DFSR

EventTitleChannelSampleRule
1002The DFS Replication service is starting.DFS ReplicationYN
1004The DFS Replication service has started.DFS ReplicationYN
1006The DFS Replication service is stopping.DFS ReplicationYN
1008The DFS Replication service has stopped.DFS ReplicationYN
1102The DFS Replication service has temporarily stopped replication because another …DFS ReplicationYN
1104The DFS Replication service successfully restarted replication after a backup or …DFS ReplicationYN
1202The DFS Replication service failed to contact domain controller !DFS ReplicationYN
1206The DFS Replication service successfully contacted domain controller …DFS ReplicationYN
1210The DFS Replication service successfully set up an RPC listener for incoming …DFS ReplicationYN
1314The DFS Replication service successfully configured the debug log files.DFS ReplicationYN
2212Event ID 2212DFS ReplicationYN
2214Event ID 2214DFS ReplicationYN
2218Event ID 2218DFS ReplicationYN
4602The DFS Replication service successfully initialized the SYSVOL replicated …DFS ReplicationYN
6016The DFS Replication service failed to update configuration in Active Directory …DFS ReplicationYN
6018The DFS Replication service successfully updated configuration in Active …DFS ReplicationYN
6102The DFS Replication service has successfully registered the WMI provider.DFS ReplicationYN
6104The DFS Replication service failed to register the WMI providers.DFS ReplicationYN
8000The DFSR global settings required for SYSVOL migration have been successfully …DFS ReplicationYN

Event ID 1002: The DFS Replication service is starting.

#
Channel
DFS Replication
Level
Informational

Example Event #

{
  "system": {
    "provider": "DFSR",
    "guid": "",
    "event_source_name": "",
    "event_id": 1002,
    "version": 0,
    "level": 4,
    "task": 0,
    "opcode": 0,
    "keywords": 36028797018963968,
    "time_created": "2026-05-29T16:33:06.8397079+00:00",
    "event_record_id": 101,
    "correlation": {},
    "execution": {
      "process_id": 0,
      "thread_id": 0
    },
    "channel": "DFS Replication",
    "computer": "telemetry-DC-a.cell-a.ludus.domain",
    "security": {
      "user_id": ""
    }
  },
  "event_data": {},
  "message": "The DFS Replication service is starting."
}

Event ID 1004: The DFS Replication service has started.

#
Channel
DFS Replication
Level
Informational

Example Event #

{
  "system": {
    "provider": "DFSR",
    "guid": "",
    "event_source_name": "",
    "event_id": 1004,
    "version": 0,
    "level": 4,
    "task": 0,
    "opcode": 0,
    "keywords": 36028797018963968,
    "time_created": "2026-05-29T16:33:06.8397079+00:00",
    "event_record_id": 102,
    "correlation": {},
    "execution": {
      "process_id": 0,
      "thread_id": 0
    },
    "channel": "DFS Replication",
    "computer": "telemetry-DC-a.cell-a.ludus.domain",
    "security": {
      "user_id": ""
    }
  },
  "event_data": {},
  "message": "The DFS Replication service has started."
}

Event ID 1006: The DFS Replication service is stopping.

#
Channel
DFS Replication
Level
Informational

Example Event #

{
  "system": {
    "provider": "DFSR",
    "guid": "",
    "event_source_name": "",
    "event_id": 1006,
    "version": 0,
    "level": 4,
    "task": 0,
    "opcode": 0,
    "keywords": 36028797018963968,
    "time_created": "2026-06-13T05:22:34.5079118+00:00",
    "event_record_id": 101,
    "correlation": {},
    "execution": {
      "process_id": 0,
      "thread_id": 0
    },
    "channel": "DFS Replication",
    "computer": "telemetry-DC-c.cell-c.ludus.domain",
    "security": {
      "user_id": ""
    }
  },
  "event_data": {},
  "message": "The DFS Replication service is stopping."
}

Event ID 1008: The DFS Replication service has stopped.

#
Channel
DFS Replication
Level
Informational

Example Event #

{
  "system": {
    "provider": "DFSR",
    "guid": "",
    "event_source_name": "",
    "event_id": 1008,
    "version": 0,
    "level": 4,
    "task": 0,
    "opcode": 0,
    "keywords": 36028797018963968,
    "time_created": "2022-04-07T08:12:41.226907+00:00",
    "event_record_id": 7,
    "correlation": {},
    "execution": {
      "process_id": 0,
      "thread_id": 0
    },
    "channel": "DFS Replication",
    "computer": "WIN-FPV0DSIC9O6",
    "security": {
      "user_id": ""
    }
  },
  "event_data": {},
  "message": "The DFS Replication service has stopped."
}

References #

Event ID 1102: The DFS Replication service has temporarily stopped replication because another application is performing a backup or restore operation.

