Cluster service failed to start the cluster log trace session

Microsoft.Windows.10.0.Cluster.Management.Monitoring.Cluster.service.failed.to.start.the.cluster.log.trace.session (Rule)

Knowledge Base article:

Summary

Cluster service failed to start the cluster log trace session

Resolutions

The Cluster service either failed to start the cluster log trace session, or failed to change the trace log size. If you do not currently have Event Viewer open, to view the event message, see 'Opening Event Viewer and viewing events related to failover clustering.' If the event contains an error code that you have not yet looked up, see 'Finding more information about error codes that some event messages contain.'

To capture detailed logs of events on a node in a failover cluster, see 'Using Reliability and Performance Monitor to ensure that Event Trace Sessions are started on a node in a failover cluster.' To check the current setting for the cluster log size, see 'Using a command to check the setting for the cluster log size.'

To perform the following procedures, you must be a member of the local Administrators group on the node in the failover cluster, or you must have been delegated the equivalent authority.

To open Event Viewer and view events related to failover clustering:

To find more information about the error codes that some event messages contain:

To use Reliability and Performance Monitor to ensure that Event Trace Sessions are started on a node in a failover cluster:

To use a command to check the setting for the cluster log size:

Element properties:

TargetMicrosoft.Windows.10.0.Cluster.Monitoring.Service
CategoryAlert
EnabledTrue
Alert GenerateTrue
Alert SeverityWarning
Alert PriorityNormal
RemotableTrue
Alert Message
Cluster service failed to start the cluster log trace session
{0}

Member Modules:

ID Module Type TypeId RunAs 
DS DataSource Microsoft.Windows.10.0.Cluster.EventProvider Default
WA WriteAction Microsoft.Windows.Cluster.GenerateAlertAction.SuppressedByDescription Default

Source Code:

<Rule ID="Microsoft.Windows.10.0.Cluster.Management.Monitoring.Cluster.service.failed.to.start.the.cluster.log.trace.session" Enabled="true" Target="Clus8Library!Microsoft.Windows.10.0.Cluster.Monitoring.Service" ConfirmDelivery="true" Remotable="true" Priority="Normal" DiscardLevel="100">
<Category>Alert</Category>
<DataSources>
<DataSource ID="DS" TypeID="Microsoft.Windows.10.0.Cluster.EventProvider">
<Criteria>
<SimpleExpression>
<ValueExpression>
<XPathQuery>EventDisplayNumber</XPathQuery>
</ValueExpression>
<Operator>Equal</Operator>
<ValueExpression>
<Value>4868</Value>
</ValueExpression>
</SimpleExpression>
</Criteria>
<LogName>System</LogName>
<PublisherName>Microsoft-Windows-FailoverClustering</PublisherName>
</DataSource>
</DataSources>
<WriteActions>
<WriteAction ID="WA" TypeID="ClusLibrary!Microsoft.Windows.Cluster.GenerateAlertAction.SuppressedByDescription">
<Priority>1</Priority>
<Severity>1</Severity>
<AlertMessageId>$MPElement[Name="Microsoft.Windows.10.0.Cluster.Management.Monitoring.Cluster.service.failed.to.start.the.cluster.log.trace.session.AlertMessage"]$</AlertMessageId>
</WriteAction>
</WriteActions>
</Rule>