Showing posts with label experiencing. Show all posts
Showing posts with label experiencing. Show all posts

Monday, February 20, 2012

lsass.exe high cpu, Error 18456

We just migrated to a new sql server with SQL Server 2005 installed (we moved from 2000).

We are experiencing two issues that we cannot resolve:

1. The site and database clients that use this SQL Server run very slow now. We have noticed that the lsass.exe process consistantly uses 25% CPU, +/- 10%. When we stop SQL server the lsass.exe process goes down to 0. What can be causing this? The website uses a SQL user account, not a windows user account.

2. We have an error in the event log that might be related to the issue above. It appears every few minutes:

Event Type: Failure Audit
Event Source: MSSQLSERVER
Event Category: (4)
Event ID: 18456
Date: 10/25/2006
Time: 11:54:42 AM
User: NT AUTHORITY\SYSTEM
Computer: MSDB
Description:
Login failed for user 'NT AUTHORITY\SYSTEM'. [CLIENT: <local machine>]

The error log from SQL gives more info:

Error: 18456, Severity: 14, State: 16.

What is causing this? How can this be traced?

I am stuck here. All help greatly appreciated.

Moshe

I'm not sure about the lsass.exe process, but here is a good blog from the SQL Protocols team about the failure error messages.

http://blogs.msdn.com/sql_protocols/archive/2006/02/21/536201.aspx

Thanks,
Sam Lester (MSFT)

|||

I have seen that blog, but it did not help me. I will post there anyway though.

Please advise, this is a serious issue.

|||

I may also add that I have not yet ungraded to Service Pack 1. Are their any known issues related to this that were fixed with Service Pack 1? I would only upgrade now if you were confident that upgrading would fix the issue since the server is now deployed.

|||People, including me, have also seen high CPU usage by lsass.exe when signing into Windows Live Messenger (and possibly earlier versions of Messenger).
|||I have the same problem, everytime that I open messenger live the cpu goes high, lsass.exe take all my cpu...

have you find something to fix the problem?

regards,

|||I reformatted the machine that resolved the issue. Microsoft PSS was not helpful in this and could not uncover the cause of the issue. Sad

lsass.exe high cpu, Error 18456

We just migrated to a new sql server with SQL Server 2005 installed (we moved from 2000).

We are experiencing two issues that we cannot resolve:

1. The site and database clients that use this SQL Server run very slow now. We have noticed that the lsass.exe process consistantly uses 25% CPU, +/- 10%. When we stop SQL server the lsass.exe process goes down to 0. What can be causing this? The website uses a SQL user account, not a windows user account.

2. We have an error in the event log that might be related to the issue above. It appears every few minutes:

Event Type: Failure Audit
Event Source: MSSQLSERVER
Event Category: (4)
Event ID: 18456
Date: 10/25/2006
Time: 11:54:42 AM
User: NT AUTHORITY\SYSTEM
Computer: MSDB
Description:
Login failed for user 'NT AUTHORITY\SYSTEM'. [CLIENT: <local machine>]

The error log from SQL gives more info:

Error: 18456, Severity: 14, State: 16.

What is causing this? How can this be traced?

I am stuck here. All help greatly appreciated.

Moshe

I'm not sure about the lsass.exe process, but here is a good blog from the SQL Protocols team about the failure error messages.

http://blogs.msdn.com/sql_protocols/archive/2006/02/21/536201.aspx

Thanks,
Sam Lester (MSFT)

|||

I have seen that blog, but it did not help me. I will post there anyway though.

Please advise, this is a serious issue.

|||

I may also add that I have not yet ungraded to Service Pack 1. Are their any known issues related to this that were fixed with Service Pack 1? I would only upgrade now if you were confident that upgrading would fix the issue since the server is now deployed.

|||People, including me, have also seen high CPU usage by lsass.exe when signing into Windows Live Messenger (and possibly earlier versions of Messenger).
|||I have the same problem, everytime that I open messenger live the cpu goes high, lsass.exe take all my cpu...

have you find something to fix the problem?

regards,

|||I reformatted the machine that resolved the issue. Microsoft PSS was not helpful in this and could not uncover the cause of the issue. Sad

lsass.exe high cpu, Error 18456

We just migrated to a new sql server with SQL Server 2005 installed (we moved from 2000).

