Smart questions
Smart answers
Smart people
Join Tek-Tips Forums
INTELLIGENT WORK FORUMS
FOR COMPUTER PROFESSIONALS

Member Login




Remember Me
Forgot Password?
Join Us!

Come Join Us!

Are you a
Computer / IT professional?
Join Tek-Tips now!
  • Talk With Other Members
  • Be Notified Of Responses
    To Your Posts
  • Keyword Search
  • One-Click Access To Your
    Favorite Forums
  • Automated Signatures
    On Your Posts
  • Best Of All, It's Free!

Join Tek-Tips
*Tek-Tips's functionality depends on members receiving e-mail. By joining you are opting in to receive e-mail.

Posting Guidelines

Promoting, selling, recruiting, coursework and thesis posting is forbidden.
Jobs from Indeed

Link To This Forum!

Partner Button
Add Stickiness To Your Site By Linking To This Professionally Managed Technical Forum.
Just copy and paste the
code below into your site.

irbk (MIS) (OP)
4 Jan 11 9:24
Recently, I've started getting the following warnings in my Exchange 2010 server's application log.

CODE

Log Name:      Application
Source:        ESE
Date:          1/3/2011 10:06:02 PM
Event ID:      906
Task Category: Performance
Level:         Warning
Keywords:      Classic
User:          N/A
Computer:      ServerName.Domain.com
Description:
Information Store (6800) A significant portion of the database buffer cache has been written out to the system paging file.  This may result in severe performance degradation.
See help link for complete details of possible causes.
Resident cache has fallen by 240438 buffers (or 99%) in the last 50341 seconds.
Current Total Percent Resident: 0% (414 of 260621 buffers)
Event Xml:
<Event xmlns="http://schemas.microsoft.com/win/2004/08/events/event">
  <System>
    <Provider Name="ESE" />
    <EventID Qualifiers="0">906</EventID>
    <Level>3</Level>
    <Task>7</Task>
    <Keywords>0x80000000000000</Keywords>
    <TimeCreated SystemTime="2011-01-04T04:06:02.000000000Z" />
    <EventRecordID>144764</EventRecordID>
    <Channel>Application</Channel>
    <Computer>ServerName.Domain.com</Computer>
    <Security />
  </System>
  <EventData>
    <Data>Information Store</Data>
    <Data>6800</Data>
    <Data>
    </Data>
    <Data>240438</Data>
    <Data>99</Data>
    <Data>50341</Data>
    <Data>0</Data>
    <Data>414</Data>
    <Data>260621</Data>
  </EventData>
</Event>
I've done some Google searching and have not found much that seems applicable to me.  The server should have plenty of "oompf" for ~150 users.  
Dual 2.5 Ghz Xeon proc
16 GB memory
2 Databases (1 is ~33.5 Gb, the other is ~76 Gb) running on a RAID 10.
Daily full backups that purge the transaction logs after a successful backup.
I can't figure out what seems to be causing this, but it seems to happen about twice a day, but the times vary.  It happened at about 10 PM last night, so it will likely happen at about 10 AM this morning.  I'm going to fire up ProcessMonitor at about that time and see if I'm lucky and happen to catch when it's running.  I've not had any luck with catching it so far.  I'm hoping some one else has perhaps run across this and could offer some advice.
irbk (MIS) (OP)
4 Jan 11 11:27
I didn't manage to catch it with ProcessMonitor, however, I was going through the old logs paying more attention to what was just before the warning.  It was just an informational message and it kept escaping my attention.  So far, I've noticed that before every one of these ESE warnings is a McAfee Event.  Says the McShield service started.  So my guess is that when McAfee is checking for updates (and I'm pretty sure McAfee checks for updates about every 12 hours) finds a DAT update and applies it, it's causing my system to have to right everything from buffer.  This would explain why it seems to happen on a some what regular schedule, yet not all the time.  Thankfully, were getting rid of the McAfee ASAP/Total Protection software on our servers.  It's never really run well on the servers.  Works good for the desktops but on the servers it's always been problematic despite McAfee's claims that it's compatible with servers.  We are switching to Endpoint on the servers.  It's more of a "stand alone" product like VirusScan was.  Hopefully after we get teh Endpoint installed I'll see these errors go away.

Reply To This Thread

Posting in the Tek-Tips forums is a member-only feature.

Click Here to join Tek-Tips and talk with other members!

Back To Forum

Close Box

Join Tek-Tips® Today!

Join your peers on the Internet's largest technical computer professional community.
It's easy to join and it's free.

Here's Why Members Love Tek-Tips Forums:

Register now while it's still free!

Already a member? Close this window and log in.

Join Us             Close