Build a great reporting interface using Splunk, one of the leaders in the Security Information and Event Management (SIEM) field, linking the collected Windows events to www.eventid.net. The EventId.Net for Splunk Add-on assumes that Splunk is collecting information from Windows servers and workstation via the Splunk Universal Forwarder.
The DHCP Client service is shutting down. The following error occurred: <error>.
|English: Request a translation of the event description in plain English.|
|Concepts to understand:|
What is a DHCP Lease?
I had this error on a 2003 R2 SP2 DC. Turned out to be the permissions issue. What gave me a bit of trouble was broken inheritance of rights on the HKLM\SYSTEM\CurrentControlSet\Services\Dhcp\Parameters subkey. I had tried setting the 'Full Control' right to 'Network Services' account on the Dhcp key and checked inheritance - but didn't think of the possibility of broken inheritance.
WITP83228 provides information that can help you solve this problem.
Check registry permissions on the HKLM\SYSTEM\CurrentControlSet\Services\Dhcp\Parameters registry key. I had this error in Win2003 when the NETWORK SERVICE group did not have Full Control.
With error Access Denied (Error code 5), you can determine the registry keys which have to be fixed, by using Process Monitor from Sysinternals. Define the filter as “errors only”, and then try to start the DHCP client service.
According to Microsoft, this event record indicates that the DHCP database is corrupted. See MSW2KDB for more details on this event.
|Private comment: Subscribers only. See example of private comment|
|Links: Process Monitor from Sysinternals|
|Search: Google - Bing - Microsoft - Yahoo - EventID.Net Queue (0) - More links...|
|Custom search for *****: Google - Bing - Microsoft - Yahoo|
Send comments or solutions
- Notify me when updated