[SDP3][b1406aad-e437-4681-8e6d-4f24a5416bb7] Windows Time Service Diagnostic

Gilt für: Microsoft Windows XP Service Pack 3Microsoft Windows Server 2003 Service Pack 2Microsoft Windows Server 2003 R2 Standard Edition (32-bit x86)

Summary


This diagnostic collects data used to troubleshoot Windows Time Service issues. During collection, there will be an opportunity to enable Windows Time Service debug logging. You may then reproduce a specific problem or choose to leave the logging enabled as directed by a Support Engineer.

More Information


Windows Time Service diagnostic interactions are detailed below.

Introduction:


Prompt for Windows Time Service debug logging:

Debug logging may help your support engineer troubleshoot and diagnose the support issue. Only the registry values not already configured on the system will be displayed in this dialog. The output log file will be limited to 10 megabytes and a subsequent dialog will help guide you through disabling the logging. 

Prompt for Windows Time Service restart:

As displayed above, the service will be automatically restarted if no dependent service were detected. If dependent services are detected, they will be displayed within the dialog along with instructions to restart the service. Please ensure it is safe to restart dependent services and restart the service, or simply click the 'Next' button to proceed with data collection without a service restart.

Windows Time Service debug logging is active:

If a specific time-related activity is failing on the system, you may now perform the activity. The Support Engineer may request other actions be performed at this time depending on the nature of the support issue. Once you have reproduced the behavior or wish to complete data collection, click the 'Next' button.

Disabling Windows Time Service debug logging:

Windows Time Service debug logging may now be disabled. However, if you wish to monitor service operation over long periods, you may choose the option 'No: Leave debug logging enabled'. Debug logging will remain active indefinitely. Future uses of the Windows Time Service diagnostic will detect the logging as already enabled and gather the debug log during data collection.


Information Collected


File Version Information (Chksym)
DescriptionFile name
File version information from %ProgramFiles%\Microsoft iSNS Server\*.* and %windir%\system32\iscsi*.*
{ComputerName}_sym_MS_iscsi.csv
{ComputerName}_sym_MS_iscsi.txt
File version information from %windir%\cluster\*.*
{ComputerName}_sym_ProgramFiles_sys.csv
{ComputerName}_sym_ProgramFiles_sys.txt
File version information from %windir%\cluster\*.*
{ComputerName}_sym_Cluster.csv
{ComputerName}_sym_Cluster.txt
File version information from %windir%\system32\*.dll
{ComputerName}_sym_System32_dll.csv
{ComputerName}_sym_System32_dll.txt
File version information from %windir%\system32\*.exe
{ComputerName}_sym_System32_exe.csv
{ComputerName}_sym_System32_exe.txt
File version information from %windir%\system32\*.sys
{ComputerName}_sym_System32_sys.csv
{ComputerName}_sym_System32_sys.txt
File version information from %windir%\system32\drivers folder
{ComputerName}_sym_Drivers.csv
{ComputerName}_sym_Drivers.txt
File version information from %windir%\system32\Spool\*.*
{ComputerName}_sym_PrintSpooler.csv
{ComputerName}_sym_PrintSpooler.txt
File version information from %windir%\syswow64 folder and subfolders
{ComputerName}_sym_SysWOW64_sys.csv
{ComputerName}_sym_SysWOW64_sys.txt
File version information from %windir%\syswow64\drivers folder
{ComputerName}_sym_SysWOW64_sys.csv
{ComputerName}_sym_SysWOW64_sys.txt
File version information from {Program Files (x86)}\*.sys folder and subfolders
{ComputerName}_sym_ProgramFilesx86_sys.csv
{ComputerName}_sym_ProgramFilesx86_sys.txt
File version information from {Program Files}\*.sys folder and subfolders
{ComputerName}_sym_ProgramFiles_sys.csv
{ComputerName}_sym_ProgramFiles_sys.txt
File version information from drivers currently running on the machine
{ComputerName}_sym_RunningDrivers.csv
{ComputerName}_sym_RunningDrivers.txt
File version information from processes currently running on the machine
{ComputerName}_sym_Process.csv
{ComputerName}_sym_Process.txt