We are experiencing two issues that we cannot resolve:

1. The site and database clients that use this SQL Server run very slow now. We have noticed that the lsass.exe process consistantly uses 25% CPU, +/- 10%. When we stop SQL server the lsass.exe process goes down to 0. What can be causing this? The website uses a SQL user account, not a windows user account.

2. We have an error in the event log that might be related to the issue above. It appears every few minutes:

Event Type: Failure Audit
Event Source: MSSQLSERVER
Event Category: (4)
Event ID: 18456
Date: 10/25/2006
Time: 11:54:42 AM
User: NT AUTHORITY\SYSTEM
Computer: MSDB
Description:
Login failed for user 'NT AUTHORITY\SYSTEM'. [CLIENT: <local machine>]

The error log from SQL gives more info:

Error: 18456, Severity: 14, State: 16.

What is causing this? How can this be traced?

I am stuck here. All help greatly appreciated.

Moshe

I'm not sure about the lsass.exe process, but here is a good blog from the SQL Protocols team about the failure error messages.

http://blogs.msdn.com/sql_protocols/archive/2006/02/21/536201.aspx

Thanks,
Sam Lester (MSFT)

|||

I have seen that blog, but it did not help me. I will post there anyway though.

Please advise, this is a serious issue.

|||

I may also add that I have not yet ungraded to Service Pack 1. Are their any known issues related to this that were fixed with Service Pack 1? I would only upgrade now if you were confident that upgrading would fix the issue since the server is now deployed.

|||People, including me, have also seen high CPU usage by lsass.exe when signing into Windows Live Messenger (and possibly earlier versions of Messenger).|||I have the same problem, everytime that I open messenger live the cpu goes high, lsass.exe take all my cpu...

have you find something to fix the problem?

regards,|||I reformatted the machine that resolved the issue. Microsoft PSS was not helpful in this and could not uncover the cause of the issue. Sad

LSASS.EXE high CPU usage

I have a web/SQL server (Win2k3sp1, SQL2005) currently experiencing a serious
problem.
Regularly throughout the day, the LSASS.EXE process jumps from <2% CPU usage
to 50-70% CPU, sometime for 30 seconds, sometimes as long as 30 minutes. The
consequence of course being that the server goes to a constant 100% CPU
usage, causing services to be denied or be unacceptably slow. During normal
operation (when LSASS is behaving), the server spec is more than enough to
cope with it's workload, and runs at around 20% CPU usage.
There were issues with LSASS.EXE in Win2k, but none that I know of or can
find in Win2k3. This is not a SASSER type worm virus, it's genuine LSASS.EXE.
I'm not even sure if this is the cause of the problem or a symptom of
something else.
Please suggest something, this is a critical production server and this has
now become a serious issue.
Thanks.
Could you check in your eventLog and see if there are repeated error
messages , particuarly in Directory Services Log?
Jack Vamvas
__________________________________________________ ________________
Receive free SQL tips - register at www.ciquery.com/sqlserver.htm
SQL Server Performance Audit - check www.ciquery.com/sqlserver_audit.htm
New article by Jack Vamvas - SQL and Markov Chains -
www.ciquery.com/articles/art_04.asp
"The Vogon" <TheVogon@.discussions.microsoft.com> wrote in message
news:0CB0C2E5-4AC5-4F71-B7D7-16180F368002@.microsoft.com...
> I have a web/SQL server (Win2k3sp1, SQL2005) currently experiencing a
serious
> problem.
> Regularly throughout the day, the LSASS.EXE process jumps from <2% CPU
usage
> to 50-70% CPU, sometime for 30 seconds, sometimes as long as 30 minutes.
The
> consequence of course being that the server goes to a constant 100% CPU
> usage, causing services to be denied or be unacceptably slow. During
normal
> operation (when LSASS is behaving), the server spec is more than enough to
> cope with it's workload, and runs at around 20% CPU usage.
> There were issues with LSASS.EXE in Win2k, but none that I know of or can
> find in Win2k3. This is not a SASSER type worm virus, it's genuine
LSASS.EXE.
> I'm not even sure if this is the cause of the problem or a symptom of
> something else.
> Please suggest something, this is a critical production server and this
has
> now become a serious issue.
> Thanks.
>
|||Thanks for the reply...
There are no errors regarding this in the log files, no out of the ordinary
errors or warnings are generated. Incidentally, the server is not a Domain
Controller so no DS logs.
"Jack Vamvas" wrote:

