this server. I have tried to remotely restart services but they fail once this happens as it loses connectivity to the "domain". I have tried to do it via local admin login and that fails too. This is a brand new HP DL 380 Gen 10 server, less than a year old. This started happening in February. We installed last July and had no issues until then. I can't find a remedy for this and was hoping beyond hope that maybe someone would have an idea. I have 10 of these servers out in the wild and this is the only one having issues.

I'll say that I've noticed that a solarwinds orion error in the Netlogon description, our client runs solarwinds on their network and have an agent running on this box. Not sure if this is causing it, I have removed it for 48 hours and we still had issues so I'm not sure that's the case.

It runs:
Windows 2019 Standard
SQL 2016 Standard
Proprietary software
Hyper-V (3 small linux installations)

That is all. It's a dual core Silver Xeon processor with 192GB of ram and all solid state drives. Anyone have any ideas? I'm at my wits end here.

Windows for business | Windows Server | User experience | Other
0 comments No comments
{count} votes

6 answers

Sort by: Most helpful
  1. Anonymous
    2022-03-31T19:27:26.073+00:00

    5783 is a secure channel problem. Something here could help.
    https://awinish.wordpress.com/2010/12/24/when-secure-channel-is-broken/
    https://techcommunity.microsoft.com/t5/core-infrastructure-and-security/quick-reference-troubleshooting-netlogon-error-codes/ba-p/256000

    --please don't forget to upvote and Accept as answer if the reply is helpful--


  2. Andrew Musson 1 Reputation point
    2022-04-01T16:48:38.373+00:00

    I have setup Netlogon logging on this device. I will repost once I have a better understanding of what is occurring here. I did re-establish the Secure Channel so I'm hoping that'll fix some of these issues. I'll let you know this weekend.


  3. Andrew Musson 1 Reputation point
    2022-04-05T14:12:13.547+00:00

    Unfortunately no. It still occurs around 10 AM every day, longest it has gone was 3 days recently and the only thing I can find is there happens to be a break in the secure channel according to the Netlogon debugging logs and once that happens I lose connectivity. I am unable to restart DNS Client, Netlogon and a few other services. Restarting the network cards do nothing, the only way to log back in is to reboot. Once I reboot, all services generally work until the following day.

    0 comments No comments

  4. Andrew Musson 1 Reputation point
    2022-04-05T14:12:13.597+00:00

    Unfortunately no. It still occurs around 10 AM every day, longest it has gone was 3 days recently and the only thing I can find is there happens to be a break in the secure channel according to the Netlogon debugging logs and once that happens I lose connectivity. I am unable to restart DNS Client, Netlogon and a few other services. Restarting the network cards do nothing, the only way to log back in is to reboot. Once I reboot, all services generally work until the following day.

    0 comments No comments

  5. Anonymous
    2022-04-05T14:38:10.37+00:00

    Might try standing up a new one as a test.

    I'd use dcdiag / repadmin tools to verify health correcting all errors found before starting any operations. Then stand up the new 2019, patch it fully, license it, join existing domain, add active directory domain services, promote it also making it a GC (recommended), transfer FSMO roles over (optional), transfer pdc emulator role (optional), use dcdiag / repadmin tools to again verify health.

    If the issue does not occur on this new one then consider using it as a replacement for the faulty one.

    --please don't forget to upvote and Accept as answer if the reply is helpful--


Your answer

Answers can be marked as 'Accepted' by the question author and 'Recommended' by moderators, which helps users know the answer solved the author's problem.