DNS Event ID 4010

Short history, I have two 2003 domain controllers that I am retiring. Two newer 2008 R2 servers are replacing them. In the process of moving everything over I ran into a few issues, but was able to work through almost all of them. Right now the old 2003 servers are only member servers with all roles transferred to the new 2008 R2 servers. At one point I was getting errors about the _msdcs zone so I followed a couple of guides to re-create it which got rid of the original errors. Then I started getting errors with event ID 4010:

The DNS server was unable to create a resource record for  ba82ef0f-5263-488d-a526-0e799335df5b._msdcs.domain.local. in zone domain.local. The Active Directory definition of this resource record is corrupt or contains an invalid DNS name. The event data contains the error.

I was getting one error for each active domain controller at that time (one old and two new ones). I was able to use ADSIedit to fix one of them about a month ago by following the instructions to delete all of the records in the ForestDnsZones and DomainDnsZones in ADSIedit. That worked perfectly back then. Now I ran dcpromo on the second 2003 server to retire it, and wanted to use ADSIedit to remove the old records as well, but noticed something really strange.

When I connect to dc=domaindnszones,dc=domain,dc=local I am not seeing my domain listed under cn=MicrosoftDNS, only the RootDNSservers are listed there. I could swear that is was there about a month ago. Is this something I should be worried about? Does anyone know what happened?

February 24th, 2015 6:56pm

I fount this solution


At earlier I thought that the partion might be corrupted however as this point of time I would recommend Stop the netlogon service. Go to Windows\system32\config and rename the netlogon.dns and netlogon.dnb files to netlogon.dns_old and netlogon.dnb-old . From a command prompt type "ipconfig /flushdns" then run "ipconfig /registerdns" and then start netlogon again and check the event log if the error reoccurs.
If still the issue persist take the backup of DNS as suggested earlier,delete foward lookup zone and recreate new forward lookup zone.I think this should fix the issue.

https://social.technet.microsoft.com/Forums/windowsserver/en-US/55c7a4cd-2932-4b0e-bfd2-b043490df000/eventid-4010-dns-the-active-directory-definition-of-this-resource-record-is-corrupt-or-contains-an?forum=winserverDS

Free Windows Admin Tool Kit Click here and download it now
February 24th, 2015 9:11pm

Thanks for the reply. Before I delete or rename anything I want to know what this would actually accomplish and what the risks are. I am not very familiar with this whole thing so I am treading very lightly so to speak.

My biggest concern right now is the fact that I am not seeing my domain listed in DomainDnsZones and I am pretty sure that it was there before. Or maybe I was seeing ghosts?

February 25th, 2015 6:27pm

Hi,

Restart Netlogon service in order to re-registry SRV and related records in the DNS zone.
 
The Netlogon service creates a log file that contains all the locator resource records and places the log file in the location % SystemRoot %\System32\Config\Netlogon.dns. rename this file is the same as delete it, once renamed, related service will recreate this file with current configuration. Besides, you may delete the newly file and change the renamed file name to its original name to undo this change.

Besides, reference the link below for detailed information about  Event ID 4010 DNS Server Active Directory Integration:
https://technet.microsoft.com/en-us/library/cc735667%28v=ws.10%29.aspx?f=255&MSPPError=-2147217396

Best Regards,
Eve Wang

Free Windows Admin Tool Kit Click here and download it now
February 27th, 2015 3:55am

This topic is archived. No further replies will be accepted.

Other recent topics Other recent topics