> Could you check in your eventLog and see if there are repeated error
> messages , particuarly in Directory Services Log?
> --
> Jack Vamvas
> __________________________________________________ ________________
> Receive free SQL tips - register at www.ciquery.com/sqlserver.htm
> SQL Server Performance Audit - check www.ciquery.com/sqlserver_audit.htm
> New article by Jack Vamvas - SQL and Markov Chains -
> www.ciquery.com/articles/art_04.asp
> "The Vogon" <TheVogon@.discussions.microsoft.com> wrote in message
> news:0CB0C2E5-4AC5-4F71-B7D7-16180F368002@.microsoft.com...
> serious
> usage
> The
> normal
> LSASS.EXE.
> has
>
>

LSASS.EXE high CPU usage

I have a web/SQL server (Win2k3sp1, SQL2005) currently experiencing a serious
problem.
Regularly throughout the day, the LSASS.EXE process jumps from <2% CPU usage
to 50-70% CPU, sometime for 30 seconds, sometimes as long as 30 minutes. The
consequence of course being that the server goes to a constant 100% CPU
usage, causing services to be denied or be unacceptably slow. During normal
operation (when LSASS is behaving), the server spec is more than enough to
cope with it's workload, and runs at around 20% CPU usage.
There were issues with LSASS.EXE in Win2k, but none that I know of or can
find in Win2k3. This is not a SASSER type worm virus, it's genuine LSASS.EXE.
I'm not even sure if this is the cause of the problem or a symptom of
something else.
Please suggest something, this is a critical production server and this has
now become a serious issue.
Thanks.Could you check in your eventLog and see if there are repeated error
messages , particuarly in Directory Services Log?
--
Jack Vamvas
__________________________________________________________________
Receive free SQL tips - register at www.ciquery.com/sqlserver.htm
SQL Server Performance Audit - check www.ciquery.com/sqlserver_audit.htm
New article by Jack Vamvas - SQL and Markov Chains -
www.ciquery.com/articles/art_04.asp
"The Vogon" <TheVogon@.discussions.microsoft.com> wrote in message
news:0CB0C2E5-4AC5-4F71-B7D7-16180F368002@.microsoft.com...
> I have a web/SQL server (Win2k3sp1, SQL2005) currently experiencing a
serious
> problem.
> Regularly throughout the day, the LSASS.EXE process jumps from <2% CPU
usage
> to 50-70% CPU, sometime for 30 seconds, sometimes as long as 30 minutes.
The
> consequence of course being that the server goes to a constant 100% CPU
> usage, causing services to be denied or be unacceptably slow. During
normal
> operation (when LSASS is behaving), the server spec is more than enough to
> cope with it's workload, and runs at around 20% CPU usage.
> There were issues with LSASS.EXE in Win2k, but none that I know of or can
> find in Win2k3. This is not a SASSER type worm virus, it's genuine
LSASS.EXE.
> I'm not even sure if this is the cause of the problem or a symptom of
> something else.
> Please suggest something, this is a critical production server and this
has
> now become a serious issue.
> Thanks.
>|||Thanks for the reply...
There are no errors regarding this in the log files, no out of the ordinary
errors or warnings are generated. Incidentally, the server is not a Domain
Controller so no DS logs.
"Jack Vamvas" wrote:
> Could you check in your eventLog and see if there are repeated error
> messages , particuarly in Directory Services Log?
> --
> Jack Vamvas
> __________________________________________________________________
> Receive free SQL tips - register at www.ciquery.com/sqlserver.htm
> SQL Server Performance Audit - check www.ciquery.com/sqlserver_audit.htm
> New article by Jack Vamvas - SQL and Markov Chains -
> www.ciquery.com/articles/art_04.asp
> "The Vogon" <TheVogon@.discussions.microsoft.com> wrote in message
> news:0CB0C2E5-4AC5-4F71-B7D7-16180F368002@.microsoft.com...
> > I have a web/SQL server (Win2k3sp1, SQL2005) currently experiencing a
> serious
> > problem.
> >
> > Regularly throughout the day, the LSASS.EXE process jumps from <2% CPU
> usage
> > to 50-70% CPU, sometime for 30 seconds, sometimes as long as 30 minutes.
> The
> > consequence of course being that the server goes to a constant 100% CPU
> > usage, causing services to be denied or be unacceptably slow. During
> normal
> > operation (when LSASS is behaving), the server spec is more than enough to
> > cope with it's workload, and runs at around 20% CPU usage.
> >
> > There were issues with LSASS.EXE in Win2k, but none that I know of or can
> > find in Win2k3. This is not a SASSER type worm virus, it's genuine
> LSASS.EXE.
> > I'm not even sure if this is the cause of the problem or a symptom of
> > something else.
> >
> > Please suggest something, this is a critical production server and this
> has
> > now become a serious issue.
> >
> > Thanks.
> >
> >
>
>

