Windows file server issues... looking for assistance

Posted by Craig__D@reddit | sysadmin | View on Reddit | 15 comments

We are a small company with a small IT team. We are mostly generalists. Capable, but very much generalists. We are having an issue that I believe needs troubleshooting and diagnosis from someone with in-depth Windows file server expertise. I'll briefly describe what is happening below. I am a pretty decent troubleshooter and have worked and worked to try and isolate where the problem is coming from, but I haven't been able to pin it down. This is why I think I need help from someone with this particular set of skills and experience. I think it will be necessary to watch file handles, SMB traffic, etc. to see when the files are opened, closed, who or what opened them, etc. The most visible symptom is that when a certain program requires an update, the installer consistently experiences an error when we try to install the update from a workstation (which is how this program is updated). The program is one that uses a server-based file share to house its files, but doesn't have any processes that actually run on the server. It's just a file share-based program that is accessible from many people on our system from this shared location. The cause of the error appears to be that the installer cannot update three files that stored on the server share. The three files seem to be held open by some mysterious source, and this causes the installer to be unable to overwrite them and thus the installer fails. We've talked with the development team of the software product that is experiencing the failure, and they do not believe it is a problem with their installer (and I tend to agree, as we have seen some other evidence of a similar thing happening with other files). We've run down the anti-virus trail, and the conclusion is that it's not that... though I still believe it's a possibility. We just haven't found the "smoking gun" yet. Our environment (the parts that matter) consists of Dell hosts running ESXi 8, Windows Server (and some workstation) OSes running on those hosts, an Aruba core switch, and Pure and Tintri SAN devices. I won't go into too much more detail about the issue in this post, as it is long enough already, but will be happy to answer questions either here or in a one-on-one conversation. We've contacted the company that we occasionally lean on for technical assistance, and they do not have anyone they feel can help us with this. I'd love to hear from you if you have this particular expertise and experience. Thanks in advance.