After patching multiple environments that belong to our customers we have have experienced some problems with the CAB file logs in C:\windows\logs\CBS increases in size to about 2-3 GB. This causes cabxxxxxx files to be auto generated in C.\windows\temp. This keeps on going until the disk goes full. This happens only on 2008 R2 servers.
I have a workaround that fixes this, but i want to find a fix that stops this completely. Has anyone experienced this or have any tips?
Edit:
Thanks all. Tho we dont know the root problem yet i have created a analysis that should root out the problem. I am also thinking og creating a task policy which will automatically fix it.
I am running this relevance code. If someone has some tips on making it better i would be happy to get them.
(sum of sizes of files of folder “c:\windows\logs\cbs” > 15000000000 or free space of drive “C:” < 5000000000 and exists file whose (name of it contains “cab”) of folder “C:\windows\temp”)
The cab files are created to archive log files in C:\windows\logs\CBS folder. There is usually a .log file in the same folder, you may want to open it up and see what logs are filling it up.
Once the \windows\logs\cbs\cbs.log reaches 2 GB or so, the makecab command that Microsoft uses to periodically archive the file fails. Repeatedly. And every time it fails, it adds its incomplete archive to \windows\temp.
Only resolution I’ve seen is to delete the cbs.log.
I don’t know whether the cause is a particular patch, or whether it’s an accumulation of running many in quick succession that increases the cbs.log size beyond the threshold that makecab can handle, but I’ve been able to reproduce the makecab failure on arbitrary files of sufficient size.
…and I’ve seen this on Windows 7 Enterprise x64 as well as 2008 R2.
I will probably and eventually be posting a full TechNote on this Microsoft Issue. Would be nice to have a fixlet to detect on and remediate condition.
Yes , this is confirmed to be a Microsoft problem outside of BigFix. The only thing one can do is to detect and remediate against it. I am working on a TechNote for it.
Thanks for the update. I have a task to clean this up that I’ll try to post later in the week.
I would note though, that I’ve seen this on systems that are airgapped and have no access to Windows Update, so I’m pretty sure that the causes are not limited to “two patches running at the same time”.