High LSASS Threads on 3 of our 2008 R2 DCs

Hi all,

We experience sporadic high LSASS threads on our 3 DCs. Running perfmon does not help much because the incidents are sporadic. Should I just let perfmon run without stopping it? Is there a way to do this without sacrificing the space on the server? On a side note, I ran poolmon and saw that MFEO driver is the top (and has a significant high non paged allocation compared to the rest). And after digging firther, that driver is linked to McAfee. Can someone please advise what is the best way to tackle this issue?
IT_Admin XXXXAsked:
Who is Participating?

[Product update] Infrastructure Analysis Tool is now available with Business Accounts.Learn More

x
I wear a lot of hats...

"The solutions and answers provided on Experts Exchange have been extremely helpful to me over the last few years. I wear a lot of hats - Developer, Database Administrator, Help Desk, etc., so I know a lot of things but not a lot about one thing. Experts Exchange gives me answers from people who do know a lot about one thing, in a easy to use platform." -Todd S.

Qlemo"Batchelor", Developer and EE Topic AdvisorCommented:
With PoolMon you should always monitor the difference after spotting the top consumers. Only if non-paged pool memory increases all the time, you need to really care - because the pool will get exhausted eventually.

LSASS spikes are caused by e.g. attacks, massive logins (including using file shares located on this machine), and similar stuff. So just watching LSASS for high load will not help. You'll need to obtain some evidence to allow for focussing. Event Log might show bursts of authentication attempts, for example, and then it is clear you should focus on that.

If being in the dark, setting up a PerfMon task monitoring the load of LSASS and triggering e.g. a full performance counter set to get collected for a certain timespan, if the load is over x % CPU for y minutes, can give a starting point, but that is unlikely for LSASS.

Experts Exchange Solution brought to you by

Your issues matter to us.

Facing a tech roadblock? Get the help and guidance you need from experienced professionals who care. Ask your question anytime, anywhere, with no hassle.

Start your 7-day free trial
It's more than this solution.Get answers and train to solve all your tech problems - anytime, anywhere.Try it for free Edge Out The Competitionfor your dream job with proven skills and certifications.Get started today Stand Outas the employee with proven skills.Start learning today for free Move Your Career Forwardwith certification training in the latest technologies.Start your trial today
Windows Server 2008

From novice to tech pro — start learning today.