Cluster Service failed to create a cluster identity token for Cluster Shared Volumes

Microsoft.Windows.10.0.Cluster.Cluster.Service.failed.to.create.a.cluster.identity.token.for.Cluster.Shared.Volumes (Rule)

Knowledge Base article:

Summary

In a failover cluster, virtual machines can use Cluster Shared Volumes that are on the same LUN (disk), while still being able to fail over (or move from node to node) independently of one another. Virtual machines can use a Cluster Shared Volume only when communication between the cluster nodes and the volume is functioning correctly, including network connectivity, access, drivers, and other factors.

Event Details

Event ID:

5200

Source:

Microsoft-Windows-FailoverClustering

Symbolic Name:

CAM_CANNOT_CREATE_CNO_TOKEN

Message: Cluster service failed to create a cluster identity token for Cluster Shared Volumes. The error code was '%1'. Ensure the domain controller is accessible and check for connectivity issues. Until connection to the domain controller is recovered, some operations on this node against the Cluster Shared Volumes might fail.Search System Error Codes ( http://go.microsoft.com/fwlink/?LinkId=83027).

Causes

This was due the domain controller is not accessible because of connectivity issues. Until connection to the domain controller is recovered, some operations on this node against the Cluster Shared Volumes might fail.

Resolutions

CSV - Check communication between domain controllers and nodes

If you do not currently have Event Viewer open, see "Opening Event Viewer and viewing events related to failover clustering." If the event contains an error code that you have not yet looked up, see "Finding more information about error codes that some event messages contain." After reviewing event messages, choose actions that apply to your situation:

To perform the following procedures, you must be a member of the local Administrators group on each clustered server, and the account you use must be a domain account, or you must have been delegated the equivalent authority.

Ensuring that the Network Name resource for the cluster is online

To ensure that the Network Name resource for the cluster is online:

Opening Event Viewer and viewing events related to failover clustering

To open Event Viewer and view events related to failover clustering:

Finding more information about the error codes that some event messages contain

To find more information about the error codes that some event messages contain:

NET HELPMSG errorcode

Verify

Confirm that the Cluster Shared Volume can come online. If there have been recent problems with writing to the volume, it can be appropriate to monitor event logs and monitor the function of the corresponding clustered virtual machine, to confirm that the problems have been resolved.

To perform the following procedures, you must be a member of the local Administrators group on each clustered server, and the account you use must be a domain account, or you must have been delegated the equivalent authority.

Confirming that a Cluster Shared Volume can come online

To confirm that a Cluster Shared Volume can come online:

Using a Windows PowerShell command to check the status of a resource in a failover cluster

To use a Windows PowerShell command to check the status of a resource in a failover cluster:

Get-ClusterSharedVolume

If you run the preceding command without specifying a resource name, status is displayed for all Cluster Shared Volumes in the cluster.

Element properties:

TargetMicrosoft.Windows.10.0.Cluster.Monitoring.Service
CategoryAlert
EnabledTrue
Alert GenerateTrue
Alert SeverityError
Alert PriorityNormal
RemotableTrue
Alert Message
Cluster Service failed to create a cluster identity token for Cluster Shared Volumes
{0}

Member Modules:

ID Module Type TypeId RunAs 
DS DataSource Microsoft.Windows.10.0.Cluster.EventProvider Default
WA WriteAction Microsoft.Windows.Cluster.GenerateAlertAction.SuppressedByDescription Default

Source Code:

<Rule ID="Microsoft.Windows.10.0.Cluster.Cluster.Service.failed.to.create.a.cluster.identity.token.for.Cluster.Shared.Volumes" Enabled="true" Target="Clus8Library!Microsoft.Windows.10.0.Cluster.Monitoring.Service" ConfirmDelivery="true" Remotable="true" Priority="Normal" DiscardLevel="100">
<Category>Alert</Category>
<DataSources>
<DataSource ID="DS" TypeID="Microsoft.Windows.10.0.Cluster.EventProvider">
<Criteria>
<SimpleExpression>
<ValueExpression>
<XPathQuery>EventDisplayNumber</XPathQuery>
</ValueExpression>
<Operator>Equal</Operator>
<ValueExpression>
<Value>5200</Value>
</ValueExpression>
</SimpleExpression>
</Criteria>
<LogName>System</LogName>
<PublisherName>Microsoft-Windows-FailoverClustering</PublisherName>
</DataSource>
</DataSources>
<WriteActions>
<WriteAction ID="WA" TypeID="ClusLibrary!Microsoft.Windows.Cluster.GenerateAlertAction.SuppressedByDescription">
<Priority>1</Priority>
<Severity>2</Severity>
<AlertMessageId>$MPElement[Name="Microsoft.Windows.10.0.Cluster.Cluster.Service.failed.to.create.a.cluster.identity.token.for.Cluster.Shared.Volumes.AlertMessage"]$</AlertMessageId>
</WriteAction>
</WriteActions>
</Rule>