#
Channel
DFS Replication
Level
4

Example Event #

{
  "system": {
    "provider": "DFSR",
    "guid": "",
    "event_source_name": "",
    "event_id": 1102,
    "version": 0,
    "level": 4,
    "task": 0,
    "opcode": 0,
    "keywords": 36028797018963968,
    "time_created": "2026-05-30T02:25:25.5517058+00:00",
    "event_record_id": 160,
    "correlation": {},
    "execution": {
      "process_id": 0,
      "thread_id": 0
    },
    "channel": "DFS Replication",
    "computer": "JD-DC01-2022.ludus.domain",
    "security": {
      "user_id": ""
    }
  },
  "event_data": {},
  "message": "The DFS Replication service has temporarily stopped replication because another application is performing a backup or restore operation. Replication will resume after the backup or restore operation has finished."
}

Event ID 1104: The DFS Replication service successfully restarted replication after a backup or restore operation.

#
Channel
DFS Replication
Level
4

Example Event #

{
  "system": {
    "provider": "DFSR",
    "guid": "",
    "event_source_name": "",
    "event_id": 1104,
    "version": 0,
    "level": 4,
    "task": 0,
    "opcode": 0,
    "keywords": 36028797018963968,
    "time_created": "2026-05-30T02:25:27.9448512+00:00",
    "event_record_id": 162,
    "correlation": {},
    "execution": {
      "process_id": 0,
      "thread_id": 0
    },
    "channel": "DFS Replication",
    "computer": "JD-DC01-2022.ludus.domain",
    "security": {
      "user_id": ""
    }
  },
  "event_data": {},
  "message": "The DFS Replication service successfully restarted replication after a backup or restore operation."
}

Event ID 1202: The DFS Replication service failed to contact domain controller !

#
Channel
DFS Replication
Level
Error

Fields #

NameDescription
Data_0
Data_1
Data_2
Data_3
Data

Example Event #

{
  "system": {
    "provider": "DFSR",
    "guid": "",
    "event_source_name": "",
    "event_id": 1202,
    "version": 0,
    "level": 2,
    "task": 0,
    "opcode": 0,
    "keywords": 36028797018963968,
    "time_created": "2026-05-29T16:33:29.4803144+00:00",
    "event_record_id": 105,
    "correlation": {},
    "execution": {
      "process_id": 0,
      "thread_id": 0
    },
    "channel": "DFS Replication",
    "computer": "telemetry-DC-a.cell-a.ludus.domain",
    "security": {
      "user_id": ""
    }
  },
  "event_data": {
    "Data_0": "",
    "Data_1": "60",
    "Data_2": "160",
    "Data_3": "One or more arguments are not correct."
  },
  "message": "The DFS Replication service failed to contact domain controller  to access configuration information. Replication is stopped. The service will try again during the next configuration polling cycle, which will occur in 60 minutes. This event can be caused by TCP/IP connectivity, firewall, Active Directory Domain Services, or DNS issues. \r\n \r\nAdditional Information: \r\nError: 160 (One or more arguments are not correct.)"
}

References #

Event ID 1206: The DFS Replication service successfully contacted domain controller WIN-FPV0DSIC9O6.

#
Channel
DFS Replication
Level
Informational

Fields #

NameDescription
Data_0
Data

Example Event #

{
  "system": {
    "provider": "DFSR",
    "guid": "",
    "event_source_name": "",
    "event_id": 1206,
    "version": 0,
    "level": 4,
    "task": 0,
    "opcode": 0,
    "keywords": 36028797018963968,
    "time_created": "2026-05-29T16:38:30.5115515+00:00",
    "event_record_id": 106,
    "correlation": {},
    "execution": {
      "process_id": 0,
      "thread_id": 0
    },
    "channel": "DFS Replication",
    "computer": "telemetry-DC-a.cell-a.ludus.domain",
    "security": {
      "user_id": ""
    }
  },
  "event_data": {
    "Data_0": "telemetry-DC-a.cell-a.ludus.domain"
  },
  "message": "The DFS Replication service successfully contacted domain controller telemetry-DC-a.cell-a.ludus.domain to access configuration information."
}

Event ID 1210: The DFS Replication service successfully set up an RPC listener for incoming replication requests.

