Hi,
Hoping to get a few ideas on what might be the cause of this issue we are having.
Background
We have two hyper-v clusters running Server 2012R2.
Our AD environment is a mix of 2008R2 and one 2012R2 DC’s.
We have both 2008R2 and 2012R2 DC’s running virtualised on the Hyper-V clusters.
2008R2 DC is on a VHD disk.
2012R2 DC is on VHDX disk.
We have a number of other 2012R2 and 2008R2 servers on the clusters.
Issue
We have started seeing the above error being logged on the 2012R2 DC only. The 2008R2 DC’s do not show this error at all.
Event ID: 508
Source: ESENT
Level: Warning
svchost (2568) A request to write to the file «C:Windowssystem32LogFilesSumSvc.log» at offset 2023424 (0x00000000001ee000) for 4096 (0x00001000) bytes succeeded, but took an abnormally long time (15 seconds) to be serviced by the OS. This
problem is likely due to faulty hardware. Please contact your hardware vendor for further assistance diagnosing the problem.
lsass (628) A request to write to the file «?Volume{538f044f-9c00-11e3-80c2-00155d1c0903}WindowsNTDSntds.dit» at offset 31342592 (0x0000000001de4000) for 8192 (0x00002000) bytes succeeded, but took an abnormally long time (15 seconds) to
be serviced by the OS. This problem is likely due to faulty hardware. Please contact your hardware vendor for further assistance diagnosing the problem.
Source: NTDS ISAM
NTDS (628) NTDSA: A request to write to the file «E:WindowsNTDSedb.log» at offset 1306624 (0x000000000013f000) for 4096 (0x00001000) bytes succeeded, but took an abnormally long time (21 seconds) to be serviced by the OS. This problem is likely
due to faulty hardware. Please contact your hardware vendor for further assistance diagnosing the problem.
Event ID 509
Source: NTDS ISAM
NTDS (628) NTDSA: A request to read from the file «E:WindowsNTDSntds.dit» at offset 243572736 (0x000000000e84a000) for 8192 (0x00002000) bytes succeeded, but took an abnormally long time (21 seconds) to be serviced by the OS. In addition, 0
other I/O requests to this file have also taken an abnormally long time to be serviced since the last message regarding this problem was posted 23679 seconds ago. This problem is likely due to faulty hardware. Please contact your hardware vendor for further
assistance diagnosing the problem.
Troubleshooting So Far
AV exceptions are in place for scanning
Backup (DPM 2012) disabled for testing
Moved 2012R2 DC to another virtual host
Moved 2012R2 DC to another storage server
The server is fully patched with all latest updates available from windows update.
Any assistance is appreciated.
Regards,
Denis Cooper
MCITP EA — MCT
Help keep the forums tidy, if this has helped please mark it as an answer
My Blog
LinkedIn:
-
Edited by
Monday, February 24, 2014 9:29 AM
Hi,
Hoping to get a few ideas on what might be the cause of this issue we are having.
Background
We have two hyper-v clusters running Server 2012R2.
Our AD environment is a mix of 2008R2 and one 2012R2 DC’s.
We have both 2008R2 and 2012R2 DC’s running virtualised on the Hyper-V clusters.
2008R2 DC is on a VHD disk.
2012R2 DC is on VHDX disk.
We have a number of other 2012R2 and 2008R2 servers on the clusters.
Issue
We have started seeing the above error being logged on the 2012R2 DC only. The 2008R2 DC’s do not show this error at all.
