The symptoms align with a storage/CSV access failure rather than a confirmed cluster-network isolation root cause.
Supported indicators from the described timeline are:
- CSV access failure pattern
- Event IDs 5120/5142 are associated with CSV paused or disconnected states and VM disk I/O errors.
-
STATUS_NO_SUCH_DEVICEand reservation-release failures around the same time are consistent with storage path or disk visibility problems.
- Likely areas to validate first
- Storage pathing / MPIO: confirm all paths are online by using
mpclaim -s -d. - Disk health / visibility: review
Get-PhysicalDisk | Format-Tableand check for storage-related events such as 157, 11, 129, and 153. - Drivers / firmware / DSM-MPIO stack: update storage drivers, SAN firmware, and DSM/MPIO software.
- CSV/network transport factors: verify there is no network bottleneck or misconfiguration affecting CSV traffic, and confirm adapter configuration is aligned across all nodes.
- Filter drivers / antivirus: inspect filter drivers with
fltmc; remove unsupported filter drivers and avoid multiple antivirus products.
- Storage pathing / MPIO: confirm all paths are online by using
- How to interpret Event ID 5120
- If Event ID 5120 shows
STATUS_CLUSTER_CSV_AUTO_PAUSE_ERRORorc0130021, that specific event can be ignored. - If Event ID 5120 shows other error codes, it indicates a real problem and the error code in each event should be reviewed.
- If Event ID 5120 shows
- Data to collect before a controlled reproduction
Collect the following before reproducing the ownership transfer:
- Cluster logs:
Get-ClusterLog -Destination \\<FolderPath> -UseLocal -TimeSpan <Minutes> - Export System, Application, and FailoverClustering event logs.
- Network trace:
Netsh trace start scenario=GENERAL capture=yes tracefile=<path> - Process dump files as needed by using Sysinternals or built-in Windows tools.
- Storage and hardware diagnostics from the storage vendor tools.
- Security software logs if any security/filtering product is installed.
- Cluster logs:
- If the cluster service or disk resource is hanging
For failover cluster hangs, triage the Windows Error Reporting data under:
C:\ProgramData\Microsoft\Windows\WER\ReportArchive\...Start with Report.wer. Relevant dumps can include RHS, clussvc.exe, and the process hosting smphost. For physical disk hangs, theDumpServicesSmphostproperty controls which services/processes are collected. - Recovery actions if a node remains quarantined after reproduction
General recovery guidance includes:
-
Start-ClusterNode -ClearQuarantine - restart and monitor logs
- if necessary, evict and re-add the node
-
- Important caution Commands that remove cluster resources or alter storage pool ownership are destructive in the wrong scenario. Avoid using CSV removal or storage-pool recovery steps unless the environment actually matches that recovery article and there is a validated rollback plan.
The available material does not document a specific known Windows Server 2022 bug for CsvFsVolumeStateSetDownlevel, a specific issue with the named filter drivers, or a Dell ME5024-specific defect. The supported conclusion is to treat this as a CSV/storage-path investigation and collect cluster, event, network, dump, vendor storage, and filter-driver evidence around the ownership transfer.
References: