Problem
Diagnosis
Look at your interface log file(s) from a time when multiple NLINK Sessions are posting to the same log file. If you notice that messages from each session are a second or more apart when they should logically be happening much closer together, this is a symptom. (Normally many messages could be logged within a single second, even from multiple sessions.)
Look at the Inbound Message Queue in the NLINK Management Module (NMM) while multiple NLINK sessions are working on the Events for the same interface. If you notice that the Current Action for the active Events is frequenly a Log Message Action, this is a symptom. (Normally a Log Message should be so quick that it rarely shows up as the Current Action.)
Solution
As an example, the following steps describe how to add a Folder Exclusion Rule for the Logs folder and a Process Exclusion Rule for the NLINK Server in Windows Defender on a Windows 2016 Server.
- Open Windows Defender from the System Tray or by searching for the Windows Defender desktop app.
- Click on Settings in the menu bar.
Different operating systems or different anti-virus tools will have different procedures, but all should allow for these sorts of exclusion rules.
Related articles