Event ID: 508
Source: ESENT
Level: Warning
svchost (2568) A request to write to the file «C:Windowssystem32LogFilesSumSvc.log» at offset 2023424 (0x00000000001ee000) for 4096 (0x00001000) bytes succeeded, but took an abnormally long time (15 seconds) to be serviced by the OS. This
problem is likely due to faulty hardware. Please contact your hardware vendor for further assistance diagnosing the problem.
lsass (628) A request to write to the file «?Volume{538f044f-9c00-11e3-80c2-00155d1c0903}WindowsNTDSntds.dit» at offset 31342592 (0x0000000001de4000) for 8192 (0x00002000) bytes succeeded, but took an abnormally long time (15 seconds) to
be serviced by the OS. This problem is likely due to faulty hardware. Please contact your hardware vendor for further assistance diagnosing the problem.
Source: NTDS ISAM
NTDS (628) NTDSA: A request to write to the file «E:WindowsNTDSedb.log» at offset 1306624 (0x000000000013f000) for 4096 (0x00001000) bytes succeeded, but took an abnormally long time (21 seconds) to be serviced by the OS. This problem is likely
due to faulty hardware. Please contact your hardware vendor for further assistance diagnosing the problem.
Event ID 509
Source: NTDS ISAM
NTDS (628) NTDSA: A request to read from the file «E:WindowsNTDSntds.dit» at offset 243572736 (0x000000000e84a000) for 8192 (0x00002000) bytes succeeded, but took an abnormally long time (21 seconds) to be serviced by the OS. In addition, 0
other I/O requests to this file have also taken an abnormally long time to be serviced since the last message regarding this problem was posted 23679 seconds ago. This problem is likely due to faulty hardware. Please contact your hardware vendor for further
assistance diagnosing the problem.
Troubleshooting So Far
AV exceptions are in place for scanning
Backup (DPM 2012) disabled for testing
Moved 2012R2 DC to another virtual host
Moved 2012R2 DC to another storage server
The server is fully patched with all latest updates available from windows update.
Any assistance is appreciated.
Regards,
Denis Cooper
MCITP EA — MCT
Help keep the forums tidy, if this has helped please mark it as an answer
My Blog
LinkedIn:
-
Edited by
Monday, February 24, 2014 9:29 AM
Hi,
Hoping to get a few ideas on what might be the cause of this issue we are having.
Background
We have two hyper-v clusters running Server 2012R2.
Our AD environment is a mix of 2008R2 and one 2012R2 DC’s.
We have both 2008R2 and 2012R2 DC’s running virtualised on the Hyper-V clusters.
2008R2 DC is on a VHD disk.
2012R2 DC is on VHDX disk.
We have a number of other 2012R2 and 2008R2 servers on the clusters.
Issue
We have started seeing the above error being logged on the 2012R2 DC only. The 2008R2 DC’s do not show this error at all.
Event ID: 508
Source: ESENT
Level: Warning
svchost (2568) A request to write to the file «C:Windowssystem32LogFilesSumSvc.log» at offset 2023424 (0x00000000001ee000) for 4096 (0x00001000) bytes succeeded, but took an abnormally long time (15 seconds) to be serviced by the OS. This
problem is likely due to faulty hardware. Please contact your hardware vendor for further assistance diagnosing the problem.
lsass (628) A request to write to the file «?Volume{538f044f-9c00-11e3-80c2-00155d1c0903}WindowsNTDSntds.dit» at offset 31342592 (0x0000000001de4000) for 8192 (0x00002000) bytes succeeded, but took an abnormally long time (15 seconds) to
be serviced by the OS. This problem is likely due to faulty hardware. Please contact your hardware vendor for further assistance diagnosing the problem.
Source: NTDS ISAM
NTDS (628) NTDSA: A request to write to the file «E:WindowsNTDSedb.log» at offset 1306624 (0x000000000013f000) for 4096 (0x00001000) bytes succeeded, but took an abnormally long time (21 seconds) to be serviced by the OS. This problem is likely
due to faulty hardware. Please contact your hardware vendor for further assistance diagnosing the problem.
