Build a great reporting interface using Splunk, one of the leaders in the Security Information and Event Management (SIEM) field, linking the collected Windows events to www.eventid.net. The EventId.Net for Splunk Add-on assumes that Splunk is collecting information from Windows servers and workstation via the Splunk Universal Forwarder.
The time provider 'NtpClient' failed to start due to the following error: <error message>. (<error code>).
|English: Request a translation of the event description in plain English.|
- Error: "An attempt was made to perform an initialization operation when initialization has already been completed (0x800704DF)" - This error can occur when w32tm crashes but somehow manages to leave svchost.exe holding port 123 open. Subsequent attempts to start w32tm result in this event being logged as w32tm cannot bind to port 123. Debug logging reveals the same error text as in the event log and that 0 NTP clients were started. Rebooting the system frees port 123 and w32tm can start (assuming no other configuration problems make it crash again).
I imagine if a 3rd party NTP application (or any other application using port 123 UDP) was running first then w32tm would also show this error when you try to start it.
|Private comment: Subscribers only. See example of private comment|
|Search: Google - Bing - Microsoft - Yahoo - EventID.Net Queue (0) - More links...|
Send comments or solutions
- Notify me when updated