Exchange 2010 Health Check Script

A few years ago when I was leading my first Exchange team, one of the very first lessons I learned was that everyone has a different idea for how to validate a change. When I started my IT career, I was taught after any change you reboot, and when the system comes back up you check the event logs, services, and any relevant application logs to make sure everything is running as expected. However, as I found out after delegating a patching change to a subordinate, everyone didn’t learn that same lesson. Hence, the Exchange 2010 Health Check script.

Start PowerShell to run the Exchange 2010 Health Check script
Server restart – friend or foe?

The Change

During that change window, three out of four mailbox servers didn’t start their Mail Submission service. This was on a weekend of course, and IIRC no one really noticed until Sunday evening. Once I got the call though, I knew exactly what the issue was. I remoted in to the network as soon as I could, started the Mail Submission services, and dreaded going to work the next morning.

The Aftermath

That night I thought about the two questions that were going to come my way the next morning- how did this happen, and how do we prevent it in the future? The first question is relatively easy. Sometimes, for some reason, Exchange services just don’t want to start after a reboot. This is something of a cop-out of course, but I’ve seen this service hang at reboot in most of the environments I’ve worked on. The other question of how we prevent this in the future, was going to take a bit of work.

The Solution

Training is of course the simple answer, but that isn’t the answer that I would want to hear. Especially after an outage of that magnitude.

The solution I came up with was the following Exchange 2010 Health Check Script. This script was to be run against any Exchange 2010 server post-change, and would gather the following server stats and perform the relevant tests:

  • All Servers
    • Status of Services set to startup automatically
    • All of the Error and Warning logs in the last 100 Application log entries
    • All of the Error and Warning logs in the last 100 System log entries
  • For CASes
    • All active connections to all services (based off this function)
    • Test POP connectivity
    • Test IMAP connectivity
    • Test OWA connectivity
    • Test EWS connectivity
  • For Hub Transports
    • Test SMTP connectivity
    • Report on messages in queue
  • For Mailbox Servers
    • Test DAG health
    • Report on the mailbox database copy statuses
    • Test MAPI connectivity
    • Test mailflow

In situations where we had multi-role servers, namely CAS/HTs, the script would run the tests and generate reports for each role. And once run, the admin will be prompted to email the Messaging team’s distribution group so everyone can have eyes on the results.

#################################################################
# Exchange 2010 Health Check Script                             #
# This script generates an Exchange Server health check report  #
# And can email it to a specified recipient			#
#								#
# Created by Eric Kukkuck 3/3/2015				#
# https://MSExchangeHelp.com					#
#################################################################

$OrgName = "MyCo"
$TranscriptPath = "D:\ABZ\Reports\E2010HealthCheck_" + (Get-Date -f yyyy-MM-dd_HH-mm) + ".txt"

$POPEnabled = "$False"
$IMAPEnabled = "$True"

$SMTPServer = "smtp.domain.intranet"
$SMTPSender = "postmaster@domain.net"
$SMTPRecipient = "MessagingTeamDG@domain.net"

start-transcript -Path $TranscriptPath

    Write-Host ""
write-host "Welcome to the $OrgName Exchange Server Health Check script. This script is to be run upon completion of any changes made to an Exchange sever and the results emailed to $SMTPRecipient." -foregroundcolor "green"

    write-host ""
Write-Host "Enter server name to validate:" -ForegroundColor "Yellow"

    write-host ""
$Server = Read-Host

    write-host ""
$ServerRole = get-ExchangeServer $Server | Select ServerRole

function Get-CASActiveUsers {
  [CmdletBinding()]
    param(
    [Parameter(Position=1, ParameterSetName="Value", Mandatory=$true)]
    [String[]]$ComputerName,
    [Parameter(Position=0, ParameterSetName="Pipeline", ValueFromPipelineByPropertyName=$true, Mandatory=$true)]
    [String]$Name
  )

