search cancel

ntevl probe is not creating alarms even though configured Windows events are generated


Article ID: 241445


Updated On:


DX Unified Infrastructure Management (Nimsoft / UIM)


We recently enabled monitoring for a few eventid's for DHCP database related events. Today we noticed that events 1010 and 1016 were triggered in the windows event viewer but no events are alert generated in Nimsoft.
When I am checking the NTEVL logs, I noticed one message.


- ntevl configuration


Release : 20.3

Component : UIM - NTEVL


  1. Please ensure you are using the latest GA version ntevl v4.33

          Via Raw Configure mode for ntevl,

  1. Set poll interval to 30 seconds
  2. Increase max number of threads to 10, then to 20 if the issue persists
  3. Make sure that there all profiles match logs that are being monitored by the probe (ie. Application, System)
  4. wmi_timeout = 15 sec
  5. no_of_threads = 5
  6. AlarmTimeOutDuration = <keep this value empty>
  7. Also, If you’re seeing high CPU consumption from the ntevl probe, try removing the Security log from monitoring: Via ntevl probe Raw Configure option, Disable (remove) Security log from the logs section thereby preventing Security log monitoring.