Event ID 509
Source: NTDS ISAM
NTDS (628) NTDSA: A request to read from the file «E:WindowsNTDSntds.dit» at offset 243572736 (0x000000000e84a000) for 8192 (0x00002000) bytes succeeded, but took an abnormally long time (21 seconds) to be serviced by the OS. In addition, 0
other I/O requests to this file have also taken an abnormally long time to be serviced since the last message regarding this problem was posted 23679 seconds ago. This problem is likely due to faulty hardware. Please contact your hardware vendor for further
assistance diagnosing the problem.
Troubleshooting So Far
AV exceptions are in place for scanning
Backup (DPM 2012) disabled for testing
Moved 2012R2 DC to another virtual host
Moved 2012R2 DC to another storage server
The server is fully patched with all latest updates available from windows update.
Any assistance is appreciated.
Regards,
Denis Cooper
MCITP EA — MCT
Help keep the forums tidy, if this has helped please mark it as an answer
My Blog
LinkedIn:
-
Edited by
Monday, February 24, 2014 9:29 AM
-
#1
Whenever I am using google chrome my computer freezes up for about 30 seconds. After the 30 seconds I check my event viewer I get the ESENT issues 508 & 533. I have restored the PC 4 times now and still cannot seem to fix it. All my drivers are installed and up to date. My PC specs are:
EVGA GeForce GTX 970 04G-P4-2978-KR 4GB FTW GAMING w/ACX 2.0, Silent Cooling Graphics Card
CORSAIR RMx RM750X 750W ATX12V / EPS12V 80 PLUS GOLD
AMD FX-8350 Black Edition Vishera 8-Core 4.0 GHz (4.2 GHz Turbo) Socket AM3+ 125W FD8350FRHKBOX Desktop Processor
GIGABYTE GA-990FXA-UD5 R5 (rev. 1.0) AM3+ AMD 990FX SATA 6Gb/s USB 3.0 ATX AMD Motherboard
HyperX Fury Black Series 16GB (2 x 8GB) 240-Pin DDR3 SDRAM DDR3 1600
And the event details are:
— <Event xmlns=»http://schemas.microsoft.com/win/2004/08/events/event»>
— <System>
<Provider Name=»ESENT» />
<EventID Qualifiers=»0″>508</EventID>
<Level>3</Level>
<Task>7</Task>
<Keywords>0x80000000000000</Keywords>
<TimeCreated SystemTime=»2016-08-18T17:52:12.241672100Z» />
<EventRecordID>382</EventRecordID>
<Channel>Application</Channel>
<Computer>DESKTOP-99BECKT</Computer>
<Security />
</System>
— <EventData>
<Data>taskhostw</Data>
<Data>3880</Data>
<Data>WebCacheLocal:</Data>
<Data>C:UsersHugoAppDataLocalMicrosoftWindowsWebCacheV01.log</Data>
<Data>507904 (0x000000000007c000)</Data>
<Data>4096 (0x00001000)</Data>
<Data>36</Data>
</EventD
— <Event xmlns=»http://schemas.microsoft.com/win/2004/08/events/event»>
— <System>
<Provider Name=»ESENT» />
<EventID Qualifiers=»0″>533</EventID>
<Level>3</Level>
<Task>1</Task>
<Keywords>0x80000000000000</Keywords>
<TimeCreated SystemTime=»2016-08-18T17:52:12.241672100Z» />
<EventRecordID>383</EventRecordID>
<Channel>Application</Channel>
<Computer>DESKTOP-99BECKT</Computer>
<Security />
</System>
— <EventData>
<Data>taskhostw</Data>
<Data>3880</Data>
<Data>WebCacheLocal:</Data>
<Data>C:UsersHugoAppDataLocalMicrosoftWindowsWebCacheWebCacheV01.dat</Data>
<Data>98304 (0x0000000000018000)</Data>
<Data>32768 (0x00008000)</Data>
<Data>36</Data>
</EventData>
</Event>
And the General view:
taskhostw (3880) WebCacheLocal: A request to write to the file «C:UsersHugoAppDataLocalMicrosoftWindowsWebCacheV01.log» at offset 507904 (0x000000000007c000) for 4096 (0x00001000) bytes succeeded, but took an abnormally long time (36 seconds) to be serviced by the OS. This problem is likely due to faulty hardware. Please contact your hardware vendor for further assistance diagnosing the problem.