#
Channel
DFS Replication
Level
Informational

Fields #

NameDescription
Data_0
Data

Example Event #

{
  "system": {
    "provider": "DFSR",
    "guid": "",
    "event_source_name": "",
    "event_id": 1210,
    "version": 0,
    "level": 4,
    "task": 0,
    "opcode": 0,
    "keywords": 36028797018963968,
    "time_created": "2026-05-29T16:38:30.7928092+00:00",
    "event_record_id": 107,
    "correlation": {},
    "execution": {
      "process_id": 0,
      "thread_id": 0
    },
    "channel": "DFS Replication",
    "computer": "telemetry-DC-a.cell-a.ludus.domain",
    "security": {
      "user_id": ""
    }
  },
  "event_data": {
    "Data_0": "0"
  },
  "message": "The DFS Replication service successfully set up an RPC listener for incoming replication requests. \r\n \r\nAdditional Information: \r\nPort: 0"
}

Event ID 1314: The DFS Replication service successfully configured the debug log files.

#
Channel
DFS Replication
Level
Informational

Fields #

NameDescription
Data_0
Data

Example Event #

{
  "system": {
    "provider": "DFSR",
    "guid": "",
    "event_source_name": "",
    "event_id": 1314,
    "version": 0,
    "level": 4,
    "task": 0,
    "opcode": 0,
    "keywords": 36028797018963968,
    "time_created": "2026-05-29T16:33:17.9646683+00:00",
    "event_record_id": 103,
    "correlation": {},
    "execution": {
      "process_id": 0,
      "thread_id": 0
    },
    "channel": "DFS Replication",
    "computer": "telemetry-DC-a.cell-a.ludus.domain",
    "security": {
      "user_id": ""
    }
  },
  "event_data": {
    "Data_0": "C:\\Windows\\debug"
  },
  "message": "The DFS Replication service successfully configured the debug log files. \r\n \r\nAdditional Information: \r\nDebug Log File Path: C:\\Windows\\debug"
}

Event ID 2212

#
Channel
DFS Replication
Level
Warning

Fields #

NameDescription
Data_0
Data_1
Binary

Example Event #

{
  "system": {
    "provider": "DFSR",
    "guid": "",
    "event_source_name": "",
    "event_id": 2212,
    "version": 0,
    "level": 3,
    "task": 0,
    "opcode": 0,
    "keywords": 36028797018963968,
    "time_created": "2026-03-06T19:19:21.663747+00:00",
    "event_record_id": 54,
    "correlation": {},
    "execution": {
      "process_id": 0,
      "thread_id": 0
    },
    "channel": "DFS Replication",
    "computer": "LAB-DC01.ludus.domain",
    "security": {
      "user_id": ""
    }
  },
  "event_data": {
    "Data_0": "77AC4D73-0000-0000-0000-100000000000",
    "Data_1": "C:",
    "Binary": ""
  },
  "message": ""
}

Event ID 2214

#
Channel
DFS Replication
Level
Informational

Fields #

NameDescription
Data_0
Data_1
Binary

Example Event #

{
  "system": {
    "provider": "DFSR",
    "guid": "",
    "event_source_name": "",
    "event_id": 2214,
    "version": 0,
    "level": 4,
    "task": 0,
    "opcode": 0,
    "keywords": 36028797018963968,
    "time_created": "2026-03-06T19:19:21.926999+00:00",
    "event_record_id": 56,
    "correlation": {},
    "execution": {
      "process_id": 0,
      "thread_id": 0
    },
    "channel": "DFS Replication",
    "computer": "LAB-DC01.ludus.domain",
    "security": {
      "user_id": ""
    }
  },
  "event_data": {
    "Data_0": "77AC4D73-0000-0000-0000-100000000000",
    "Data_1": "C:",
    "Binary": ""
  },
  "message": ""
}

Event ID 2218

#
Channel
DFS Replication
Level
Informational

Fields #

NameDescription
Data_0
Data_1
Binary

Example Event #

{
  "system": {
    "provider": "DFSR",
    "guid": "",
    "event_source_name": "",
    "event_id": 2218,
    "version": 0,
    "level": 4,
    "task": 0,
    "opcode": 0,
    "keywords": 36028797018963968,
    "time_created": "2026-03-06T19:19:21.668342+00:00",
    "event_record_id": 55,
    "correlation": {},
    "execution": {
      "process_id": 0,
      "thread_id": 0
    },
    "channel": "DFS Replication",
    "computer": "LAB-DC01.ludus.domain",
    "security": {
      "user_id": ""
    }
  },
  "event_data": {
    "Data_0": "77AC4D73-0000-0000-0000-100000000000",
    "Data_1": "C:",
    "Binary": ""
  },
  "message": ""
}

Event ID 4602: The DFS Replication service successfully initialized the SYSVOL replicated folder at local path C:\Windows\SYSVOL\domain!