  process {
    switch($PsCmdlet.ParameterSetName) {
      "Value" {$servers = $ComputerName}
      "Pipeline" {$servers = $Name}
    }
    $servers | %{
      $RPC = Get-Counter "\MSExchange RpcClientAccess\User Count" -ComputerName $_
      $OWA = Get-Counter "\MSExchange OWA\Current Unique Users" -ComputerName $_
      $AS = Get-Counter “\MSExchange ActiveSync\Current Requests” -ComputerName $_
      $AB = Get-Counter "\MSExchangeAB\NSPI Connections Current" -ComputerName $_
      $IMAP =  If($IMAPEnabled -eq 'True'){get-counter "\MSExchangeimap4(1)\current connections" -ComputerName $_}Else{'Disabled'}
      $POP = If($POPEnabled -eq 'True'){Get-Counter "\MSExchangePOP3(_Total)\Connections Current" -ComputerName $_}Else{'Disabled'}
      $EWS = Get-Counter "\W3SVC_W3WP(*msexchangeservicesapppool)\Active Requests" -ComputerName $_
      New-Object PSObject -Property @{
        Server = $_
        "RPC Client Access" = $RPC.CounterSamples[0].CookedValue
        "Outlook Web App" = $OWA.CounterSamples[0].CookedValue
	"ActiveSync" = $AS.CounterSamples[0].CookedValue
	"Address Book" = $AB.CounterSamples[0].CookedValue
	"IMAP" = If($IMAP -eq'Disabled'){'Disabled'}Else{$IMAP.CounterSamples[0].CookedValue}
	"POP" = If ($POP -eq 'Disabled'){'Disabled'}Else {$POP.CounterSamples[0].CookedValue}
	"EWS" = $EWS.CounterSamples[0].CookedValue
      } | Select-Object Server,"RPC Client Access","Outlook Web App",ActiveSync,IMAP,POP,"Address Book",EWS | FT -Auto
    }
  }
}

if ($ServerRole -like '@{ServerRole=ClientAccess}'){write-host 'Dedicated CAS Server Detected...' -foregroundcolor "magenta"
write-host ""
write-host 'Service Status (Displays Services that are configured for Automatic startup but are in a stopped state):' -foregroundcolor "green"
Get-WmiObject Win32_Service -computername $Server |
Where-Object { $_.StartMode -eq 'Auto' -and $_.State -ne 'Running' } |
# process them; in this example we just show them:
Format-Table -AutoSize @(
    'DisplayName'
    @{ Expression = 'State'; Width = 9 }
    @{ Expression = 'StartMode'; Width = 9 }
    'StartName'
)
write-host "All 'Error' & 'Warning' Application log entries in the most recent 100 entries:" -foregroundcolor "green"

Get-EventLog -Newest 100 -ComputerName $Server -LogName application | where {($_.Entrytype -like 'error') -or ($_.EntryType -like 'warning')} | ft TimeGenerated,EntryType,Source,Message

write-host "All 'Error' & 'Warning' System log entries in the most recent 100 entries:" -foregroundcolor "green"

Get-EventLog -Newest 100 -ComputerName $Server -LogName System | where {($_.Entrytype -like 'error') -or ($_.EntryType -like 'warning')} | ft TimeGenerated,EntryType,Source,Message

write-host 'Active Client Connections:' -foregroundcolor "green"

get-casactiveusers -computername $Server

write-host 'IMAP Connectivity Validation:' -foregroundcolor "green"

If($IMAPEnabled -eq 'False'){Write-Host ""}

If($IMAPEnabled -eq 'True'){Test-ImapConnectivity -ClientAccessServer $Server | fl Result,scenariodescription}Else{'IMAP Service disabled, continuing to next test...'}

If($IMAPEnabled -eq 'False'){Write-Host ""}

write-host 'POP Connectivity Validation:' -foregroundcolor "green"

If($POPEnabled -eq 'False'){Write-Host ""}

If($POPEnabled -eq 'True'){Test-PopConnectivity -ClientAccessServer $Server | fl Result,ScenarioDescription}Else{'POP Service disabled, continuing to next test...'}

If($POPEnabled -eq 'False'){Write-Host ""}

write-host 'Outlook Web Services Connectivity Validation:' -foregroundcolor "green"

Test-OutlookWebServices -ClientAccessServer $Server | ft Type,Message -auto -wrap

write-host 'OWA Validation:' -foregroundcolor "green"

Test-OwaConnectivity -ClientAccessServer $Server | fl Result,URL,AuthenticationMethod,ScenarioDescription

write-host 'Web Services Validation:' -foregroundcolor "green"