- Jun 12, 2015
- 61,167
- 5,188
- 166,290
- 10,454
-
#14
samsung ssd have 5 year warranties, you might want to rma yours and ask for a new one. Those scores are a little worrying
- Jun 12, 2015
- 61,167
- 5,188
- 166,290
- 10,454
-
#3
Sorry haha. I have a 1 TB western digital HDD and a 250 Gb samsung SSD. And both barley have anything on them. After I ran the test with the link you gave me nothing worked but what information I did get was when I safe booted and I turned off all the 3rd party application that google chrome still froze.
- Jun 12, 2015
- 61,167
- 5,188
- 166,290
- 10,454
-
#4
ESENT is a database used by Microsoft search, and indexing. There is very little information on google about these errors, which always helps. Its also used by the apps on the store.
Event 508:
If the event is just one odd occurrence, then it may be just a transient problem. If it happens on regular basis then the specified drive should be checked for problems (run chkdsk, make sure you have enough free space and physical memory — running low on memory may affect all the disk operations).
http://www.eventid.net/display-eventid-508-source-ESENT-eventno-5580-phase-1.htm
try a checkdisk on both drives, you don’t fall into last two.
-
#5
ESENT is a database used by Microsoft search, and indexing. There is very little information on google about these errors, which always helps. Its also used by the apps on the store.
Event 508:
If the event is just one odd occurrence, then it may be just a transient problem. If it happens on regular basis then the specified drive should be checked for problems (run chkdsk, make sure you have enough free space and physical memory — running low on memory may affect all the disk operations).
http://www.eventid.net/display-eventid-508-source-ESENT-eventno-5580-phase-1.htm
try a checkdisk on both drives, you don’t fall into last two.
Nope tried it on both and it says nothing is wrong with both of them
- Jun 12, 2015
- 61,167
- 5,188
- 166,290
- 10,454
-
#6
One guy fixed it running this so its worth a try
right click start button
choose command prompt (admin)
type SFC /scannow and press enter
this scans system files and may fix this behaviour
-
#7
One guy fixed it running this so its worth a try
right click start button
choose command prompt (admin)
type SFC /scannow and press enter
this scans system files and may fix this behaviour
Nope nothing. I did notice my RAM sticks were not in the same color I’m not sure if that could be the cause but so far no freezes in 30min of use
- Jun 12, 2015
- 61,167
- 5,188
- 166,290
- 10,454
-
#8
508, on ever search I do comes back as the storage device being the cause. I looked into your ram idea but did not see any results similar. I assume windows is seeing the right amount for you?
533 appears to be a logon failure: Event 533 is logged on the workstation or server where the user failed to logon. https://www.ultimatewindowssecurity.com/securitylog/encyclopedia/event.aspx?eventid=533
I checked around and found a few explanations for the event you listed. The common theme for this event was that it is indicating a faulty drive or controller. Here are some of the explanations for the event 508, I got them from eventid.net you have to be a member to see the results so I will paste some of what I found.
«As per Microsoft: «This Warning event is logged when the Exchange database engine tries to write to the named file and encounters a delayed response from the operating system in performing that write operation. This is a warning, not an error, because the operation eventually finishes, although it is slow. This might indicate a hardware problem, probably with the disk controller, a disk, or other storage component». See MSEX2K3DB for more information about this event»
https://www.experts-exchange.com/questions/23306210/Sporadic-networking-performance-issues-only-event-ID-508-from-ESE-to-suggest-problem.html
i think 533 is a result of 508, you must have been trying to logon to a site online and the ssd was too slow to respond, and the logon timed out in the 30 second freeze time.
