Saturday, January 29, 2011

I'm running out of disk space on my Exchange 2007 server, what are my short term options?

The volume that has the Exchange 2007 databases on has less than 10GB left out of 250GB. I can't move over to another server just yet and there is no spare capacity in the server for additional disks.

Do I have any short term options I can run without much disruption? Compact the database maybe? Any powershell commands to magically shrink the db? Thanks

PS I've already set some policies to clean up old mail but these don't appear to have made any difference.

Thanks S

  • First I would check is that you regurlarly do Exchange backups, as this will flush out your transaction logs, freeing valuable space.

    Apart from that, as long as your Exchange database is running database maintenance regularly, it will free up space itself.

    You can also use the export-mailbox cmdlet to copy parts of user's mailboxes (say, items older than two years for instance) to pst files. I wouldn't do this without some end user communication first, though.

    joeqwerty : @Trondh: Your comments regarding the Exchange maintenence process and regarding exporting users mailboxes to pst file are incorrect. These operations, while removing items from the database, do not reduce the size of the physical file. In order to reduce the size of the physical file and reclaim the disk space, you need to perform an offline defrag of the database using the ESEUTIL utility.
    From Trondh
  • Our run after the basics already outlined is to identify the biggest mail users and have them export their old email to a .pst archive...usually there's a small number of users taking up a huge amount of space. Seems to help with buying time.

    joeqwerty : @Bart: See my comment to Trondh's answer. Exporting to pst files does not reduce the size of the physical file, so at the end of the day you're left with a database file with lots of whitespace and a physical file that hasn't changed in size. To reduce the size of the physical file, you need to perform an offline defrag of the database with eseutil.
    Bart Silverstrim : @joeqwerty: you're saying it's a two-step process then...so I was giving half-good advice? :-)
    Graeme Donaldson : Anything involving pst files is unlikely to be good :-)
    Bart Silverstrim : @Graeme:See, my personal preference says that anything involving Exchange is unlikely to be good in many cases :-)
    Graeme Donaldson : It's a complex beast, there's no denying it. But there's still no viable alternative after all these years.
    Bart Silverstrim : @Graeme: for what it is, it's good enough. But I'd still say there are viable alternatives, depending on how users are actually using the platform (for example, our organization is using it just for email. I personally think it's overkill to run Exchange JUST for email...) This isn't the forum to get into that though. If you need calendar, notes, addressbook, domain integration, email, integration with Windows services...yeah, exchange is great.
  • Short term, get an external SCSI enclosure that is 500GB+ with your preferred disk setup and move your databases there.

    From Dan
  • It's doubtful that the database is taking up all that much disk space. What's the size of the edb file(s)? It's more likely that you have a large number of transaction logs that haven't been flushed. My recommendation would be to perform a full backup of Exchange using an Exchange aware backup program that can flush the transaction logs after the backup completes.

    Bart Silverstrim : Forgot about logs. We've been bitten more than once by space issues and having gigs of transaction log txt files left on a partition. Deleting them freed up huge amounts of space.
    Evan Anderson : ACK! You don't *EVER* delete Exchange transaction logs. You perform a full backup and allow the engine to flush them itself!
    joeqwerty : I'm with Evan on this, deleting the logs is only asking for trouble. Perform a full Exchange aware backup as suggested and let the backup flush the logs.
    Bart Silverstrim : I wasn't in charge of the exchange server in question, but out of curiosity, was something keeping them open or still using them?
    joeqwerty : The transaction logs are never flushed\purged unless an Exchange aware backup is performed with the flush logs option enabled, or a full backup of the Information Store is performed by an Exchange aware backup program (or you have circular logging enabled). Here's some good info from the MS Exchange Team regarding the transaction logs: http://msexchangeteam.com/archive/2004/05/12/130556.aspx
    Steven : The logs are not taking up much space, the logs are removed by our backup program. The space is mostly the databases, guess I'll have to move the databases double quick!
    Bart Silverstrim : @joeqwerty: if I'm understanding your link correctly, it's okay to delete the transaction logs as long as you leave the last few in the system for recovery and consistency. I think that's what our site had done...deleted logfiles older than, say, a month, then restart. Am I mistaken in that understanding?
    joeqwerty : @Bart: Yes, you're slightly mistaken. While I never recommend deleting the log files, if you absolutely need to you can but you can't just pick some random log files based on the timestamp. You need to make sure the logs you delete have been commited to the database. The article I posted a link to details how to determine this.
    From joeqwerty
  • There are no "magical" commands to shrink the database. The database file (EDB) will only shrink if you perform an offline degfragmentation, and even then it won't shrink unless the database had white-space (free space) in the file to begin with.

