Insights /SQL Server, ERP and legacy systems

SQL Server starts and stops after a few seconds: using ERRORLOG, service accounts, master and tempdb

When SQL Server stops during start-up, read ERRORLOG and Windows events first, then check the service account, start-up parameters, system databases, storage and patching.

Quick answer

When SQL Server stops during start-up, read ERRORLOG and Windows events first, then check the service account, start-up parameters, system databases, storage and patching. For this case, first verify SQL Server ERRORLOG and Windows event logs, then use service-account permissions and passwords to decide whether remediation is needed.

Define the failure boundary first

For this server and database case, establish the failure boundary with SQL Server ERRORLOG and Windows, then continue to service-account permissions and passwords. Capture the current state, incident time and one known-good comparison before changing production configuration.

Work through the dependency chain

CheckWhy it mattersRecommended action
01 · SQL Server ERRORLOGVerify SQL Server ERRORLOG on the affected path using logs, counters or state information rather than relying only on the configured rule.Record the current value, evidence source and timestamp for SQL Server ERRORLOG. If adjustment is required, change one condition only and retain the original setting for rollback.
02 · Windows event logsVerify Windows event logs on the affected path using logs, counters or state information rather than relying only on the configured rule.Check Windows event logs read-only and save the result. If it differs from the baseline, correlate it with the incident time and recent changes before remediation.
03 · service-account permissions and passwordsVerify service-account permissions and passwords on the affected path using logs, counters or state information rather than relying only on the configured rule.Compare service-account permissions and passwords with a known-good peer, the log timeline and the real application path; confirm whether it is causal before changing production.
04 · startup parametersReview the current state, related logs and recent changes for startup parameters, then align them with the incident timeline before deciding whether a change is required.Record the current value, evidence source and timestamp for startup parameters. If adjustment is required, change one condition only and retain the original setting for rollback.
05 · master/model/tempdb pathsReview the current state, related logs and recent changes for master/model/tempdb paths, then align them with the incident timeline before deciding whether a change is required.Check master/model/tempdb paths read-only and save the result. If it differs from the baseline, correlate it with the incident time and recent changes before remediation.
06 · disk space and patch levelReview the current state, related logs and recent changes for disk space and patch level, then align them with the incident timeline before deciding whether a change is required.Compare disk space and patch level with a known-good peer, the log timeline and the real application path; confirm whether it is causal before changing production.

Change only after the evidence is clear

  1. Start with read-only evidence. Check SQL Server ERRORLOG and Windows event logs before changing configuration.
  2. If the first checks are normal, continue with service-account permissions and passwords and startup parameters, keeping evidence tied to the incident time.
  3. Change configuration only when the evidence explains the symptom. For master/model/tempdb paths, preserve the original value and define the rollback trigger before adjustment.
  4. Validate disk space and patch level in a controlled scope before expanding to production users or traffic.

Validation and rollback

  • Validate the complete user or application workflow; do not stop at the single status of SQL Server ERRORLOG.
  • Recheck master/model/tempdb paths and disk space and patch level after the change and confirm that no new bypass, permission expansion or secondary error has appeared.
  • Archive evidence from SQL Server ERRORLOG through disk space and patch level, together with before/after configuration, business validation and the rollback point.

Common wrong turns

  • Changing SQL Server ERRORLOG and Windows at the same time, which makes the original cause impossible to prove.
  • Treating a normal result for service-account permissions and passwords as proof that startup parameters and the rest of the business path are healthy.
  • Leaving a temporary exception related to master/model/tempdb or disk space and patch level in production without an owner, expiry time and rollback note.

Related questions

Where should I start with “SQL Server starts and stops after a few seconds: using ERRORLOG, service accounts, master and tempdb”?

Start with SQL Server ERRORLOG and Windows event logs; they establish the first useful troubleshooting boundary without changing production state.

What should be checked after the first layer looks normal?

Continue with service-account permissions and passwords and startup parameters, then correlate the result with the incident time and the actual user or application path.

What should be retained after the change?

Keep evidence for master/model/tempdb paths and disk space and patch level, plus the original configuration, validation result, observation notes and rollback point.

PreviousSYSVOL or NETLOGON shares are missing on a domain controller: diagnosing DFSR and Group PolicyNextSQL Server database is Recovery Pending or Suspect: safe recovery without increasing damage

Need an assessment based on the actual environment?