All signs point at ssd, you may not believe it but that is what PC is telling you. Only other choice is drivers, I don’t think flashing bios would fix this, and you say you have latest now.
-
#9
508, on ever search I do comes back as the storage device being the cause. I looked into your ram idea but did not see any results similar. I assume windows is seeing the right amount for you?
533 appears to be a logon failure: Event 533 is logged on the workstation or server where the user failed to logon. https://www.ultimatewindowssecurity.com/securitylog/encyclopedia/event.aspx?eventid=533
I checked around and found a few explanations for the event you listed. The common theme for this event was that it is indicating a faulty drive or controller. Here are some of the explanations for the event 508, I got them from eventid.net you have to be a member to see the results so I will paste some of what I found.
«As per Microsoft: «This Warning event is logged when the Exchange database engine tries to write to the named file and encounters a delayed response from the operating system in performing that write operation. This is a warning, not an error, because the operation eventually finishes, although it is slow. This might indicate a hardware problem, probably with the disk controller, a disk, or other storage component». See MSEX2K3DB for more information about this event»
https://www.experts-exchange.com/questions/23306210/Sporadic-networking-performance-issues-only-event-ID-508-from-ESE-to-suggest-problem.html
i think 533 is a result of 508, you must have been trying to logon to a site online and the ssd was too slow to respond, and the logon timed out in the 30 second freeze time.
All signs point at ssd, you may not believe it but that is what PC is telling you. Only other choice is drivers, I don’t think flashing bios would fix this, and you say you have latest now.
I ran a benchmark test with my SSD and it seems it be really slow with random read and write.
- Jun 12, 2015
- 61,167
- 5,188
- 166,290
- 10,454
-
#10
Can you share results and I see if I can confirm your suspicion.
-
#11
Can you share results and I see if I can confirm your suspicion.
Sequential Read: 2563
Sequential Write: 1140
Random Read: 62282
Random Write: 22469
- Jun 12, 2015
- 61,167
- 5,188
- 166,290
- 10,454
-
#12
Can you share results and I see if I can confirm your suspicion.
Sequential Read: 2563
Sequential Write: 1140
Random Read: 62282
Random Write: 22469
are you running rapid through Samsung Magician? I only ask as your sequential is way bigger than mine but I am not running rapid
mine are (we both had same SSD)
SR: 548
SW: 484
RR: 95725
RW: 82982
your random scores are still lower so, especially the Random write
rapid mode is essentially a RAMDISK that the magician software creates in your system for the SSD to use. the memory in SSDs is slower then your ram. but using the ram means your risk of data loss in a power failure should be greater since your SSD is using it as a buffer of sorts.
IF samsung is using the rapid mode test results in their official benchmarks for these drives, what they are doing would be considered a scam because its not testing the drives, its testing a ramdisk.
i have a brand new samsung 850 pro 256GB and i have the same issue. using magician Without rapid mode my scores are.
Sequential read — 547 MB/s (expected 550 but good enough)
Sequential write — 502 MB/s (expected 520 but good enough)Random read — 61893 IOPs (expected 100,000)
Random write — 50409 IOPs (expected 90,000)
http://www.tomshardware.com/answers/id-2507951/850-evo-low-iops.html
looking through that thread, one possible thing you can do is install latest Intel Raid Storage Technology drivers, it seems it might speed you up, but your random read/write scores are very low. Also seems AMD motherboards supply slower scores than Intel ones.
If you used samsung magician to do benchmarks, it seems it isn’t very accurate. http://www.tomshardware.com/answers/id-2573130/brand-samsung-850-evo-250gb-low-random-read-write-iops.html
try running As SSD benchmark
as a comparison — these are my scores

-
#13
Can you share results and I see if I can confirm your suspicion.
