Hi,
today I've got alarms from 2 Hyper-V hosts they are shutting down. Thought at first on power issues, but both have double UPS, redundant PSUs, so it was not likely power related. Once they came up again, I examined Event logs and found this:
First Event ID 43:
Installation Started: Windows has started installing the following update: 2023-06 Cumulative Update for Windows Server 2016 for x64-based Systems (KB5027219)
And Event ID 19:
Installation Successful: Windows successfully installed the following update: Windows Malicious Software Removal Tool x64 - v5.114 (KB890830)
Then 5 hours later, event id 1074:
The process C:\Windows\system32\svchost.exe (HYPERV2) has initiated the restart of computer HYPERV2 on behalf of user NT AUTHORITY\SYSTEM for the following reason: Operating System: Service pack (Planned)
Reason Code: 0x80020010
Shutdown Type: restart
Those Hyper-V hosts run for 4 or 5 years and have never ever auto-reboot nor auto-install anything! Untill now. They are both Server 2016 Standard. How is it possible now all of the sudden both auto-reboot on the same day? Ok, might be coincidence the same day, but auto-reboot - this should not happen on Hyper-V!
They are both stand-alone, not domain joined, no GPO applied, auto-install and auto-reboot are DISABLED.
What the heck happened? Thoughts?