    Assuming you are doing backups with an Exchange-aware backup, your database doesn't have any significant quantity of white space in it, and the database file really is approaching 250GB, there's not a lot that you can do other than add storage or get users to delete a sufficient quantity of items (and perform a backup so that those items are actually flushed from the store) in order to create white space in the database file to arrest the growth of the database file. (You can find your white space by looking for event ID 1221 in your Application Log, from event source "MSExchangeIS Mailbox Store").

    My guess lies with the other posters' answers, though. You're probably building up database transaction logs (do you see many, many gigabytes of ".LOG" files in your Exchange database directory-- \Program Files\Microsoft\Exchange Server\Mailbox, by default) and you're not doing proper backups. If you're not using an Exchange aware backup you're likely not going to be able to recover your server in the event of a fault condition, and you're going to have disk space exhaustion like you're seeing.

    (It is theoretically possible to enable circular logging for a storage group and stop transaction log growth, as well, but you're sacraficing recovery capabilities if you do that.)

Not able to load msnbc.com. Weird timeouts. Is my router to blame?

And everything has been taking a long time to connect the past couple days. Wireless is working for msnbc.com and other site just fine though.

Below is what a log for tracert for www.msnbc.com. Any clues in it?

Tracing route to msnbc.com [207.46.245.60]
over a maximum of 30 hops:

  1    <1 ms    <1 ms    <1 ms  192.168.0.1
  2   165 ms    43 ms    43 ms  eugn-dsl-gw08-200.eugn.qwest.net [67.42.192.200]

  3   217 ms   229 ms   192 ms  eugn-agw1.inet.qwest.net [67.42.193.57]
  4    90 ms    92 ms    97 ms  eug-core-01.inet.qwest.net [205.171.150.57]
  5   123 ms   124 ms   127 ms  sea-core-02.inet.qwest.net [67.14.1.198]
  6   143 ms   141 ms    49 ms  sea-edge-01.inet.qwest.net [205.171.26.134]
  7   139 ms    51 ms    49 ms  65.116.65.166
  8   190 ms    63 ms    50 ms  ge-0-3-0-54.wst-64cb-1a.ntwk.msn.net [207.46.46.
33]
  9   132 ms    50 ms    49 ms  ge-0-2-0-0.tuk-64cb-1b.ntwk.msn.net [207.46.47.7
0]
 10    88 ms     *      301 ms  ten2-4.tuk-76c-1b.ntwk.msn.net [207.46.46.23]
 11     *        *        *     Request timed out.
 12     *        *        *     Request timed out.
 13     *        *        *     Request timed out.
 14     *        *        *     Request timed out.
 15     *        *        *     Request timed out.
 16     *        *        *     Request timed out.
 17     *        *        *     Request timed out.
 18     *        *        *     Request timed out.
 19     *        *        *     Request timed out.
 20     *        *        *     Request timed out.
 21     *        *        *     Request timed out.
 22     *        *        *     Request timed out.
 23     *        *        *     Request timed out.
 24     *        *        *     Request timed out.
 25

not sure on how to make this look good on here. Blockquote tags did not help.

Here is the tracert for the wireless connection, coming from the same router (different computer though)

Tracing route to msnbc.com [207.46.150.20] over a maximum of 30 hops:

1     1 ms     4 ms     2 ms  qwestmodem.domain.actdsltmp [192.168.0.1]
2   185 ms   207 ms   178 ms  eugn-dsl-gw08-200.eugn.qwest.net [67.42.192.200]