Sequential Read: 2563
Sequential Write: 1140
Random Read: 62282
Random Write: 22469
are you running rapid through Samsung Magician? I only ask as your sequential is way bigger than mine but I am not running rapid
mine are (we both had same SSD)
SR: 548
SW: 484
RR: 95725
RW: 82982
your random scores are still lower so, especially the Random write
rapid mode is essentially a RAMDISK that the magician software creates in your system for the SSD to use. the memory in SSDs is slower then your ram. but using the ram means your risk of data loss in a power failure should be greater since your SSD is using it as a buffer of sorts.
IF samsung is using the rapid mode test results in their official benchmarks for these drives, what they are doing would be considered a scam because its not testing the drives, its testing a ramdisk.
i have a brand new samsung 850 pro 256GB and i have the same issue. using magician Without rapid mode my scores are.
Sequential read — 547 MB/s (expected 550 but good enough)
Sequential write — 502 MB/s (expected 520 but good enough)Random read — 61893 IOPs (expected 100,000)
Random write — 50409 IOPs (expected 90,000)
http://www.tomshardware.com/answers/id-2507951/850-evo-low-iops.html
looking through that thread, one possible thing you can do is install latest Intel Raid Storage Technology drivers, it seems it might speed you up, but your random read/write scores are very low. Also seems AMD motherboards supply slower scores than Intel ones.
If you used samsung magician to do benchmarks, it seems it isn’t very accurate. http://www.tomshardware.com/answers/id-2573130/brand-samsung-850-evo-250gb-low-random-read-write-iops.html
try running As SSD benchmark
Yes I am running Rapid without it my random stuff are 9000 or lower
- Jun 12, 2015
- 61,167
- 5,188
- 166,290
- 10,454
-
#14
samsung ssd have 5 year warranties, you might want to rma yours and ask for a new one. Those scores are a little worrying
-
#15
I had this same issue and immediately suspected a Trojan. It was Poweliks Trojan. This piece of garbage does not download files but just changes some code and causes your machine to pull in fake ad visits and fake clicks that look like real clicks to the vendors. I removed it with Hitman Pro, but symantek has a free poweliks removal tool.
My machine was freezing for 30 seconds or more at a time and it was maddening. Anyone with these ESENT issues should use a good quality Trojan or rootkit sniffer to see if that’s the issue.
-
#16
samsung ssd have 5 year warranties, you might want to rma yours and ask for a new one. Those scores are a little worrying
I was hoping you could interpret these numbers for me after running a scan. The last couple days I have been having random freezing, which last for about 15-30 seconds, then returns to normal. I have updated all drivers, checked memory, run disk check, system file checker, etc. with no resolution. During this test I noticed in the upper left hand corner, in German lol, it says PCI IDE controller-bad. Here are the numbers:
292.37 — 163.84
14.36 — 50.72
18.37 — 82.32
0.261 — 0.304
Score 62 — 156
I would appreciate any help you could provide.
- Jun 12, 2015
- 61,167
- 5,188
- 166,290
- 10,454
-
#17
what are specs of PC? How old is motherboard? What make ssd?
- Advertising
- Cookies Policies
- Privacy
- Term & Conditions
- Topics

Проблема: система зависает на 30 секунд, фризит полностью, не двигается даже мышь. Взаимосвязи пока не увидел — происходит в рандомные промежутки использования пк, но вроде как чаще при запуске игр.
в просмотре событий появляется несколько предупреждений с источником ESENT, код события 508 или 510. заметил, что одновременно вместе с ними появляются ошибки «Операция ввода-вывода по адресу логического блока 0x15706b40 для диска 0 (имя PDO: Device000003b) выполнена повторно.» и «Был произведен возврат к устройству DeviceRaidPort0.»
