DistributedBen
Limp Gawd
- Joined
- Mar 26, 2004
- Messages
- 227
For a few weeks I have been trying to track down the reasons for our primary file server running low on storage at an unusually high rate. Many times it has gone below 1GB of free space. At first I figured it was due to large project files being saved to the server.
However, this week I'm thinking it is something else. While I was gone on Tuesday the 6th - the server parition with the files filled up. This also caused other services running on that parition - mainly Exchange '03 to shut down.
When I left work the day before we had almost 1.5GB free. I had twice that free the previous Friday. I asked around to see if anyone had dumped files on the server - nope.
After tracking the storage growth for the home directories over a few days, they never grew by more than a hundred or so MBs during this week. But I was still running out of space - down to less than 400MB yesterday at lunch.
There are other folders on the partition but they are non shared or only I have access. I saw no change in their sizes. The Exchange folder (with the db) was holding steady at 8GB which is normal.
After everyone went home yesterday I decided to take a closer look. Much to my suprise I now had 23GB free. How the %$@ did that happen? In less than 5 hours and during the workday 23GB of space had been freed up.
I paniced, thinking the worse that if it was a security issue, they may have deleted a company data. After all, I knew we were low on space, but I didn't know how big a gap there was between our files and what was taking up all that room. Luckily, I checked and the home directories don't apear to have been touched and Exchange is running as usual. In fact, I have no idea where the free space came from anymore that I knew what was taking up all the space.
I figure that an outside source was using the server to route junk mail or possible a file server for files. But I haven't (yet) found any services that shouldn't be running. There never seemed to be a processor or memory drain on the server, just disappearing space. I hadn't had time to change anything either, it just all came back.
So today, I'm scanning the logs/server, etc to see if there is anything out of the ordinary. One thing that has aleady caught my eye are repititive and successful login attempts from a remote location to one of our employee accounts during the early morning hours.
Unfortunatly this server does everything (AD/DNS, Exchange w/ WebAccess, File/Print). I need to get Exchange and OWA off this box.
Any ideas and suggestions on how to go about this? The confusing part is that it just stopped. I ran filemon and nothing out of the ordinary came up last night. I will compare it to the previous nights capture.
However, this week I'm thinking it is something else. While I was gone on Tuesday the 6th - the server parition with the files filled up. This also caused other services running on that parition - mainly Exchange '03 to shut down.
When I left work the day before we had almost 1.5GB free. I had twice that free the previous Friday. I asked around to see if anyone had dumped files on the server - nope.
After tracking the storage growth for the home directories over a few days, they never grew by more than a hundred or so MBs during this week. But I was still running out of space - down to less than 400MB yesterday at lunch.
There are other folders on the partition but they are non shared or only I have access. I saw no change in their sizes. The Exchange folder (with the db) was holding steady at 8GB which is normal.
After everyone went home yesterday I decided to take a closer look. Much to my suprise I now had 23GB free. How the %$@ did that happen? In less than 5 hours and during the workday 23GB of space had been freed up.
I paniced, thinking the worse that if it was a security issue, they may have deleted a company data. After all, I knew we were low on space, but I didn't know how big a gap there was between our files and what was taking up all that room. Luckily, I checked and the home directories don't apear to have been touched and Exchange is running as usual. In fact, I have no idea where the free space came from anymore that I knew what was taking up all the space.
I figure that an outside source was using the server to route junk mail or possible a file server for files. But I haven't (yet) found any services that shouldn't be running. There never seemed to be a processor or memory drain on the server, just disappearing space. I hadn't had time to change anything either, it just all came back.
So today, I'm scanning the logs/server, etc to see if there is anything out of the ordinary. One thing that has aleady caught my eye are repititive and successful login attempts from a remote location to one of our employee accounts during the early morning hours.
Unfortunatly this server does everything (AD/DNS, Exchange w/ WebAccess, File/Print). I need to get Exchange and OWA off this box.
Any ideas and suggestions on how to go about this? The confusing part is that it just stopped. I ran filemon and nothing out of the ordinary came up last night. I will compare it to the previous nights capture.