Cluster node has been evicted from the failover cluster

Microsoft.Windows.2008.Cluster.Management.Monitoring.Cluster.node.has.been.evicted.from.the.failover.cluster (Rule)

Knowledge Base article:

A node was evicted from the cluster. If you are not sure why, review the sequence of logged events before the eviction. If you do not currently have Event Viewer open, see "Opening Event Viewer and viewing events related to failover clustering." In Event Viewer, look for the following information:

After correcting a problem on a node, if necessary, restart the Cluster service on the node. For more information, see "Restarting the Cluster service after correcting a problem on a node," later in this topic.

To perform the following procedures, you must be a member of the local Administrators group on each clustered server, and the account you use must be a domain account, or you must have been delegated the equivalent authority.

Restarting the Cluster service after correcting a problem on a node

To restart the Cluster service after correcting a problem on a node:

  1. To open the failover cluster snap-in, click Start, click Administrative Tools, and then click Failover Cluster Management. If the User Account Control dialog box appears, confirm that the action it displays is what you want, and then click Continue.
  2. In the Failover Cluster Management snap-in, if the cluster you want to manage is not displayed, in the console tree, right-click Failover Cluster Management, click Manage a Cluster, and then select or specify the cluster that you want.
  3. If the console tree is collapsed, expand the tree under the cluster you want to manage.
  4. Expand the console tree under Nodes.
  5. Right-click the node that you want to start and then click More Actions. If Stop Cluster Service is available, click it. Otherwise, skip to the next step.
  6. Right-click the node that you want to start, click More Actions, and then click Start Cluster Service.

Enabling auditing of a cluster after auditing has been configured in your organization

To enable auditing of a cluster after auditing has been configured in your organization:

  1. To open the failover cluster snap-in, click Start, click Administrative Tools, and then click Failover Cluster Management. If the User Account Control dialog box appears, confirm that the action it displays is what you want, and then click Continue.
  2. In the Failover Cluster Management snap-in, if the cluster you want to manage is not displayed, in the console tree, right-click Failover Cluster Management, click Manage a Cluster, and then select or specify the cluster that you want.
  3. Right-click the cluster, click Properties, and then click the Cluster Permissions tab.
  4. Click the Advanced button, and then click Auditing.
  5. Specify the users or groups that you want to audit in the same way that you would for other resources.

Opening Event Viewer and viewing events related to failover clustering

To open Event Viewer and view events related to failover clustering:

  1. If Server Manager is not already open, click Start, click Administrative Tools, and then click Server Manager. If the User Account Control dialog box appears, confirm that the action it displays is what you want, and then click Continue.
  2. In the console tree, expand Diagnostics, expand Event Viewer, expand Windows Logs, and then click System.
  3. To filter the events so that only events with a Source of FailoverClustering are shown, in the Actions pane, click Filter Current Log. On the Filter tab, in the Event sources box, select FailoverClustering. Select other options as appropriate, and then click OK.
  4. To sort the displayed events by date and time, in the center pane, click the Date and Time column heading.

Element properties:

TargetMicrosoft.Windows.2008.Cluster.Monitoring.Service
CategoryAlert
EnabledTrue
Alert GenerateTrue
Alert SeverityWarning
Alert PriorityNormal
RemotableTrue
Alert Message
Cluster node has been evicted from the failover cluster
{0}

Member Modules:

ID Module Type TypeId RunAs 
DS DataSource Microsoft.Windows.2008.Cluster.EventProvider Default
WA WriteAction Microsoft.Windows.Cluster.GenerateAlertAction.SuppressedByDescription Default

Source Code:

<Rule ID="Microsoft.Windows.2008.Cluster.Management.Monitoring.Cluster.node.has.been.evicted.from.the.failover.cluster" Enabled="true" Target="Clus2008Library!Microsoft.Windows.2008.Cluster.Monitoring.Service" ConfirmDelivery="true" Remotable="true" Priority="Normal" DiscardLevel="100">
<Category>Alert</Category>
<DataSources>
<DataSource ID="DS" TypeID="Microsoft.Windows.2008.Cluster.EventProvider">
<Criteria>
<SimpleExpression>
<ValueExpression>
<XPathQuery>EventDisplayNumber</XPathQuery>
</ValueExpression>
<Operator>Equal</Operator>
<ValueExpression>
<Value>1011</Value>
</ValueExpression>
</SimpleExpression>
</Criteria>
<LogName>System</LogName>
<PublisherName>Microsoft-Windows-FailoverClustering</PublisherName>
</DataSource>
</DataSources>
<WriteActions>
<WriteAction ID="WA" TypeID="ClusLibrary!Microsoft.Windows.Cluster.GenerateAlertAction.SuppressedByDescription">
<Priority>1</Priority>
<Severity>1</Severity>
<AlertMessageId>$MPElement[Name="Microsoft.Windows.2008.Cluster.Management.Monitoring.Cluster.node.has.been.evicted.from.the.failover.cluster.AlertMessage"]$</AlertMessageId>
</WriteAction>
</WriteActions>
</Rule>