3   169 ms   191 ms   226 ms  eugn-agw1.inet.qwest.net [67.42.193.57]
4    44 ms    52 ms    48 ms  eug-core-01.inet.qwest.net [205.171.150.57]
5    87 ms    86 ms    92 ms  sea-core-02.inet.qwest.net [67.14.1.198]
6    55 ms    51 ms    49 ms  sea-edge-01.inet.qwest.net [205.171.26.134]
7   110 ms   115 ms    51 ms  65.116.65.166
8   204 ms   196 ms    85 ms  ge-0-3-0-54.wst-64cb-1a.ntwk.msn.net [207.46.46.33]
9   131 ms    51 ms    51 ms  ge-1-0-0-0.cpk-64c-1a.ntwk.msn.net [207.46.43.218]
10    90 ms    58 ms    49 ms  ten3-4.cpk-76c-1b.ntwk.msn.net [207.46.47.193]
11    82 ms    54 ms    50 ms  10.22.0.14
12     *     10.22.0.10  reports: Destination net unreachable.
  • First, it could be a problem with the LAN side network port on the modem. Get a replacement unit in from your ISP and see if that helps.

    However, it's worth noting that I had a very similar problem on a business class DSL line that involved not being able to access MSNBC.com, Microsoft.com and a few other sites. I ended up calling my ISP and got an interesting tip: switch my DSL modem from PPPoE to PPPoA. They had very similar problems with some other businesses in the city and that "fixed" it. My contact wasn't a technical person so I wasn't able to get any specific reason as to why that changed things for the better. I know it sounds weird... but that's because it is. =) You might want to give that a try if the modem and your ISP network supports it.

    bobber205 : Does this explain why wirless works with no issues? I have a tomato firmware router plugged into the modem/router that my ISP gave me and the wireless for that Tomato/Linksys router can get to msnbc fine. This just started happening last night.
    Gerald Combs : Switching from PPPoE to PPPoA gives you a "normal" 1500-byte MTU. This can often avoid path MTU problems.
    Wesley 'Nonapeptide' : @bobber: now that I understand that the wireless is not a function of the modem itself, that indeed does change things. Probably neither of my suggestions are relevant now.
    Wesley 'Nonapeptide' : @Gerald Combs: Thanks for that tip! Any documentation that you're aware of that could school me further in this topic?
    bobber205 : Both my modem and my linksys router have wireless.
    Wesley 'Nonapeptide' : But you're not using the modem's wireless, correct?
    bobber205 : I was. The modem's wireless was able to get to the site just fine. The ethernet was not.
    Wesley 'Nonapeptide' : Hrm. Oh well. No worries now since it seems Zypher has nailed the problem.
  • MSNBC has DNS round robbin setup, your wireless computer is getting a different response than your non wireless computer. It appears that a router between you and the edge router that services the 207.46.245.60 Address is having issues. while there are no issues with the path to the 207.46.150.20 network. I would try specifying those ips manually in a traceroute and not relying on DNS, if you get the same results - .60 un available - then you'll just have to wait it out.

    bobber205 : I just tried plugging my cord for the computer having problems into the linksys/tomato router and it works. Pretty sweet. :)
    From Zypher

WSUS not working on clients - deployed via GPO

I've deployed WSUS on a server called INet This has downloaded the required updates that I selected.

I've configured automatic updates in the GPO - Set the following:

  • Allow Automatic Updates immediate installation
  • Allow non-administrators to receive update notifications

  • Specify intranet Microsoft update service location: (I set this to http://INet)

I also set the time to check for updates to 4pm (for testing)

I linked the GPO in the relevant OU, then signed on to a test computer (windows xp pro) Logged in, checked the Update tab in My Computer, and it was grayed out, with 4pm set as the update time (so i know the GPO had worked)

4pm came and went, but no updates.... Checked on INet server in the WSUS console, still showed 0 computers...

What have I missed?

**

Edit / Update

**

I've now run "wuauclt /detectnow" and it has put some errors in the error log

Failed to find updates with error code 80244019

I also notice the url it is searching for is: http://INet/ClientWebService/client.asmx

When i try this URL in IE from the client, I get a 404. on looking on IIS on INet - i see the folder, but it is emtpy..

  • The %SystemRoot%\WindowsUpdate.log file is your friend. Assuming the "Automated Updates" service is started, you'll see the diagnostic output from the process there.

