You need to enable JavaScript to run this app.
优惠活动
大模型
产品
解决方案
定价
更多

计划任务无法检测异常重启,求助排查原因与解决方法

解决方案:异常重启检测计划任务未触发问题

问题根源分析

核心问题有两点:一是异常重启生成的Event ID 41/6008,确实可能在任务调度器服务完全启动前就已写入事件日志,导致实时事件触发的任务错过检测时机;二是你的脚本中New-ScheduledTaskPrincipal参数存在明显乱码无效内容,会导致任务注册或权限异常。

修复步骤

1. 修正任务主体(Principal)的错误配置

脚本中New-ScheduledTaskPrincipal行的乱码参数(-Hola战 升级版计划 RequiredGoesquot地排.create)完全无效,正确的gMSA配置应改为:

$principal = New-ScheduledTaskPrincipal -UserID DOMAIN\gMSA$ -LogonType Password -RunLevel Highest

2. 配置触发器的事件回溯与延时启动

为捕获任务调度器启动前生成的事件,需修改触发器的XPath查询添加时间范围过滤,同时设置延时启动确保服务就绪:

添加事件回溯查询

将触发器的订阅改为包含过去1小时内的目标事件(可根据需求调整时长,3600000为毫秒数):

# Trigger 1 针对 Event ID 41
$Trigger1.Subscription = @"
<QueryList><Query Id="0" Path="System"><Select Path="System">*[System[EventID=41 and TimeCreated[timediff(@SystemTime) <= 3600000]]]</Select></Query></QueryList>
"@

# Trigger 2 针对 Event ID 6008
$Trigger2.Subscription = @"
<QueryList><Query Id="0" Path="System"><Select Path="System">*[System[EventID=6008 and TimeCreated[timediff(@SystemTime) <= 3600000]]]</Select></Query></QueryList>
"@

设置触发器延时启动

给每个触发器添加2分钟延时,确保任务调度器服务完全就绪后再执行检测:

$Trigger1.Delay = "PT2M"
$Trigger2.Delay = "PT2M"

3. 优化任务设置

开启错过触发时立即运行,并保留足够执行时间:

$settings = New-ScheduledTaskSettingsSet -AllowStartIfOnBatteries `
                                        -DontStopIfGoingOnBatteries `
                                        -StartWhenAvailable `
                                        -ExecutionTimeLimit (New-TimeSpan -Hours 1)

完整修复后的脚本

$taskName = "MON_UNEXPECTED_REBOOT"
$psPath = "C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe"
$arguments = '-file "C:\MAINTENANCE\MON\MON_REBOOT\MON_UNEXPECTED_REBOOT_SEND_MAIL.ps1"'
$action = New-ScheduledTaskAction -Execute $psPath -Argument $arguments

$CIMTriggerClass = Get-CimClass -ClassName MSFT_TaskEventTrigger -Namespace Root/Microsoft/Windows/TaskScheduler

# Trigger 1: Event ID 41 带回溯查询与延时
$Trigger1 = New-CimInstance -CimClass $CIMTriggerClass -ClientOnly
$Trigger1.Subscription = @"
<QueryList><Query Id="0" Path="System"><Select Path="System">*[System[EventID=41 and TimeCreated[timediff(@SystemTime) <= 3600000]]]</Select></Query></QueryList>
"@
$Trigger1.Enabled = $True
$Trigger1.Delay = "PT2M"

# Trigger 2: Event ID 6008 带回溯查询与延时
$Trigger2 = New-CimInstance -CimClass $CIMTriggerClass -ClientOnly
$Trigger2.Subscription = @"
<QueryList><Query Id="0" Path="System"><Select Path="System">*[System[EventID=6008 and TimeCreated[timediff(@SystemTime) <= 3600000]]]</Select></Query></QueryList>
"@
$Trigger2.Enabled = $True
$Trigger2.Delay = "PT2M"

$Triggers = @($Trigger1,$Trigger2)

# 修正后的任务主体配置
$principal = New-ScheduledTaskPrincipal -UserID DOMAIN\gMSA$ -LogonType Password -RunLevel Highest

$settings = New-ScheduledTaskSettingsSet -AllowStartIfOnBatteries `
                                        -DontStopIfGoingOnBatteries `
                                        -StartWhenAvailable `
                                        -ExecutionTimeLimit (New-TimeSpan -Hours 1)

Register-ScheduledTask -TaskName $taskName -taskpath 'MON' -Action $action -Trigger $Triggers -Settings $settings -Principal $principal -Description "Sends email when reboot is unexpected."

额外验证步骤

  • 注册任务后,打开任务计划程序,检查触发器的延时和事件查询是否正确配置
  • 强制断电模拟异常重启,重启后查看任务历史记录确认是否触发
  • 若仍有问题,检查gMSA账户是否具备读取系统事件日志、执行PowerShell脚本的权限

内容的提问来源于stack exchange,提问作者tpcolson

相关产品推荐
方舟 Agent Plan

超全模态模型 × Harness 升级,最新支持 Deepseek-V4.1-Flash、GLM-5.3 系列、Doubao-Seedream-5.0-pro、Kimi-K3 (部分), 限时 9.9 元起

最近更新时间:2026.06.14 06:04:54