Test-WebServicesConnectivity -ClientAccessServer $Server | ft Result,Scenario,ScenarioDescription -auto

}

if ($ServerRole -like '@{ServerRole=HubTransport}'){write-host 'Dedicated Hub Transport Server Detected...' -foregroundcolor "magenta"
write-host ""
write-host 'Service Status (Displays Services that are configured for Automatic startup but are in a stopped state):' -foregroundcolor "green"
Get-WmiObject Win32_Service -computername $Server |
Where-Object { $_.StartMode -eq 'Auto' -and $_.State -ne 'Running' } |
# process them; in this example we just show them:
Format-Table -AutoSize @(
    'DisplayName'
    @{ Expression = 'State'; Width = 9 }
    @{ Expression = 'StartMode'; Width = 9 }
    'StartName'
)
write-host "All 'Error' & 'Warning' Application log entries in the most recent 100 entries:" -foregroundcolor "green"

Get-EventLog -Newest 100 -ComputerName $Server -LogName application | where {($_.Entrytype -like 'error') -or ($_.EntryType -like 'warning')} | ft TimeGenerated,EntryType,Source,Message

write-host "All 'Error' & 'Warning' System log entries in the most recent 100 entries:" -foregroundcolor "green"

Get-EventLog -Newest 100 -ComputerName $Server -LogName System | where {($_.Entrytype -like 'error') -or ($_.EntryType -like 'warning')} | ft TimeGenerated,EntryType,Source,Message

write-host 'SMTP Connectivity Validation:' -foregroundcolor "green"

Test-SmtpConnectivity $Server | FT

write-host 'Transport Queue Status:' -foregroundcolor "green"

get-queue -server $Server | FT

}

if ($ServerRole -like '@{ServerRole=ClientAccess, HubTransport}'){write-host 'CAS\HT Multirole Server Detected...' -foregroundcolor "magenta"
write-host ""
write-host 'Service Status (Displays Services that are configured for Automatic startup but are in a stopped state):' -foregroundcolor "green"
Get-WmiObject Win32_Service -computername $Server |
Where-Object { $_.StartMode -eq 'Auto' -and $_.State -ne 'Running' } |
# process them; in this example we just show them:
Format-Table -AutoSize @(
    'DisplayName'
    @{ Expression = 'State'; Width = 9 }
    @{ Expression = 'StartMode'; Width = 9 }
    'StartName'
)
write-host "All 'Error' & 'Warning' Application log entries in the most recent 100 entries:" -foregroundcolor "green"

Get-EventLog -Newest 100 -ComputerName $Server -LogName application | where {($_.Entrytype -like 'error') -or ($_.EntryType -like 'warning')} | ft TimeGenerated,EntryType,Source,Message

write-host "All 'Error' & 'Warning' System log entries in the most recent 100 entries:" -foregroundcolor "green"

Get-EventLog -Newest 100 -ComputerName $Server -LogName System | where {($_.Entrytype -like 'error') -or ($_.EntryType -like 'warning')} | ft TimeGenerated,EntryType,Source,Message

write-host 'Active Client Connections:' -foregroundcolor "green"

get-casactiveusers -computername $Server

write-host 'IMAP Connectivity Validation:' -foregroundcolor "green"

If($IMAPEnabled -eq 'False'){Write-Host ""}

If($IMAPEnabled -eq 'True'){Test-ImapConnectivity -ClientAccessServer $Server | fl Result,scenariodescription}Else{'IMAP Service disabled, continuing to next test...'}

If($IMAPEnabled -eq 'False'){Write-Host ""}

write-host 'POP Connectivity Validation:' -foregroundcolor "green"

If($POPEnabled -eq 'False'){Write-Host ""}

If($POPEnabled -eq 'True'){Test-PopConnectivity -ClientAccessServer $Server | fl Result,ScenarioDescription}Else{'POP Service disabled, continuing to next test...'}

If($POPEnabled -eq 'False'){Write-Host ""}

write-host 'Outlook Web Services Connectivity Validation:' -foregroundcolor "green"

Test-OutlookWebServices -ClientAccessServer $Server | ft Type,Message -auto -wrap

write-host 'OWA Validation:' -foregroundcolor "green"

Test-OwaConnectivity -ClientAccessServer $Server | fl Result,URL,AuthenticationMethod,ScenarioDescription

write-host 'Web Services Validation:' -foregroundcolor "green"