    That's all I can really say w/o knowing more detail.

    alex : I've had a look through.. and theres nothing 5 mins either side of 4pm... so it looks like it didn't even try it?
    Evan Anderson : Polsy is correct in his statement that the time (4PM, in your case) is when the updates are *installed*, not when they're detected. Detection can happen at any time, and is on a once per 22 hours schedule, by default, just like he says.
    Evan Anderson : What else are you seeing in that file, though? Is it contacting your intranet update server at all? Are you seeing any errors?
    Izzy : The worlds most verbose, and unreadable log. Ever :)
    alex : Ok, now when i run that cmd, i see in the error log... amongst other things... 0x80244019
    Polsy : http://inetexplorer.mvps.org/archive/wuc.htm has been (sometimes) useful to me for diagonising Windows Update things. Apparently that one represents a 404 error, so possibly something's up with the web server end. I'm not sure where to look to help with that, though.
  • The time in the Automatic Updates configuration is the time when downloaded updates are installed, the check will stay on its usual schedule (see Automatic Updates detection frequency, default every 22 hours). Running 'wuauclt /detectnow' will trigger an immediate detection.

    Evan Anderson : I don't have documentation handy that says so, but I had a recollection that detection would be triggered immediately if the update source changed.
    From Polsy
  • Ok, I figured it out...

    WSUS was installed on port 8530 for some reason... this may be the default port? By changing my url in the GPO to http://INet:8530 it then worked. I ran the wuauclt /detectnow command, and checked the error log.

    There were a bunch of errors about Windows Installer 3.1 - then a balloon popped up, saying updates were ready etc.. I presume one of these updates will be the required Windows Installer 3.1

    Evan Anderson : You have a choice during installation to install to a dedicated site, which defaults to port 8530. (Now I'm kicking myself that I didn't mention in my answer checking to see that you didn't install on a site running on port 8530... Grr...)
    Chris Thorpe : Yep, latest version of windows installer, bits etc are the first patches that will be installed before any others will be attempted.
    alex : I take it I'm not "missing out on any goodies" by installing it as it is? I mean... if i want to change it at some later date, all I need to do is alter my GPO? is that right? Thanks for your help Evan... I wouldn't of looked in the log otherwise!
    From alex

Corrupted zip file after using split and cat on Linux

Hello everyone,

I had to split this 2.6 GB zip-file in order to send it thru a slow uplink. I did this:

split -b 879m BIGFILE.zip

This created xaa, xab & xac which I uploaded to the remote server. After the transfer finished I verified each one of these 3 pieces with md5sum (both on my local system and on the server):

md5sum xaa
md5sum xab
md5sum xab

All of the 3 hashes were identical to that of the 3 ones on my system so the transfer went well. Now, on the remote system, when I do this:

cat xa* > BIGFILE.zip

...then I verify the hash of this BIGFILE.zip (on both systems):

md5sum BIGFILE.zip

...and both of them match.

Now comes the interesting part. When I try to list the contents of the zip file I get an error:

unzip -l BIGFILE.zip

I get:

Archive:  BIGFILE.zip
  End-of-central-directory signature not found.  Either this file is not
  a zipfile, or it constitutes one disk of a multi-part archive.  In the
  latter case the central directory and zipfile comment will be found on
  the last disk(s) of this archive.
unzip:  cannot find zipfile directory in one of BIGFILE.zip or
        BIGFILE.zip.zip, and cannot find BIGFILE.zip.ZIP, period.

This is totally weird. I'm using the same version of "unzip" on both systems. When I use the "unzip -l" on my local system it works.

Thanks for any help. JFA

  • You should have used rsync instead. split is gheeetto. That said I have no idea what's wrong with your problem. Oh .. wait ... you can use rsync now. It will only transfer the difference between the files. Assuming you have ssh access on the remote machine:

    rsync -Pvz BIGFILE.zip remotehostname:/path/to/BIGFILE.zip
    

    ... and you're done.

    Dennis Williamson : The checksums indicate that the file was transmitted completely and correctly.
    From niXar
  • How did you transfer file files? If you did it via FTP ASCII mode will hose the files. You may be able to use the -F flag of unzip to correct this but don't bet on it.

    You may need to retransmit the files-I'd recommend doing it via scp

    Dennis Williamson : If the files got mangled during transmission then the checksums wouldn't match.
    From Josh Budde
  • Identical MD5 hashes suggest that the transfer has worked well.