Интересно то, что проблема проявляется где-то раз в неделю и перезагрузка/полное выключение/выключение блока питания проблему не убирают, уходит она сама через 1-2 часа и не появляется еще около недели при таком же сценарии использования пк (как бы я его не нагружал и как бы я не пытался повторить ошибку)
Что делал:
Переустанавливал винду с 10 на 11, менял провод сата, менял порт в материнке, менял провод питания от БП, устанавливал драйвера для чипсета. версия биос последняя, AHCI активирован, ставил 0 в графе «отключать жд через». Системный диск проверял чекдиском и викторией
Инфа: Mobo: B550 GAMING X
CPU: AMD Ryzen™ 5 5600X @ 4.6GHz + ID-Cooling Zoomflow 240XT
GPU: RTX 3070 Ti Aorus Master
RAM: 32GB DDR4 3200 Mhz
SSD: 1TB NVMe M.2 Kingston A2000 + 250GB Samsung 850 EVO
HDD: 2TB 7200RPM
PSU: 700W BeQuiet SP 9
Case: ZET GAMING Rare M2
OS: Windows 11 64bit
Monitor: LG 32GK650F (144hz QHD 31.5″) + AOC Q3279VWFD8 (75hz QHD 31.5″)
Recently set up a new file server (VM running Server 2012 R2). Server has separate OS and Data partitions (each on different physical disk array) and I’ve enabled Shadow Copies on the Data volume. Server is also running DFS/DFSR and replicating the files
on the Data volume with other file servers. The VM is running on Hyper-V host, which is also Server 2012 R2.
Each day, when a shadow copy snapshot is taken, the file server generates an ESENT Event ID 508 similar to the following:
DFSRs (1192) \.D:System Volume InformationDFSRdatabase_5464_BC1C_64BC_2B2dfsr.db: A request to write to the file «\.D:System Volume InformationDFSRdatabase_5464_BC1C_64BC_2B2fsr.log»
at offset 4075520 (0x00000000003e3000) for 4096 (0x00001000) bytes succeeded, but took an abnormally long time (25 seconds) to be serviced by the OS. This problem is likely due to faulty hardware. Please contact your hardware vendor for further assistance
diagnosing the problem.
So first thought was maybe I do have faulty hardware. But I set up a second file server (on separate physical host with identical hardware) and am seeing the same behavior on that server as well. The odds of both servers having faulty hardware are pretty
low, so it must be my configuration.
I noticed the Shadow Copy storage area was set to the same volume as the snapshot being taken, so I changed that to use the OS volume instead, but that didn’t fix it:
Then I tried turning off Windows write-cache buffer flushing on the Data volume, but that didn’t help:
Tried allocating more (and static) memory to the server, rather than having it use Dynamic Memory, but no change there either.
Using Hyper-V manager, tried moving the vhdx file from IDE controller to SCSI, but no change there.
Anyone else have any suggestions/insight into what the problem might be or how I can fix it?
Shaun
-
Edited by
Thursday, May 5, 2016 6:34 PM
Hi,
Hoping to get a few ideas on what might be the cause of this issue we are having.
Background
We have two hyper-v clusters running Server 2012R2.
Our AD environment is a mix of 2008R2 and one 2012R2 DC’s.
We have both 2008R2 and 2012R2 DC’s running virtualised on the Hyper-V clusters.
2008R2 DC is on a VHD disk.
2012R2 DC is on VHDX disk.
We have a number of other 2012R2 and 2008R2 servers on the clusters.
Issue
We have started seeing the above error being logged on the 2012R2 DC only. The 2008R2 DC’s do not show this error at all.
Event ID: 508
Source: ESENT
Level: Warning
svchost (2568) A request to write to the file «C:Windowssystem32LogFilesSumSvc.log» at offset 2023424 (0x00000000001ee000) for 4096 (0x00001000) bytes succeeded, but took an abnormally long time (15 seconds) to be serviced by the OS. This
problem is likely due to faulty hardware. Please contact your hardware vendor for further assistance diagnosing the problem.
lsass (628) A request to write to the file «\?Volume{538f044f-9c00-11e3-80c2-00155d1c0903}WindowsNTDSntds.dit» at offset 31342592 (0x0000000001de4000) for 8192 (0x00002000) bytes succeeded, but took an abnormally long time (15 seconds) to
be serviced by the OS. This problem is likely due to faulty hardware. Please contact your hardware vendor for further assistance diagnosing the problem.
