Overview
The DFS Replication Events test appears under AD Replication for domain controllers. AD Replication covers four related tests — Replication Status, Diagnostics, AD Events and DFS Replication. This page covers DFS Replication Events.
Monitoring Benefit
This test watches the DFS Replication event log on each domain controller for the events that indicate SYSVOL replication is in trouble, and changes the indicator when it finds one.
SYSVOL is where Group Policy and logon scripts live, and DFSR is what keeps it consistent between domain controllers. That makes this failure quieter and more damaging than most: Active Directory replication can be perfectly healthy while SYSVOL silently diverges. Nothing breaks. Users just start receiving different policy depending on which domain controller authenticated them, which is close to impossible to diagnose from the client side.
This complements AD Replication Status rather than duplicating it. That test reports whether directory replication attempts are succeeding; this one reports what Windows has logged about file replication, which is a separate mechanism with separate failure modes.
What tends to be behind it
| Condition | Why it matters |
|---|---|
| The replicated folder is no longer replicating | DFSR has stopped the folder, usually after a problem it could not resolve. SYSVOL is now stale on that DC and will drift further. |
| A dirty shutdown or journal wrap | Follows an unexpected reboot or a full volume. DFSR may not recover on its own and can need manual intervention. |
| The DFSR database is rebuilding | Often transient and self-clearing, but worth knowing about because replication is paused while it happens. |
| Staging area problems | The staging quota is too small for the content being replicated, so DFSR churns and falls behind. |
| Content freshness exceeded | The DC has been disconnected longer than the tombstone period. It will not resume replicating without being reinitialised. |
How do we verify the monitoring test results?
1. Check what ENow recorded. From EMS 8.0 onward, collected results are held in the ENow SQL database rather than in files on the web server. Open the AD Replication monitoring page for that domain controller in the ENow console.
2. Check the client-side cache on the domain controller. The ENow agent stores its results on the monitored server rather than logging them:
\Program Files (x86)\ENow\Mailscape Agent\Cache\NetworkAgentMessage.xml
This is on the monitored domain controller, not the ENow web server.
3. Read the event itself. The alert names the event that was found. On the affected DC, open the dedicated DFS Replication log — it is not in the System log:
Get-WinEvent -LogName "DFS Replication" -MaxEvents 50 |
Where-Object LevelDisplayName -in 'Error','Warning' |
Format-List TimeCreated, Id, LevelDisplayName, Message
4. Ask DFSR directly what state it is in. The event tells you what happened; this tells you where things stand now:
dfsrdiag ReplicationState /all
Get-DfsrState -ComputerName <domain controller>
(Get-WmiObject -Namespace root\microsoftdfs -Class dfsrreplicatedfolderinfo).State
5. Confirm whether SYSVOL actually diverged. Compare the contents of \\<dc>\SYSVOL\<domain>\Policies across two domain controllers. A difference in the policy folders is the symptom users will eventually feel.
Common warning or error results, and potential solutions
| Result | Potential solution |
|---|---|
| Events on one DC only | Work that domain controller. Confirm the DFS Replication service is running and check its disk for space. |
| Events on several DCs at once | Look at what they share — a partner that has gone offline, or a site link. DFSR errors propagate outward from the partner that stopped. |
| Errors after an unexpected reboot | Likely a dirty shutdown. Check whether DFSR recovered on its own before intervening; it often does. |
| The indicator clears and returns | Something is failing and retrying. Check the staging quota and the volume's free space rather than treating each occurrence separately. |
| AD replication healthy, DFS Replication failing | Expected and important. They are separate mechanisms — directory objects are replicating while SYSVOL files are not. |
| Group Policy applying inconsistently | Check this test first. Inconsistent policy across DCs is the classic downstream symptom of SYSVOL divergence. |
Comments
0 comments
Article is closed for comments.