This is the most recent warning in the Admin Events, After a freeze I usually check the event viewer to see if there are any recent errors but at times there hadn't been one for sometimes an hour+ of the freeze.
Log Name: System
Source: Microsoft-Windows-DNS-Client
Date: 2/15/2025 11:12:16 AM
Event ID: 1014
Task Category: (1014)
Level: Warning
Keywords: (268435456)
User: NETWORK SERVICE
Computer: S142
Description:
Name resolution for the name t-ring-fdv2.msedge.net timed out after none of the configured DNS servers responded. Client PID 16632.
Event Xml:
<Event xmlns="
http://schemas.microsoft.com/win/2004/08/events/event">
<System>
<Provider Name="Microsoft-Windows-DNS-Client" Guid="{1c95126e-7eea-49a9-a3fe-a378b03ddb4d}" />
<EventID>1014</EventID>
<Version>1</Version>
<Level>3</Level>
<Task>1014</Task>
<Opcode>0</Opcode>
<Keywords>0x4000000010000000</Keywords>
<TimeCreated SystemTime="2025-02-15T16:12:16.3593753Z" />
<EventRecordID>6223</EventRecordID>
<Correlation />
<Execution ProcessID="3936" ThreadID="10496" />
<Channel>System</Channel>
<Computer>S142</Computer>
<Security UserID="S-1-5-20" />
</System>
<EventData>
<Data Name="QueryName">t-ring-fdv2.msedge.net</Data>
<Data Name="AddressLength">128</Data>
<Data Name="Address">1700000000000000260017020B102E0000000000000000010000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000</Data>
<Data Name="ClientPID">16632</Data>
</EventData>
</Event>
Apart from this most recent one at 11:12:16 AM the one before that was at 10:43:17 AM:
Log Name: System
Source: Microsoft-Windows-DistributedCOM
Date: 2/15/2025 10:43:17 AM
Event ID: 10016
Task Category: None
Level: Warning
Keywords: Classic
User: S142\Sawyer
Computer: S142
Description:
The application-specific permission settings do not grant Local Activation permission for the COM Server application with CLSID
{2593F8B9-4EAF-457C-B68A-50F6B8EA6B54}
and APPID
{15C20B67-12E7-4BB6-92BB-7AFF07997402}
to the user S142\Sawyer SID (S-1-5-21-3170514173-4202580850-3380113842-1001) from address LocalHost (Using LRPC) running in the application container Unavailable SID (Unavailable). This security permission can be modified using the Component Services administrative tool.
Event Xml:
<Event xmlns="
http://schemas.microsoft.com/win/2004/08/events/event">
<System>
<Provider Name="Microsoft-Windows-DistributedCOM" Guid="{1B562E86-B7AA-4131-BADC-B6F3A001407E}" EventSourceName="DCOM" />
<EventID Qualifiers="0">10016</EventID>
<Version>0</Version>
<Level>3</Level>
<Task>0</Task>
<Opcode>0</Opcode>
<Keywords>0x8080000000000000</Keywords>
<TimeCreated SystemTime="2025-02-15T15:43:17.8833243Z" />
<EventRecordID>6213</EventRecordID>
<Correlation ActivityID="{3d290fe5-7fc0-0005-3833-293dc07fdb01}" />
<Execution ProcessID="2636" ThreadID="3064" />
<Channel>System</Channel>
<Computer>S142</Computer>
<Security UserID="S-1-5-21-3170514173-4202580850-3380113842-1001" />
</System>
<EventData>
<Data Name="param1">application-specific</Data>
<Data Name="param2">Local</Data>
<Data Name="param3">Activation</Data>
<Data Name="param4">{2593F8B9-4EAF-457C-B68A-50F6B8EA6B54}</Data>
<Data Name="param5">{15C20B67-12E7-4BB6-92BB-7AFF07997402}</Data>
<Data Name="param6">S142</Data>
<Data Name="param7">Sawyer</Data>
<Data Name="param8">S-1-5-21-3170514173-4202580850-3380113842-1001</Data>
<Data Name="param9">LocalHost (Using LRPC)</Data>
<Data Name="param10">Unavailable</Data>
<Data Name="param11">Unavailable</Data>
</EventData>
</Event>