Hello,
Yesterday at around 1pm GMT, Forefront on our Exchange 2010 servers tried to download updates for multiple engines. The download failed for all engines on some servers and for some engines on other servers. Immediately after that, the CPU utilisation by the scheduled/real-time FF processes brought CPU utilisation on these servers to 100%. That caused client problems, delays in Outlook, messages stuck in Outbox and/or Sent Items. So we had to disable FF hub and real-time scanning to return CPU utilisation to normal.
Our servers all have the same configuration: they host the CAS, HT and Mailbox roles in an 8-server DAG. 4 servers with active copies, 4 servers with passive copies.
On servers where we don't have active copies of the DAG database, the download succeeded and no effects on CPU utilisation.
Nothing obvious in the event viewer.
Any ideas please? Fortunately, FF isn't our own protection.
Thanks,
- Alan.