Source: NTDS ISAM
NTDS (628) NTDSA: A request to write to the file «E:WindowsNTDSedb.log» at offset 1306624 (0x000000000013f000) for 4096 (0x00001000) bytes succeeded, but took an abnormally long time (21 seconds) to be serviced by the OS. This problem is likely
due to faulty hardware. Please contact your hardware vendor for further assistance diagnosing the problem.
Event ID 509
Source: NTDS ISAM
NTDS (628) NTDSA: A request to read from the file «E:WindowsNTDSntds.dit» at offset 243572736 (0x000000000e84a000) for 8192 (0x00002000) bytes succeeded, but took an abnormally long time (21 seconds) to be serviced by the OS. In addition, 0
other I/O requests to this file have also taken an abnormally long time to be serviced since the last message regarding this problem was posted 23679 seconds ago. This problem is likely due to faulty hardware. Please contact your hardware vendor for further
assistance diagnosing the problem.
Troubleshooting So Far
AV exceptions are in place for scanning
Backup (DPM 2012) disabled for testing
Moved 2012R2 DC to another virtual host
Moved 2012R2 DC to another storage server
The server is fully patched with all latest updates available from windows update.
Any assistance is appreciated.
Regards,
Denis Cooper
MCITP EA — MCT
Help keep the forums tidy, if this has helped please mark it as an answer
My Blog
LinkedIn:
-
Edited by
Monday, February 24, 2014 9:29 AM
Hi there,
Users have complained to me that at about 3:00 every day, our file server slows down and applications hang. I finally found an indicator of this after looking at all scheduled tasks, backup plans, etc.
The Application logs in Event Viewer show every day for the last month at about 3:05pm warning (with one outlier at 5:45am):
Source: Esent
EventID: 508
svchost (5184) A request to write to the file «C:Windowssystem32LogFilesSumSvc.log» at offset 2904064 (0x00000000002c5000) for 4096 (0x00001000) bytes succeeded, but took an abnormally long time (39 seconds) to be serviced by the OS. This problem is likely due to faulty hardware. Please contact your hardware vendor for further assistance diagnosing the problem.
I don’t know if this is exactly it, but it seems like it’s cause for concern. To rule out faulty hardware, I’m going to run a chkdsk after folks head out this evening. Just thinking out loud; my file server partition and the Windows Server 2012 partitions are on the same physical disk (yuck) but I do have a RAID1 setup going, so a bad disk won’t be the end of the world.
I’ve seen some other posts about this being caused by a dead battery on a RAID controller. so I’ll check that out too. I have half a terabyte free on this partition, so it’s not an issue of a full disk.
Any other known culprits of this issue?
My monitoring system informed me about the following event log entry on my Azure VM (Windows Server 2016 Datacenter):
Catalog Database (1180) Catalog Database: A request to write to the file «C:Windowssystem32CatRoot2{F750E6C3-38EE-11D1-85E5-00C04FC295EE}catdb» at offset 48676864 (0x0000000002e6c000) for 4096 (0x00001000) bytes succeeded, but took an abnormally long time (17 seconds) to be serviced by the OS. This problem is likely due to faulty hardware. Please contact your hardware vendor for further assistance diagnosing the problem.
(EventLog: Application, Source: ESENT, EventID: 508, EventLevelName: Warning)
I remember seeing this message before, a few months ago (and maybe another time a few months before that). The machine is an Azure VM, so my «hardware vendor» is Microsoft.
So, is the event log warning (a) likely to point to a serious problem that needs addressing, or (b) a well-known false positive in hosting scenarios?
