We recently enabled monitoring for a few eventid's for DHCP database related events. Today we noticed that events 1010 and 1016 were triggered in the windows event viewer but no events are alert generated in Nimsoft.
Environment
Release: 20.3+, 23.4+
Component: UIM - NTEVL
Cause
- ntevl configuration
Resolution
Please ensure you are using the latest GA version ntevl v4.35 or higher
Via Raw Configure mode for ntevl, set poll interval to 30 seconds
Increase max number of threads to 10, then to 20 if the issue persists
Make sure that there all profiles that match logs that are being monitored by the probe (ie. Application, System)
wmi_timeout = 15 sec
no_of_threads = 5
AlarmTimeOutDuration = <keep this value empty>
Also, If you’re seeing high CPU consumption from the ntevl probe, try removing the Security log from monitoring: Via ntevl probe Raw Configure option, Disable (remove) Security log from the logs section thereby preventing Security log monitoring.