    More than 2G filesize sounds suspiciously like some pointer size issue - maybe the zip in question doesn't handle that well? more than (ca) 2G would be a negative number in 32 bit... Can you unzip the file on the system where you zipped it? Do both systems differ? Is one 64bit, the problematic 32 bit? What are the filesystems on both systems? Can you find another zip utility?

    If you have a chance to retransmit the content, you might want to use tar.gz or keep file size lower than that value. gzip compressed content should handle this better. Zip stores the contents (index) at the end of the file.

    Edit: Yup, see here:

    In practice, the real limit may be 2 GB on many systems, due to UnZip's use of the fseek() function to jump around within an archive. Because's fseek's offset argument is usually a signed long integer, on 32-bit systems UnZip will not find any file that is more than 2 GB from the beginning of the archive [...]

    Dennis Williamson : +1 Brilliant. Great thinking!
    From Olaf

Windows networked printers freeze on PDF

I have two HP LaserJet printers on a Windows Server 2003-based network. Both printers are managed by a print server and shared from there to multiple users in the domain, most of whom use Windows XP. They usually work fine. Every now and then, somebody sends a document to the printer and it "locks up" on the print queue. The document shows up on the print queue applet but is never actually printed. No error message appears and no event is looged in the server. The problem affect both printers. The only way we have found to solve this is to restart the spooler service on the server.

Some clues. In every occasion that we have observed this, the involved document was a PDF. Also, the problem seems to happen randomly, but especially early in the morning, so we suspect that it may be related to the printing waking up from power saving mode. We have been unsuccessful to reproduce the problem. We have even waited for the printer to go to power-saving mode and sent a PDF that was known to have caused a lock up in a previous occasion; the PDF printed perfectly.

I have done some research and there seems to be people talking about a possible issue with HP LaserJet drivers on Windows Server 2003, but no specific details or resolution was available.

Basically, we have no clue what might be going on. Any ideas? Thanks.

Update 9-Dec-09. We have opened a technical support ticket with HP. They don't seem to have a readily available fix to the problem.

Update 13-Jan-10. We have installed HP Easy Printer Care on the print server as advised by HP support. Don't ask me why, but the issues seems to have disappeared!

  • It's almost always a print driver issue. Experiment with different print drivers to get the desired results. On some printers (with regard to pdfs) we have to use the PCL6 driver and on others the PCL5 drivers.

    Ward : If he is using PCL drivers, maybe Postscript would work better?
    CesarGon : Thanks GregD and Ward. I will experiment with PCL5 and PS drivers.
    From GregD
  • Have you considered that the problem might be network related? Have you tried to see what kind of traffic is actually getting to the printer? What does the printer's logs (not the print server's logs) indicate is happening at the time that the event takes place?

    I've seen this happen several times, but in every case I've experienced it, the only fix has been troubleshooting network connectivity. One time I replaced the printer's network cable, and I've not had a problem with that one in over a year. Several others were attached to consumer-grade Linksys 5-port switches, and replacing the immediately upstream switch took care of it. A few cases have been mal-functioning JetDirect cards.

    That's just one area to look at. I've had many driver issues with PDFs and Canon copiers/printers, but so far (and I've probably just jinxed myself), I haven't seen this particular problem with HP's drivers.

    From Stemen

Anonymous FTP upload on CentOS 5.2

I need to allow users to upload files to an FTP server anonymously. They should not be able to see any other files, or download files. It is a CentOS 5.2 server. I have a separate partition for the the upload area (mounted at /ftp).

I have tried to set up vsftpd, followed all the instructions/advice I could find. But, when a user logs in and tries to transfer a file it throws a "553 could not create file." error. If I do a 'pwd' it shows the directory as "/" rather than the anon_root of "/ftp/anonymous". Any attempt to change the remote directory ends with "550 Failed to change directory.". I have a subdirectory "/ftp/anonymous/incoming" that is writable for the uploads

SELinux is in permissive mode.

I am running version 2.0.5 release 16.el5 of vsftpd.