#
Channel
DFS Replication
Level
Informational

Fields #

NameDescription
Data_0
Data_1
Data_2
Data_3
Data_4
Data_5
Data_6
Data_7
Data

Example Event #

{
  "system": {
    "provider": "DFSR",
    "guid": "",
    "event_source_name": "",
    "event_id": 4602,
    "version": 0,
    "level": 4,
    "task": 0,
    "opcode": 0,
    "keywords": 36028797018963968,
    "time_created": "2026-05-29T16:38:31.1990471+00:00",
    "event_record_id": 108,
    "correlation": {},
    "execution": {
      "process_id": 0,
      "thread_id": 0
    },
    "channel": "DFS Replication",
    "computer": "telemetry-DC-a.cell-a.ludus.domain",
    "security": {
      "user_id": ""
    }
  },
  "event_data": {
    "Data_0": "354B2C44-CF96-4B0D-864C-ECA004DEA393",
    "Data_1": "C:\\Windows\\SYSVOL\\domain",
    "Data_2": "SYSVOL Share",
    "Data_3": "Domain System Volume",
    "Data_4": "F9C3F360-BC8E-4EEF-B424-5E5180AF603F",
    "Data_5": "86935E2F-8382-4422-8AEA-DF39C44C57B3",
    "Data_6": "",
    "Data_7": "0"
  },
  "message": "The DFS Replication service successfully initialized the SYSVOL replicated folder at local path C:\\Windows\\SYSVOL\\domain. This member is the designated primary member for this replicated folder. No user action is required. To check for the presence of the SYSVOL share, open a command prompt window and then type \"net share\". \r\n \r\nAdditional Information: \r\nReplicated Folder Name: SYSVOL Share \r\nReplicated Folder ID: 354B2C44-CF96-4B0D-864C-ECA004DEA393 \r\nReplication Group Name: Domain System Volume \r\nReplication Group ID: F9C3F360-BC8E-4EEF-B424-5E5180AF603F \r\nMember ID: 86935E2F-8382-4422-8AEA-DF39C44C57B3 \r\nRead-Only: 0"
}

Event ID 6016: The DFS Replication service failed to update configuration in Active Directory Domain Services.

#
Channel
DFS Replication
Level
Warning

Fields #

NameDescription
Data

Example Event #

{
  "system": {
    "provider": "DFSR",
    "guid": "",
    "event_source_name": "",
    "event_id": 6016,
    "version": 0,
    "level": 3,
    "task": 0,
    "opcode": 0,
    "keywords": 36028797018963968,
    "time_created": "2022-04-07T08:15:11.856970+00:00",
    "event_record_id": 14,
    "correlation": {},
    "execution": {
      "process_id": 0,
      "thread_id": 0
    },
    "channel": "DFS Replication",
    "computer": "WIN-FPV0DSIC9O6.lab.local",
    "security": {
      "user_id": ""
    }
  },
  "event_data": {
    "Data": [
      "msDFSR-LocalSettings",
      "CN=DFSR-LocalSettings,CN=WIN-FPV0DSIC9O6,OU=Domain Controllers,DC=sigma,DC=fr",
      "1355",
      "The specified domain either does not exist or could not be contacted.",
      "",
      "60"
    ]
  },
  "message": "The DFS Replication service failed to update configuration in Active Directory\r\nDomain Services. The service will retry this operation periodically.\r\n\n\r\n\nAdditional Information:\r\n\nObject Category: msDFSR-LocalSettings!s!\r\n\nObject DN: CN=DFSR-LocalSettings,CN=WIN-FPV0DSIC9O6,OU=Domain Controllers,DC=sigma,DC=fr!s!\r\n\nError: 1355!s! (The specified domain either does not exist or could not be contacted.!s!)\r\n\nDomain Controller: !s!\r\n\nPolling Cycle: 60!s!"
}

References #

Event ID 6018: The DFS Replication service successfully updated configuration in Active Directory Domain Services.

