The server remained unresponsive.

The event viewer also logs the start and stop times of the eventlog service. Regards, DennyPlease remember to click “Mark as Answer” on the post that helps you, and to click “Unmark as Answer” if a marked post does not actually answer your question. It gives the message "The Event log service was stopped". * Event 6008 is logged as a dirty shutdown. The event ID 6005 indicates that the eventlog service was started, and the event ID 6009 indicates that the eventlog services were stopped.

In this case, AD (DS) takes about 90 seconds to start before the GPSVC is able to connect.

EventId: 6005, time: 33:05, Application log - The winlogon notification subscriber is taking long time to handle the notification event (CreateSession.

Log Name: Application Source: Microsoft-Windows-Winlogon Event ID: 6006 Description: The winlogon notification subscriber took 66 second(s) to handle the notification event (CreateSession).

On a different hardware platform, my test login was between 45 sec to 1 min, this is ok for a domain environment with lots of group policies.

You should look for the events described by JohnC , first.

Looking at that service it has a startup type of 'Automatic (trigger start)', thought I might try changing that to delayed start.

In this case, AD (DS) takes about 90 seconds to start before the GPSVC is able to connect.

Now disabled these two Default Domain policies as well... - still same problem So to summarize we are still getting the warning without _any_ GPOs linked: The winlogon notification subscriber

This is synonymous to system startup.Event ID 6006 will be labeled as "The event log service was stopped".

See below.... > GPSVC(250.510) 12:30:08:722 CGPNotify::RegisterForNotification: > Exiting with status = 0 > > GPSVC(3c0.480) 12:30:30:774 Waiting for DS with timeout 87719 > If I'm a DC and want Reference LinksWhy Windows NT Reports 6005, 6006, 6008, and 6009 Event Log Entries Did this information help you to resolve the problem? I have several versions of Windows Server so a solution that works for at least versions 2008, 2008 R2, 2012, and 2012 R2 would be ideal. Event Id 6006 Slow Logon Event ID 6008 will let you know that the system started after it was not shut down properly.Using TurnedOnTimesViewTurnedOnTimesView is a simple, portable tool for analyzing the event log for startup and

English: Request a translation of the event description in plain English. The following setting change solved my problem: - change all services which are set to start automatically to "automatic (delayed start)

It gives the message "The Event log service was stopped". * Event 6008 is logged as a dirty shutdown.

Type CRYPTSVC in the Value Data field and click OK. 5. It gives the message "The Event log service was started". * Event 6006 is logged as a clean shutdown. Since it is a portable tool, you will only need to unzip and execute the TurnedOnTimesView.exe file.

To view the startup and shutdown times of a remote computer, go to "Options -> Advanced Options" and select "Data source as Remote Computer". You can also specify the time period under Logged.Event ID 6005 will be labeled as "The event log service was started". x 11 J.S. Recommend Us Quick Tip Connect to EventID.Net directly from the Microsoft Event Viewer!Instructions Customer services Contact usSupportTerms of Use Help & FAQ Sales FAQEventID.Net FAQ Advertise with us Articles Managing logsRecommended

In my case it was TrendMicro AntiVirus that was causing this long boot procedure.

If ten years ago it was still common to see an entire company using just one server, these days that's no longer the case.