Here is the vsftpd.conf file:

anonymous_enable=YES  
local_enable=YES  
write_enable=YES  
local_umask=002  
anon_umask=007  
file_open_mode=0666  
anon_upload_enable=YES  
anon_mkdir_write_enable=NO  
dirmessage_enable=YES  
xferlog_enable=YES  
connect_from_port_20=YES  
chown_uploads=YES  
chown_username=inftpadm  
xferlog_std_format=YES  
nopriv_user=nobody  
listen=YES  
pam_service_name=vsftpd  
userlist_enable=YES  
tcp_wrappers=YES  
ftp_username=inftpadm  
anon_root=/ftp/anonymous  
anon_other_write_enable=NO  
anon_mkdir_write_enable=NO  
anon_world_readable_only=NO  
dirlist_enable=YES  

Can anyone help?

  • I know it's a basic question, but did you check directory ownership and permissions? If so, could you show them with an "ls -al"?

    Craig : drwxr-xr-x 4 root root 4096 Nov 30 13:34 /ftp drwxr-xr-x 3 root root 4096 Nov 30 15:52 /ftp/anonymous/ drwxrwxrwx 2 root root 4096 Dec 1 14:48 /ftp/anonymous/incoming/
    Brian : Just to be thorough, did you run "getenforce" and ensure that SELinux is definitely in permissive mode currently (vs say set to permissive for the next reboot). Also ensure that there isn't already a file in the directory with that name because based on the vsftpd.conf settings above anonymous would not be able to upload over an existing file.
    Craig : It's definately in permissive mode. And, I don't want anonymous to overwrite files. The directory is currently empty.
    From Brian
  • The configuration file is pretty straightforward. Here's where you're going wrong:

    anon_mkdir_write_enable=NO  
    listen=YES   
    anon_other_write_enable=NO  
    anon_mkdir_write_enable=NO 

    You have an entry duplicated (which shouldn't be a big deal), and you have anon_other_write_enable set to NO. Also, if you're going to use the second line, make sure you have the service disabled in inetd/xinetd.

    After changing the SELinux context you also need to reboot to relabel the file system. Run sestatus to see the current context.

    From RHELAdmin

Cheapest hosting company that would give me lots of IPs

Any recommendation on hosting company that would give me lots of ips(/22,/23,/24,/25,/26) with a dedicated server and chopped it up into vps for me?

  • A /22 is a lot of IPv4 space. You're not going to find many/any that will give you that large an allocation. You'll probably have to go to your local internet registry (like APNIC) and justify/order your own range. From there you can try and find a host that will advertise it for you.

    MarkM : it depends on if he wants the /22 in private or public IPs
    womble : So *that's* what all those hosting providers offering a "free /8 of IP space" were up to...
    From rodjek
  • Any hosting company should be willing to give you a /22 of space, as long as you can justify it. I'll place a smallish wager that you won't be able to justify that much space, though.

    : please read my post carefully, any range from /26 up to /22... not /22 specifically..
    womble : Please feel free to substitute /22 for any other range you like; my answer is all purpose like that.
    From womble
  • /22 is a gigantic amount of IP space. I find it hard to believe that anyone who could justify that much IP space from a hosting company would ask where to go on ServerFault. But, if you can justify and pay for it, just find a host that has it for you and they should be willing to give it.

    The hosting company I work for (Rackspace) does /26 blocks all the time for clients.

    As far as the server, many hosts, including the one I work for, support virtualization for their clients...but I'm not sure you'd want to host a /22 worth of VMs on a single dedicated box. You're talking about 1022 hosts or so. For a /26, it's a bit more reasonable. Either way, our virtualization team supports all kind of client configs, and I'm sure most other higher-end hosting companies do as well.

    If you want to be raising huge numbers of VPSes, you might want to look in to a product like Rackspace Cloud Servers or Amazon EC-2.

    : I believe it's 1024.... not 65,534....
    phoebus : You're right I had a brain fart...1022 hosts.
    From phoebus
  • No matter how many public IPs you want you'll have to justify to the CoLo, who forwards the justification on to ICANN that you need that many IPs. That's anywhere from 5 IPs on up.

    From mrdenny
  • Our current hoster NTT Europe Online gave us /24 public range without asking for any justification. We had to chop it up to VPSes ourselves though because they don't know anything except vmware, and they are not cheap, their managed hosting costs 4 times more that Rackspace's.

    We did not really need that many IPs, its just how they do things, all IPs are public. I can not imagine any legitimate need for that many IPs except you are planning to be an ISP yourself, but in that case it is better to get a real colo and arrange the links and ranges yourself, otherwise I don't believe you can be competitive enough to survive.