Test-WebServicesConnectivity -ClientAccessServer $Server | ft Result,Scenario,ScenarioDescription -auto

write-host 'SMTP Connectivity Validation:' -foregroundcolor "green"

Test-SmtpConnectivity $Server | FT

write-host 'Transport Queue Status:' -foregroundcolor "green"

get-queue -server $Server | FT

}

if ($ServerRole -like '@{ServerRole=Mailbox, ClientAccess, HubTransport}'){write-host 'CAS\HT\MB Multirole Server Detected...' -foregroundcolor "magenta"
write-host ""
write-host 'Service Status (Displays Services that are configured for Automatic startup but are in a stopped state):' -foregroundcolor "green"
Get-WmiObject Win32_Service -computername $Server |
Where-Object { $_.StartMode -eq 'Auto' -and $_.State -ne 'Running' } |
# process them; in this example we just show them:
Format-Table -AutoSize @(
    'DisplayName'
    @{ Expression = 'State'; Width = 9 }
    @{ Expression = 'StartMode'; Width = 9 }
    'StartName'
)
write-host "All 'Error' & 'Warning' Application log entries in the most recent 100 entries:" -foregroundcolor "green"

Get-EventLog -Newest 100 -ComputerName $Server -LogName application | where {($_.Entrytype -like 'error') -or ($_.EntryType -like 'warning')} | ft TimeGenerated,EntryType,Source,Message

write-host "All 'Error' & 'Warning' System log entries in the most recent 100 entries:" -foregroundcolor "green"

Get-EventLog -Newest 100 -ComputerName $Server -LogName System | where {($_.Entrytype -like 'error') -or ($_.EntryType -like 'warning')} | ft TimeGenerated,EntryType,Source,Message

write-host 'Active Client Connections:' -foregroundcolor "green"

get-casactiveusers -computername $Server

write-host 'IMAP Connectivity Validation:' -foregroundcolor "green"

If($IMAPEnabled -eq 'False'){Write-Host ""}

If($IMAPEnabled -eq 'True'){Test-ImapConnectivity -ClientAccessServer $Server | fl Result,scenariodescription}Else{'IMAP Service disabled, continuing to next test...'}

If($IMAPEnabled -eq 'False'){Write-Host ""}

write-host 'POP Connectivity Validation:' -foregroundcolor "green"

If($POPEnabled -eq 'False'){Write-Host ""}

If($POPEnabled -eq 'True'){Test-PopConnectivity -ClientAccessServer $Server | fl Result,ScenarioDescription}Else{'POP Service disabled, continuing to next test...'}

If($POPEnabled -eq 'False'){Write-Host ""}

write-host 'Outlook Web Services Connectivity Validation:' -foregroundcolor "green"

Test-OutlookWebServices -ClientAccessServer $Server | ft Type,Message -auto -wrap

write-host 'OWA Validation:' -foregroundcolor "green"

Test-OwaConnectivity -ClientAccessServer $Server | fl Result,URL,AuthenticationMethod,ScenarioDescription

write-host 'Web Services Validation:' -foregroundcolor "green"

Test-WebServicesConnectivity -ClientAccessServer $Server | ft Result,Scenario,ScenarioDescription -auto

write-host 'SMTP Connectivity Validation:' -foregroundcolor "green"

Test-SmtpConnectivity $Server | FT

write-host 'Transport Queue Status:' -foregroundcolor "green"

get-queue -server $Server | FT

write-host 'DAG Node Status:' -foregroundcolor "green"

test-replicationhealth $Server | ft

write-host 'Database Status:' -foregroundcolor "green"

get-mailboxdatabasecopystatus -server $Server |select Identity,Status,ActiveDatabaseCopy,ContentIndexState,CopyQueueLength,ReplayQueueLength | sort Identity | ft

write-host 'MAPI Connectivity Validation:' -foregroundcolor "green"

Test-MAPIConnectivity -Server $Server | FT

write-host 'Mailflow Validation:' -foregroundcolor "green"