Event Logs
DescriptionFile name
Application (.csv .evtx .txt){ComputerName}_evt_Application.csv
{ComputerName}_evt_Application.evtx
{ComputerName}_evt_Application.txt
Security (.csv .evtx .txt){ComputerName}_evt_Securty.csv
{ComputerName}_evt_Securty.evtx
{ComputerName}_evt_Securty.txt
System (.csv .evtx .txt){ComputerName}_evt_System.csv
{ComputerName}_evt_System.evtx
{ComputerName}_evt_System.txt

Functional Levels and Group Membership Information
DescriptionFile name
Group Membership and Functional Levels information via 'net.exe localgroup' commands
{ComputerName}_DSMisc.txt

Installed Updates/hotfixes
DescriptionFile name
Update/Hotfix history
{Computername}_Hotfixes.CSV
Update/Hotfix history{Computername}_Hotfixes.htm
Update/Hotfix history{Computername}_Hotfixes.TXT


Resultant Set of Policy (RSoP)
DescriptionFile name
GPResult /H output (.txt)
{ComputerName}_GPResult.txt
GPResult /H output (.htm){Computername}_GPResult.htm


General Information
DescriptionFile name
Basic System Information including machine name, service pack, computer model and processor name and speed
resultreport.xml

List of Installed Updates and Hotfixes installed
{ComputerName}_Hotfixes.htm
{ComputerName}_Hotfixes.htm
List of User Rights (privileges) using showpriv.exe tool
{ComputerName}_UserRights.txt
List of user SID, group memberships, and privileges via the 'Whoami /all' output
{ComputerName}_Whoami.txt
Show if machine is running on a Virtual Environment and describes the virtualization environment
resultreport.xml
Registry Entries Output{Computername}_REGENTRIES.txt

Port Usage Log
DescriptionFile name
TCP and UDP port statistics
{ComputerName}_PortUsage.txt

TCPIP
DescriptionFile name
HKLM\SOFTWARE\Policies\Microsoft\Windows\TCPIP
HKLM\SYSTEM\CurrentControlSet\services\TCPIP
HKLM\SYSTEM\CurrentControlSet\Services\Tcpip6
HKLM\SYSTEM\CurrentControlSet\Services\tcpipreg
{ComputerName}_TCPIP_reg_output.TXT
TCP OFFLOAD information from netstat output
{ComputerName}_TCPIP_OFFLOAD.TXT
TCPIP Information from commands like: hostname, ipconfig, route, netstat etc.
{ComputerName}_TCPIP_info.TXT
TCPIP information from netsh output
{ComputerName}_TCPIP_netsh_info.TXT
TCPIP Services File located at: windir\system32\drivers\etc\services
{ComputerName}_TCPIP_ServicesFile.TXT

W32Time
DescriptionFile name
Output of 'W32tm /monitor'
{ComputerName}_W32TM_Monitor.txt
Processed output of 'w32tm /monitor'{ComputerName}_W32TM_Monitor_Parsed.txt
Output of 'w32tm /testif /qps'
{ComputerName}_W32TM_TestIf_QPS.txt
W32Time Debug Log file
{ComputerName}_W32Time.log
W32Time Service Permissions via 'sc sdshow w32time'
{ComputerName}_W32Time_Service_Perms.txt
W32Time Service Status via 'sc query w32time'
{ComputerName}_W32Time_Service_Status.txt
W32TM Query Status via 'w32tm /tz'
{ComputerName}_W32TM_Query_Status.txt
W32TM Stripchart via 'w32tm /stripchart'
{ComputerName}_W32TM_Stripchart.txt
W32Time registry keys{ComputerName}_W32TM_Reg_Key.txt
W32Time registry key permissions{ComputerName}_W32TM_Reg_Key_Perms.txt
W32TM Query Configuration via 'w32tm /query /configuration /verbose'{ComputerName}_W32TM_Configuration_Verbose.txt
Time Zone Registry keys{ComputerName}_TimeZone_Reg_keys.txt


In addition to collecting the information that is described earlier, this diagnostic package can detect one or more of the following symptoms:

  • Check for Windows Time Service issues
  • Detect Win32time configuration for time skew
  • Detect Windows XP End-of-Support
  • Check for ephemeral port usage
  • Check for ephemeral port usage
  • Event Logs Messages
  • Detect if this machine is a Virtual Machine running in Microsoft Azure

References

For more information about the Microsoft Automated Troubleshooting Services and about the Support Diagnostics Platform, please open the following Microsoft Knowledge Base article:


2598970 Information about Microsoft Automated Troubleshooting Services and Support Diagnostic Platform