Skip to content

dcdiag Health Checks

Using dcdiag for Replication Health Checks

The dcdiag (Directory Command-line Diagnostics) tool is a critical utility for assessing the health of Active Directory replication. It performs a series of tests to identify issues such as replication failures, inconsistent data, or misconfigured replication topologies. When troubleshooting replication problems, running dcdiag against domain controllers (DCs) or the entire domain provides structured insights into potential root causes.


Basic Usage and Syntax

The basic syntax for dcdiag is:

dcdiag [/v] [/f <filename>] [/s <DCName>] [/u <UserDN>] [/p <Password>]
- /v: Enables verbose output (useful for detailed diagnostics).
- /f <filename>: Saves the output to a specified file.
- /s <DCName>: Specifies the target DC to test (optional).
- /u <UserDN> and /p <Password>: Provide credentials for domain administration (required if running as a non-DC).

Example:

dcdiag /v /s DC01.example.com
This command runs a full diagnostic check on the DC named DC01.example.com with verbose output.


Key Replication-Specific Tests

dcdiag includes several tests directly relevant to replication health:

1. Replications Test

Checks replication between domain controllers.
Command:

dcdiag /v /test:replications
Output Highlights:
- Replication failures: Indicates domains or sites where replication did not occur.
- Replication latency: Shows delays in replication across sites.
- Replication errors: Lists specific errors (e.g., RPC server unavailable).

2. Knowledge Consistency Check (KCC) Test

Validates the replication topology generated by the KCC.
Command:

dcdiag /v /test:kcc
Output Highlights:
- Topology errors: Identifies missing or invalid replication connections.
- Connection objects: Lists all replication connections and their status.

3. Schema Replication Test

Ensures schema replication is functioning correctly.
Command:

dcdiag /v /test:schema
Output Highlights:
- Schema replication failures: Indicates issues with schema updates across DCs.


Interpreting Results

  • Errors: Look for red text or explicit error messages (e.g., Replication failure).
  • Warnings: Yellow text may indicate potential issues (e.g., high latency).
  • Success: Green text confirms no critical issues.

Example Output Snippet:

Testing domain controller DC01.example.com
...
Replications test
    DC01.example.com
        Replication with DC02.example.com failed: RPC server unavailable
        Replication with DC03.example.com succeeded
This output indicates a replication failure with DC02.example.com, likely due to an RPC issue.


Troubleshooting Scenarios

  1. Replication Latency: Use /test:replications to identify slow or stalled replication.
  2. Topology Issues: Run /test:kcc to verify replication connections and fix missing links.
  3. Schema Problems: Use /test:schema to resolve schema replication conflicts.

Key takeaways

  • Use dcdiag with /test:replications, /test:kcc, and /test:schema to diagnose replication issues.
  • Verbose output (/v) provides detailed insights into replication failures and topology problems.
  • Combine dcdiag with tools like repadmin or Event Viewer for root-cause analysis.
  • Regularly run diagnostics to proactively identify and resolve replication inconsistencies.