Test-mailflow -Identity $Server | FT TestMailflowResult,MessageLatencyTime

}

if ($ServerRole -like '@{ServerRole=Mailbox}'){write-host 'Dedicated Mailbox Server Detected...' -foregroundcolor "magenta"
write-host ""
write-host 'Service Status (Displays Services that are configured for Automatic startup but are in a stopped state):' -foregroundcolor "green"
Get-WmiObject Win32_Service -computername $Server |
Where-Object { $_.StartMode -eq 'Auto' -and $_.State -ne 'Running' } |
# process them; in this example we just show them:
Format-Table -AutoSize @(
    'DisplayName'
    @{ Expression = 'State'; Width = 9 }
    @{ Expression = 'StartMode'; Width = 9 }
    'StartName'
)
write-host "All 'Error' & 'Warning' Application log entries in the most recent 100 entries:" -foregroundcolor "green"

Get-EventLog -Newest 100 -ComputerName $Server -LogName application | where {($_.Entrytype -like 'error') -or ($_.EntryType -like 'warning')} | ft TimeGenerated,EntryType,Source,Message

write-host "All 'Error' & 'Warning' System log entries in the most recent 100 entries:" -foregroundcolor "green"

Get-EventLog -Newest 100 -ComputerName $Server -LogName System | where {($_.Entrytype -like 'error') -or ($_.EntryType -like 'warning')} | ft TimeGenerated,EntryType,Source,Message

write-host 'DAG Node Status:' -foregroundcolor "green"

test-replicationhealth $Server | ft

write-host 'Database Status:' -foregroundcolor "green"

get-mailboxdatabasecopystatus -server $Server |select Identity,Status,ActiveDatabaseCopy,ContentIndexState,CopyQueueLength,ReplayQueueLength | sort Identity | ft

write-host 'MAPI Connectivity Validation:' -foregroundcolor "green"

Test-MAPIConnectivity -Server $Server | FT

write-host 'Mailflow Validation:' -foregroundcolor "green"

Test-mailflow -Identity $Server | FT TestMailflowResult,MessageLatencyTime

}

if ($ServerRole -like '*EDGE*'){write-host 'Edge Server Detected...' -foregroundcolor "magenta"
write-host ""
write-host 'Service Status (Displays Services that are configured for Automatic startup but are in a stopped state):' -foregroundcolor "green"
Get-WmiObject Win32_Service -computername $Server |
Where-Object { $_.StartMode -eq 'Auto' -and $_.State -ne 'Running' } |
# process them; in this example we just show them:
Format-Table -AutoSize @(
    'DisplayName'
    @{ Expression = 'State'; Width = 9 }
    @{ Expression = 'StartMode'; Width = 9 }
    'StartName'
)
write-host "All 'Error' & 'Warning' Application log entries in the most recent 100 entries:" -foregroundcolor "green"

Get-EventLog -Newest 100 -ComputerName $Server -LogName application | where {($_.Entrytype -like 'error') -or ($_.EntryType -like 'warning')} | ft TimeGenerated,EntryType,Source,Message

write-host "All 'Error' & 'Warning' System log entries in the most recent 100 entries:" -foregroundcolor "green"

Get-EventLog -Newest 100 -ComputerName $Server -LogName System | where {($_.Entrytype -like 'error') -or ($_.EntryType -like 'warning')} | ft TimeGenerated,EntryType,Source,Message

write-host 'Transport Queue Status:' -foregroundcolor "green"

get-queue -server $Server | FT

}

stop-transcript

#$Body = Get-Content -Path C:\ESHC.txt | Out-String

    write-host ""
write-host "Would you like to send this report to the $SMTPRecipient address?" -foregroundcolor "yellow"
    write-host ""
    write-host "Y - Yes" -foregroundcolor "yellow"
    write-host "N - No" -foregroundcolor "red"
    write-host "" 
    write-host -nonewline "Type your choice and press Enter:" -foregroundcolor "yellow"
    $SendMail = read-host
    write-host ""
    $ok = @("Y","N","X") -contains $SendMail
    if ( -not $ok) { write-host "Invalid selection" }

if($SendMAil -eq 'Y'){send-mailmessage -From:$SMTPSender -To:$SMTPRecipient -SMTPServer:$SMTPServer -Subject:$Server' - Post-change Report' -attach $TranscriptPath -Body:"Server report"
write-host 'Report complete, returning to the command prompt...' -foregroundcolor "yellow"}
if($SendMail -eq 'N'){write-host 'Report complete, returning to the command prompt...' -foregroundcolor "yellow"}
    write-host ""

