ALERT: Some images may not load properly within the Knowledge Base Article. If you see a broken image, please right-click and select 'Open image in a new tab'. We apologize for this inconvenience.

ntevl probe is not creating alarms even though configured Windows events are generated

book

Article ID: 241445

calendar_today

Updated On:

Products

DX Unified Infrastructure Management (Nimsoft / UIM)

Issue/Introduction

We recently enabled monitoring for a few eventid's for DHCP database related events. Today we noticed that events 1010 and 1016 were triggered in the windows event viewer but no events are alert generated in Nimsoft.
When I am checking the NTEVL logs, I noticed one message.

Cause

- ntevl configuration

Environment

Release : 20.3

Component : UIM - NTEVL

Resolution

  1. Please ensure you are using the latest GA version ntevl v4.33
    http://support.nimsoft.com/Files/Archive/00074/ntevl-4.33.zip

          Via Raw Configure mode for ntevl,

  1. Set poll interval to 30 seconds
  2. Increase max number of threads to 10, then to 20 if the issue persists
  3. Make sure that there all profiles match logs that are being monitored by the probe (ie. Application, System)
  4. wmi_timeout = 15 sec
  5. no_of_threads = 5
  6. AlarmTimeOutDuration = <keep this value empty>
  7. Also, If you’re seeing high CPU consumption from the ntevl probe, try removing the Security log from monitoring: Via ntevl probe Raw Configure option, Disable (remove) Security log from the logs section thereby preventing Security log monitoring.