#
Channel
DFS Replication
Level
Informational

Fields #

NameDescription
Data_0
Data_1
Data

Example Event #

{
  "system": {
    "provider": "DFSR",
    "guid": "",
    "event_source_name": "",
    "event_id": 6018,
    "version": 0,
    "level": 4,
    "task": 0,
    "opcode": 0,
    "keywords": 36028797018963968,
    "time_created": "2026-05-28T00:51:59.7621261+00:00",
    "event_record_id": 17,
    "correlation": {},
    "execution": {
      "process_id": 0,
      "thread_id": 0
    },
    "channel": "DFS Replication",
    "computer": "telemetry-DC-d.cell-d.ludus.domain",
    "security": {
      "user_id": ""
    }
  },
  "event_data": {
    "Data_0": "telemetry-DC-d.cell-d.ludus.domain",
    "Data_1": "60"
  },
  "message": "The DFS Replication service successfully updated configuration in Active Directory Domain Services. \r\n \r\nAdditional Information: \r\nDomain Controller: telemetry-DC-d.cell-d.ludus.domain \r\nPolling Cycle: 60 minutes"
}

Event ID 6102: The DFS Replication service has successfully registered the WMI provider.

#
Channel
DFS Replication
Level
Informational

Example Event #

{
  "system": {
    "provider": "DFSR",
    "guid": "",
    "event_source_name": "",
    "event_id": 6102,
    "version": 0,
    "level": 4,
    "task": 0,
    "opcode": 0,
    "keywords": 36028797018963968,
    "time_created": "2026-05-29T16:33:28.2615485+00:00",
    "event_record_id": 104,
    "correlation": {},
    "execution": {
      "process_id": 0,
      "thread_id": 0
    },
    "channel": "DFS Replication",
    "computer": "telemetry-DC-a.cell-a.ludus.domain",
    "security": {
      "user_id": ""
    }
  },
  "event_data": {},
  "message": "The DFS Replication service has successfully registered the WMI provider."
}

Event ID 6104: The DFS Replication service failed to register the WMI providers.

#
Channel
DFS Replication
Level
Error

Fields #

NameDescription
Data

Example Event #

{
  "system": {
    "provider": "DFSR",
    "guid": "",
    "event_source_name": "",
    "event_id": 6104,
    "version": 0,
    "level": 2,
    "task": 0,
    "opcode": 0,
    "keywords": 36028797018963968,
    "time_created": "2022-04-07T17:06:57.857830+00:00",
    "event_record_id": 4,
    "correlation": {},
    "execution": {
      "process_id": 0,
      "thread_id": 0
    },
    "channel": "DFS Replication",
    "computer": "WIN-FPV0DSIC9O6",
    "security": {
      "user_id": ""
    }
  },
  "event_data": {
    "Data": [
      "2147749902",
      "100e"
    ]
  },
  "message": "The DFS Replication service failed to register the WMI providers. Replication\r\nis disabled until the problem is resolved.\r\n\n\r\n\nAdditional Information:\r\n\nError: 2147749902!s! (100e!s!)"
}

References #

Event ID 8000: The DFSR global settings required for SYSVOL migration have been successfully created on the Primary Domain Controller WIN-FPV0DSIC9O6!

#
Channel
DFS Replication
Level
Informational

Fields #

NameDescription
Data

Example Event #

{
  "system": {
    "provider": "DFSR",
    "guid": "",
    "event_source_name": "",
    "event_id": 8000,
    "version": 0,
    "level": 4,
    "task": 0,
    "opcode": 0,
    "keywords": 36028797018963968,
    "time_created": "2022-04-07T08:15:11.778898+00:00",
    "event_record_id": 13,
    "correlation": {},
    "execution": {
      "process_id": 0,
      "thread_id": 0
    },
    "channel": "DFS Replication",
    "computer": "WIN-FPV0DSIC9O6.lab.local",
    "security": {
      "user_id": ""
    }
  },
  "event_data": {
    "Data": [
      "WIN-FPV0DSIC9O6"
    ]
  },
  "message": "The DFSR global settings required for SYSVOL migration have been\r\nsuccessfully created on the Primary Domain Controller WIN-FPV0DSIC9O6!s!.\r\nMigration will not be triggered until the DFSR global settings\r\nare replicated to all the Domain Controllers.\r\n\n\r\n\nAdditional Information:\r\n\nPrimary Domain Controller: WIN-FPV0DSIC9O6!s!"
}

References #