If for some reason the text above doesn’t work, you can download the file here (rename .txt to .ps1)

Exchange CAS IIS Log Maintenance

One of the first things a young Exchange admin will learn is that there is no built in IIS log maintenance capability for clearing out old log files baked in to Exchange. Hopefully this lesson comes when SCOM starts throwing drive space alerts, and not when the C: drive fills up and craters the server :/. To mitigate this risk, most admins create a simple script for regularly performing IIS log maintenance by deleting CAS log files older than a certain date. Here are a couple of scripts you can use, depending on your environment.

Properly scheduled IIS log maintenance will help keep your C: drive clean (what was happening on 6/14!?)
15 items so the script is working as expected. Based on file size you may want to shorten the retention window to 7 days in your environment.

For info on how to create the Scheduled Task to run this script daily, look here

If you just have one CAS (or one server with the Client Access Service in the case of Exchange 2016), this one-liner will get the job done:

#################################################################
# Exchange CAS IIS Log Maintenance                              #
# This script deletes IIS log files older than 14 days from the #
# local Exchange CAS server					#
#								#
# Created by Eric Kukkuck 3/3/2015				#
#################################################################

Get-ChildItem –Path  “C:\inetpub\logs\LogFiles\W3SVC1” | Where-Object {$_.CreationTime –lt (Get-Date).AddDays(-14)} | Remove-Item

If you have multiple CASes and an Admin server, this script will pull a list of CAS servers from a text file and clear the old log files remotely. It will also remove log files from the first two additional log file directories, if you happen to have three directories in play (as I did at one point, the default website, a secondary website for basic auth ActiveSync devices, and a third website for the AV solution)

#################################################################
# Exchange CAS IIS Log Maintenance                              #
# This script deletes IIS log files older than 14 days from all #
# the Exchange CAS servers listed in the        		#
# D:\ABZ\Scripts\ExchangeCASServers.txt file			#
#								#
# Created by Eric Kukkuck 3/3/2015				#
#################################################################

$servers = get-content "D:\ABZ\Scripts\ExchangeCASServers.txt"

foreach ($server in $servers)
{
	Get-ChildItem –Path  “\\$server\c$\inetpub\logs\LogFiles\W3SVC1”,"\\$server\c$\inetpub\logs\LogFiles\W3SVC2","\\$server\c$\inetpub\logs\LogFiles\W3SVC3",“\\$server\c$\inetpub\logs\LogFiles\W3SVC4” | Where-Object {$_.CreationTime –lt (Get-Date).AddDays(-14)} | Remove-Item
}

-Eric

IIS Log Parser Script for Finding Two Items Per Line

Troubleshooting Exchange connectivity issues can often be a chore, especially if you’re trying to go line by line in the IIS logs. The close formatting in those text files makes for a blurry and mind-numbing experience, not to mention how easy it is to miss what you’re actually looking for. To make that experience easier (and to offload the hard work to PowerShell) I’ve put together the following IIS log parser script* that will allow you to search IIS logs remotely on multiple servers for lines that contain two different items and export that data to a CSV. For example, if your helpdesk reports to you that some people are unable to access their mailbox from their ActiveSync device, you may want to start your investigation by searching the IIS logs on multiple CASes for lines that contain both “ActiveSync” and “401”. This script will do just that!

*I’d like to give credit to who created the original script I edited to make this one, but I cannot seem to find it online 🙁

-Eric

#########################################################
# Search Multiple IIS Logs for Multiple Items Per Line 	#
# Created By Eric Kukkuck   04/16/2014			#
#########################################################

# Edit the variables below to meet your needs #

$Path = "\\SERVER1\c$\inetpub\logs\LogFiles\W3SVC1","\\SERVER2\c$\inetpub\logs\LogFiles\W3SVC1"
$PathArray = @()
$ResultsLog = "C:\Temp\IISSearchResults.csv"
$Variable1 = "ActiveSync"
$Variable2 = "401"

