#Requires -Version 5.1 <# JbTecWiz Support Centre -- read-only diagnostic Fault : Failover Cluster event 1135 -- a node was removed from the active failover cluster membership Source: https://jbtecwiz.com/support/srv-cluster-1135 This script CHANGES NOTHING. It runs only the inspection commands from the write-up -- the Get-, Test- and Resolve- calls that establish which cause is in play -- and prints what each returned. Anything that writes, deletes, starts or stops is excluded by construction, not by judgement. Read the output alongside the write-up, then pick the fix that matches. Each fix has its own script on the same page. -------------------------------------------------------------------- NO WARRANTY - USE AT YOUR OWN RISK This script is provided by JbTecWiz as-is and with no warranty of any kind, express or implied. You run it entirely at your own risk. JbTecWiz accepts no liability for any loss or damage arising from its use, including but not limited to data loss, downtime, or configuration changes that turn out to be wrong for your system. You are responsible for reading this script before running it, for satisfying yourself that it suits the machine in front of you, and for having a working backup first. Some steps cannot be undone. -------------------------------------------------------------------- #> [CmdletBinding()] param([switch]$Transcript) $ErrorActionPreference = 'Continue' if ($Transcript) { $log = Join-Path $env:USERPROFILE ("jbtecwiz-srv-cluster-1135-" + (Get-Date -Format yyyyMMdd-HHmmss) + ".txt") Start-Transcript -Path $log | Out-Null Write-Host (' Saving a transcript to ' + $log) } function Write-Rule { param([string]$Text) Write-Host '' Write-Host ('-' * 70) -ForegroundColor DarkGray if ($Text) { Write-Host $Text -ForegroundColor Cyan } } function Probe { param([string]$Label, [string]$Fix, [scriptblock]$Command) Write-Rule (" " + $Label) Write-Host (" from: " + $Fix) -ForegroundColor DarkGray Write-Host '' foreach ($l in ($Command.ToString().Trim() -split "`n")) { Write-Host (" " + $l.Trim()) -ForegroundColor DarkGreen } Write-Host '' try { $out = & $Command 2>&1 | Out-String if ([string]::IsNullOrWhiteSpace($out)) { Write-Host ' (returned nothing)' -ForegroundColor DarkGray } else { foreach ($l in ($out.TrimEnd() -split "`n")) { Write-Host (" " + $l.TrimEnd()) } } } catch { Write-Host (" could not run: " + $_.Exception.Message) -ForegroundColor Yellow } } Write-Rule Write-Host ' Failover Cluster event 1135 -- a node was removed from the active failover cluster membership' -ForegroundColor White Write-Host ' Read-only diagnostic -- nothing is changed.' -ForegroundColor Green Write-Rule Probe -Label 'Collect the cluster log around the eviction -- it records the heartbeat misses in detail.' -Fix 'Rule out the network and the NIC settings' -Command { Get-ClusterLog -TimeSpan 15 -Destination C:\temp } Probe -Label 'Turn off power management on every cluster NIC.' -Fix 'Rule out the network and the NIC settings' -Command { Get-NetAdapter | Get-NetAdapterPowerManagement | Where-Object AllowComputerToTurnOffDevice -eq 'Enabled' } Probe -Label 'Note the exact times from the event log and look for what else runs then.' -Fix 'Find the scheduled load that is starving the heartbeat' -Command { Get-WinEvent -FilterHashtable @{LogName='System'; Id=1135} -MaxEvents 30 | Select-Object TimeCreated } Probe -Label 'Check for scheduled antivirus full scans.' -Fix 'Find the scheduled load that is starving the heartbeat' -Command { Get-MpPreference | Select-Object ScanScheduleDay, ScanScheduleTime } Write-Rule Write-Host ' Diagnostic finished. Nothing was changed.' -ForegroundColor Green Write-Host '' Write-Host ' Compare the output above with the write-up, then run the' Write-Host ' script for the fix that matches:' Write-Host ' https://jbtecwiz.com/support/srv-cluster-1135' Write-Rule if ($Transcript) { Stop-Transcript | Out-Null }