#define EVENT_FRS_REPLICA_IN_JRNL_WRAP_ERROR 0xC00034F9L
MessageId: EVENT_FRS_REPLICA_IN_JRNL_WRAP_ERROR MessageText: The File Replication Service has detected that the replica set "%1" is in JRNL_WRAP_ERROR. %n %n Replica set name is : "%1" %n Replica root path is : "%2" %n Replica root volume is : "%3" %n A Replica set hits JRNL_WRAP_ERROR when the record that it is trying to read from the NTFS USN journal is not found. This can occur because of one of the following reasons. %n %n [1] Volume "%3" has been formatted. %n [2] The NTFS USN journal on volume "%3" has been deleted. %n [3] The NTFS USN journal on volume "%3" has been truncated. Chkdsk can truncate the journal if it finds corrupt entries at the end of the journal. %n [4] File Replication Service was not running on this computer for a long time. %n [5] File Replication Service could not keep up with the rate of Disk IO activity on "%3". %n %n Following recovery steps will be taken to automatically recover from this error state. %n [1] At the first poll which will occur in %4 minutes this computer will be deleted from the replica set. %n [2] At the poll following the deletion this computer will be re-added to the replica set. The re-addition will trigger a full tree sync for the replica set.
Lanman Server Events (2000 - 2999) 2000-2499 are generated by the server driver (kernel mode) 2500-2999 are generated by the server service (user mode) Server driver events, issued from kernel mode. Values are 32 bit values laid out as follows: 3 3 2 2 2 2 2 2 2 2 2 2 1 1 1 1 1 1 1 1 1 1 1 0 9 8 7 6 5 4 3 2 1 0 9 8 7 6 5 4 3 2 1 0 9 8 7 6 5 4 3 2 1 0 +---+-+-+-----------------------+-------------------------------+ |Sev|C|R| Facility | Code | +---+-+-+-----------------------+-------------------------------+ where Sev - is the severity code 00 - Success 01 - Informational 10 - Warning 11 - Error C - is the Customer code flag R - is a reserved bit Facility - is the facility code Code - is the facility's status code