The health monitoring process that is part of failover clustering has detected that system responsiveness has slowed. If you do not currently have Event Viewer open, see "Opening Event Viewer and viewing events related to failover clustering." Using the information from the event, review the applications and services running on the node to discover which process is draining resources or otherwise slowing down the node. You can use one or more of the following methods:
To perform the following procedures, you must be a member of the local Administrators group on each clustered server, or you must have been delegated the equivalent authority.
To use Task Manager to work with applications or services consuming large amounts of memory:
To generate a System Diagnostics Report:
To start Resource Monitor:
Important Resource Monitor stops collecting information while a System Diagnostics Report is being generated. To start collecting information after a System Diagnostics Report has completed, in Monitor, click Start.
To open Event Viewer and view events related to failover clustering:
Target | Microsoft.Windows.2008.Cluster.Monitoring.Service | ||
Category | Alert | ||
Enabled | True | ||
Alert Generate | True | ||
Alert Severity | Error | ||
Alert Priority | Normal | ||
Remotable | True | ||
Alert Message |
|
ID | Module Type | TypeId | RunAs |
---|---|---|---|
DS | DataSource | Microsoft.Windows.2008.Cluster.EventProvider | Default |
WA | WriteAction | Microsoft.Windows.Cluster.GenerateAlertAction.SuppressedByDescription | Default |
<Rule ID="Microsoft.Windows.2008.Cluster.Management.Monitoring.User.mode.health.monitoring.has.detected.that.the.system.is.not.being.responsive" Enabled="onEssentialMonitoring" Target="Clus2008Library!Microsoft.Windows.2008.Cluster.Monitoring.Service" ConfirmDelivery="true" Remotable="true" Priority="Normal" DiscardLevel="100">
<Category>Alert</Category>
<DataSources>
<DataSource ID="DS" TypeID="Microsoft.Windows.2008.Cluster.EventProvider">
<Criteria>
<RegExExpression>
<ValueExpression>
<XPathQuery>EventDisplayNumber</XPathQuery>
</ValueExpression>
<Operator>MatchesRegularExpression</Operator>
<Pattern>^(4870|4869)$</Pattern>
</RegExExpression>
</Criteria>
<LogName>System</LogName>
<PublisherName>Microsoft-Windows-FailoverClustering</PublisherName>
</DataSource>
</DataSources>
<WriteActions>
<WriteAction ID="WA" TypeID="ClusLibrary!Microsoft.Windows.Cluster.GenerateAlertAction.SuppressedByDescription">
<Priority>1</Priority>
<Severity>2</Severity>
<AlertMessageId>$MPElement[Name="Microsoft.Windows.2008.Cluster.Management.Monitoring.User.mode.health.monitoring.has.detected.that.the.system.is.not.being.responsive.AlertMessage"]$</AlertMessageId>
</WriteAction>
</WriteActions>
</Rule>