LSASS.EXE high CPU usage

I have a web/SQL server (Win2k3sp1, SQL2005) currently experiencing a seriou
s
problem.
Regularly throughout the day, the LSASS.EXE process jumps from <2% CPU usage
to 50-70% CPU, sometime for 30 seconds, sometimes as long as 30 minutes. The
consequence of course being that the server goes to a constant 100% CPU
usage, causing services to be denied or be unacceptably slow. During normal
operation (when LSASS is behaving), the server spec is more than enough to
cope with it's workload, and runs at around 20% CPU usage.
There were issues with LSASS.EXE in Win2k, but none that I know of or can
find in Win2k3. This is not a SASSER type worm virus, it's genuine LSASS.EXE
.
I'm not even sure if this is the cause of the problem or a symptom of
something else.
Please suggest something, this is a critical production server and this has
now become a serious issue.
Thanks.Could you check in your eventLog and see if there are repeated error
messages , particuarly in Directory Services Log?
Jack Vamvas
________________________________________
__________________________
Receive free SQL tips - register at www.ciquery.com/sqlserver.htm
SQL Server Performance Audit - check www.ciquery.com/sqlserver_audit.htm
New article by Jack Vamvas - SQL and Markov Chains -
www.ciquery.com/articles/art_04.asp
"The Vogon" <TheVogon@.discussions.microsoft.com> wrote in message
news:0CB0C2E5-4AC5-4F71-B7D7-16180F368002@.microsoft.com...
> I have a web/SQL server (Win2k3sp1, SQL2005) currently experiencing a
serious
> problem.
> Regularly throughout the day, the LSASS.EXE process jumps from <2% CPU
usage
> to 50-70% CPU, sometime for 30 seconds, sometimes as long as 30 minutes.
The
> consequence of course being that the server goes to a constant 100% CPU
> usage, causing services to be denied or be unacceptably slow. During
normal
> operation (when LSASS is behaving), the server spec is more than enough to
> cope with it's workload, and runs at around 20% CPU usage.
> There were issues with LSASS.EXE in Win2k, but none that I know of or can
> find in Win2k3. This is not a SASSER type worm virus, it's genuine
LSASS.EXE.
> I'm not even sure if this is the cause of the problem or a symptom of
> something else.
> Please suggest something, this is a critical production server and this
has
> now become a serious issue.
> Thanks.
>|||Thanks for the reply...
There are no errors regarding this in the log files, no out of the ordinary
errors or warnings are generated. Incidentally, the server is not a Domain
Controller so no DS logs.
"Jack Vamvas" wrote:

> Could you check in your eventLog and see if there are repeated error
> messages , particuarly in Directory Services Log?
> --
> Jack Vamvas
> ________________________________________
__________________________
> Receive free SQL tips - register at www.ciquery.com/sqlserver.htm
> SQL Server Performance Audit - check www.ciquery.com/sqlserver_audit.htm
> New article by Jack Vamvas - SQL and Markov Chains -
> www.ciquery.com/articles/art_04.asp
> "The Vogon" <TheVogon@.discussions.microsoft.com> wrote in message
> news:0CB0C2E5-4AC5-4F71-B7D7-16180F368002@.microsoft.com...
> serious
> usage
> The
> normal
> LSASS.EXE.
> has
>
>