locked
System PID4 high CPU usage. Windows Server 2016. RRS feed

  • Question

  • Hello, I have a cluster file server with two nodes, this cluster file server host Citrix roaming profiles, everything was fine until last week when the CPU went up high, 100% an is being taken by System Process PID 4, I see this using WPA

    Line #, Process, Stack, Weight (in view) (ms), Count, TimeStamp (s), % Weight
    11, ,   |    |    |    |    |    ntoskrnl.exe!<Symbols disabled>, 364,063.965943, 360936, , 57.99
    12, ,   |    |    |    |    |    srv2.sys!<Symbols disabled>, 364,063.965943, 360936, , 57.99
    13, ,   |    |    |    |    |    |- srv2.sys!<Symbols disabled>, 358,291.701147, 355215, , 57.07
    14, ,   |    |    |    |    |    |    |- srv2.sys!<Symbols disabled>, 357,793.913281, 354721, , 56.99
    15, ,   |    |    |    |    |    |    |    |- srv2.sys!<Symbols disabled>, 356,594.866577, 353533, , 56.80
    16, ,   |    |    |    |    |    |    |    |    |- srv2.sys!<Symbols disabled>, 289,581.115800, 287103, , 46.12
    17, ,   |    |    |    |    |    |    |    |    |    |- ntoskrnl.exe!<Symbols disabled>, 206,513.343609, 204745, , 32.89
    18, ,   |    |    |    |    |    |    |    |    |    |    |- ntoskrnl.exe!<Symbols disabled>, 206,096.532193, 204332, , 32.83
    19, ,   |    |    |    |    |    |    |    |    |    |    |    |- ntoskrnl.exe!<Symbols disabled>, 205,565.923129, 203806, , 32.74
    20, ,   |    |    |    |    |    |    |    |    |    |    |    |    |- ntoskrnl.exe!<Symbols disabled>, 204,332.549623, 202583, , 32.55
    21, ,   |    |    |    |    |    |    |    |    |    |    |    |    |    |- ntoskrnl.exe!<Symbols disabled>, 200,580.614258, 198863, , 31.95
    22, ,   |    |    |    |    |    |    |    |    |    |    |    |    |    |    |- ntoskrnl.exe!<Symbols disabled>, 199,132.606582, 197427, , 31.72
    23, ,   |    |    |    |    |    |    |    |    |    |    |    |    |    |    |    |- FLTMGR.SYS!<Symbols disabled>, 194,978.876142, 193309, , 31.06
    24, ,   |    |    |    |    |    |    |    |    |    |    |    |    |    |    |    |    |- FLTMGR.SYS!<Symbols disabled>, 192,995.261298, 191340, , 30.74
    25, ,   |    |    |    |    |    |    |    |    |    |    |    |    |    |    |    |    |    |- FLTMGR.SYS!<Symbols disabled>, 137,810.980328, 136635, , 21.95
    26, ,   |    |    |    |    |    |    |    |    |    |    |    |    |    |    |    |    |    |    |- FLTMGR.SYS!<Symbols disabled>, 115,230.467874, 114250, , 18.35
    27, ,   |    |    |    |    |    |    |    |    |    |    |    |    |    |    |    |    |    |    |    |- fileinfo.sys!<Symbols disabled>, 88,815.719738, 88059, , 14.15

    This is causing all users to have really slow VDIs. 

    I have disable the AV and nothing has changed. If I failover to the passive node the system process will raise too. I am not sure what could be causing this, any ideas?

    Thank you.

    Wednesday, July 24, 2019 2:33 PM