# The meat and potatoes #

if (Test-Path $ResultsLog -PathType Leaf) { 
write-host "Delete the current log file and try again " 
exit
}
# This code snippet gets all the files in $Path that end in “.log”.
Get-ChildItem $Path -Recurse -Filter “*.log” |
Where-Object { $_.Attributes -ne “Directory”} |
ForEach-Object {gc $_.FullName | % { if($_ -match "($Variable1.*$Variable2)") {
$_ | add-content -path $ResultsLog }
    }
}

Get CAS Active User Counts (Exchange 2010)

A lot of times when troubleshooting a potential Exchange CAS server issue or performing maintenance on an Exchange 2010 client access server, you’ll find you need to identify how many active connections exist on your CAS. The script found on Technet will pull your RPC, OWA, and EAS connections, but I prefer a more complete view so I’ve added Address Book, POP, IMAP, and EWS connections to fill out the script.

One thing to note about running this script – it creates a function to be called later, so you need to save it as a .ps1 file and execute it by entering “. .\filename.ps1” at the prompt. Once the function has been added to the shell you call it by entering “Get-CASActiveUsers -ComputerName casname“.

-Eric

function Get-CASActiveUsers {
  [CmdletBinding()]
    param(
    [Parameter(Position=0, ParameterSetName="Value", Mandatory=$true)]
    [String[]]$ComputerName,
    [Parameter(Position=0, ParameterSetName="Pipeline", ValueFromPipelineByPropertyName=$true, Mandatory=$true)]
    [String]$Name
  )

  process {
    switch($PsCmdlet.ParameterSetName) {
      "Value" {$servers = $ComputerName}
      "Pipeline" {$servers = $Name}
    }
    $servers | %{
      $RPC = Get-Counter "\MSExchange RpcClientAccess\User Count" -ComputerName $_
      $OWA = Get-Counter "\MSExchange OWA\Current Unique Users" -ComputerName $_
      $AS = Get-Counter “\MSExchange ActiveSync\Current Requests” -ComputerName $_
      $AB = Get-Counter "\MSExchangeAB\NSPI Connections Current" -ComputerName $_
      $IMAP =  get-counter "\MSExchangeimap4(_Total)\current connections" -ComputerName $_
      $EWS = Get-Counter "\W3SVC_W3WP(*msexchangeservicesapppool)\Active Requests" -ComputerName $_
      New-Object PSObject -Property @{
        Server = $_
         "RPC Client Access" = $RPC.CounterSamples[0].CookedValue
         "Outlook Web App" = $OWA.CounterSamples[0].CookedValue
	 "ActiveSync" = $AS.CounterSamples[0].CookedValue
	 "Address Book" = $AB.CounterSamples[0].CookedValue
	 "IMAP" = $IMAP.CounterSamples[0].CookedValue
	 "EWS" = $EWS.CounterSamples[0].CookedValue
      } | Select-Object Server,"RPC Client Access","Outlook Web App",IMAP,ActiveSync,"Address Book",EWS | FT -Auto
    }
  }
}

Recovering from Exchange Database Dismount due to Transaction Log Accumulation

As we all know, Microsoft Exchange uses transaction logs to commit data to the mailbox databases. One of the first critical issues we usually run into during our messaging career is a database dismount due to running out of capacity for the transaction logs. This is usually caused by at least one failed backup, and the emergency fix is to clear some of the oldest transaction logs from the drive so you can remount the database. Once the DB is back up (in a DAG you’ll have to manually delete the same transaction logs from each copy to restore HA), you may want to quickly truncate all of the remaining possible logs to maximize the time you have before the problem happens again. To do that, Microsoft has created a tool for testing VSS capabilities on an Exchange server (versions 2010, 2013, and 2016), but it has the additional benefit of kicking off the log truncation process while it runs. You can find the tool here:

https://gallery.technet.microsoft.com/office/VSSTesterps1-script-4ed07243

A few things to note before using the VSSTester.ps1 script:

  • You would run this tool on the server with the active copy of the database
  • If this is the server the backup failed on, you may need to reboot (you could restart the Information Store service instead but IMHO if you’re going to move all the DBs off that server to bounce the service might as well reboot to clear out any other gremlins). For the tool to complete successfully all of the VSS Writers and such need to be in the correct state
  • Once this has successfully cleared your logs on the active copy the passive copies should truncate their logs as expected.
  • If you’re having problems running the tool on one server you can always make another copy of the DB active on another server and run it there

-Eric