Prashant Girennavar
asked on
ntdll dll etwtracemessageva+0x130 on windows server 2008 R2 high CPU Usage
Hello Experts,
We have one windows server 2008 r2 which is under monitoring. Every time we get an alert about CPU Usage is high for this server. I have checked the server and found out that eventlog service is taking high CPU usage (SVCHost.exe).
I have used Process Explorer to get the information. Below are the stack value for above service.
ntoskrnl.exe!SeAccessCheck WithHint+0 xb4a
ntoskrnl.exe!IoGetRequesto rProcess+0 x250
ntoskrnl.exe!ExfTryToWakeP ushLock+0x 899
ntoskrnl.exe!KeStackAttach Process+0x 117f
ntoskrnl.exe!ObReferenceOb jectByPoin terWithTag +0x23b
wevtsvc.dll+0x7984
wevtsvc.dll+0x79f8
wevtsvc.dll+0xf231
wevtsvc.dll+0x22154
wevtsvc.dll!SvchostPushSer viceGlobal s+0x10eae
wevtsvc.dll+0x228fc
wevtsvc.dll+0x2271e
wevtsvc.dll+0x22f50
wevtsvc.dll+0x22ee0
wevtsvc.dll+0x22aaa
wevtsvc.dll!SvchostPushSer viceGlobal s+0xd9ed
wevtsvc.dll!SvchostPushSer viceGlobal s+0xd834
RPCRT4.dll!I_RpcGetBuffer+ 0x265
RPCRT4.dll!Ndr64AsyncServe rCallAll+0 x11ae
RPCRT4.dll!NdrServerCallAl l+0x40
RPCRT4.dll!NdrServerCall2+ 0x1ba4
RPCRT4.dll!NdrServerCall2+ 0x1d06
RPCRT4.dll!NdrServerCall2+ 0x23f9
RPCRT4.dll!NdrServerCall2+ 0x209d
RPCRT4.dll!NdrDllCanUnload Now+0x52f
RPCRT4.dll!NdrDllCanUnload Now+0xe5
ntdll.dll!TpSetTimer+0x3eb
ntdll.dll!EtwTraceMessageV a+0x46f
kernel32.dll!BaseThreadIni tThunk+0xd
ntdll.dll!RtlUserThreadSta rt+0x21
What does this indicate? How I will come to know what application/file which is causing this?
I think I have explained the problem in a clear manner. Please let me know if any other information is needed on this.
Thanks,
_Prashant_
We have one windows server 2008 r2 which is under monitoring. Every time we get an alert about CPU Usage is high for this server. I have checked the server and found out that eventlog service is taking high CPU usage (SVCHost.exe).
I have used Process Explorer to get the information. Below are the stack value for above service.
ntoskrnl.exe!SeAccessCheck
ntoskrnl.exe!IoGetRequesto
ntoskrnl.exe!ExfTryToWakeP
ntoskrnl.exe!KeStackAttach
ntoskrnl.exe!ObReferenceOb
wevtsvc.dll+0x7984
wevtsvc.dll+0x79f8
wevtsvc.dll+0xf231
wevtsvc.dll+0x22154
wevtsvc.dll!SvchostPushSer
wevtsvc.dll+0x228fc
wevtsvc.dll+0x2271e
wevtsvc.dll+0x22f50
wevtsvc.dll+0x22ee0
wevtsvc.dll+0x22aaa
wevtsvc.dll!SvchostPushSer
wevtsvc.dll!SvchostPushSer
RPCRT4.dll!I_RpcGetBuffer+
RPCRT4.dll!Ndr64AsyncServe
RPCRT4.dll!NdrServerCallAl
RPCRT4.dll!NdrServerCall2+
RPCRT4.dll!NdrServerCall2+
RPCRT4.dll!NdrServerCall2+
RPCRT4.dll!NdrServerCall2+
RPCRT4.dll!NdrDllCanUnload
RPCRT4.dll!NdrDllCanUnload
ntdll.dll!TpSetTimer+0x3eb
ntdll.dll!EtwTraceMessageV
kernel32.dll!BaseThreadIni
ntdll.dll!RtlUserThreadSta
What does this indicate? How I will come to know what application/file which is causing this?
I think I have explained the problem in a clear manner. Please let me know if any other information is needed on this.
Thanks,
_Prashant_
ASKER
I think filemon is not available to download from sysinternals site. It is been combined with Process Monitor.
Now I am using Process monitor to find out the program which is taking high CPU , but I am unable to find which program from this tool.
Can you please tell me the procedure to find out the program which is taking this high CPU usage.
I just have a stack of the eventlog service from process monitor tool. ( I have posted the stack above in my question).
Thanks,
_Prashant_
Now I am using Process monitor to find out the program which is taking high CPU , but I am unable to find which program from this tool.
Can you please tell me the procedure to find out the program which is taking this high CPU usage.
I just have a stack of the eventlog service from process monitor tool. ( I have posted the stack above in my question).
Thanks,
_Prashant_
Process monitor won't give you the files and specific read/write information. Darn, I used to even have a copy of the source code to filemon somewhere.
Are you sure filemon isn't there anymore? I think I loaded it on a server at office only a few months ago.
Are you sure filemon isn't there anymore? I think I loaded it on a server at office only a few months ago.
ASKER
http://technet.microsoft.com/en-us/sysinternals/bb896642.aspx
I tried searching that , but no luck. in the above link they are referring , it is been integrated with process explorer.
Please let me know how to proceed.
Thanks,
_Prashant_
I tried searching that , but no luck. in the above link they are referring , it is been integrated with process explorer.
Please let me know how to proceed.
Thanks,
_Prashant_
ASKER
ASKER
Can some one help how to find out the program which is using eventlog service heavily?
I know we have determined the cause it eventlog which is taking high amout of CPU, but I am unable to determine what program is using it extensively.
your help is much appriciated.
Thanks,
_Prashant_
I know we have determined the cause it eventlog which is taking high amout of CPU, but I am unable to determine what program is using it extensively.
your help is much appriciated.
Thanks,
_Prashant_
ASKER CERTIFIED SOLUTION
membership
This solution is only available to members.
To access this solution, you must be a member of Experts Exchange.
SOLUTION
membership
This solution is only available to members.
To access this solution, you must be a member of Experts Exchange.
Glad to help.
ASKER
This is due to HP Operations agent.
With such a utility you should be able to figure out which program is the culprit. Hopefully it wasn't written by a staffer or some commercial software you bought, rather than microsoft.
(Note you can also ask filemon to let you know when a program interacts with the DLL, as it isn't limited to data files)