Ad Widget

Collapse

Problem with services "cbdhsvc" and "webthreatdefusersvc" but only on windows 11

Collapse
X
 
  • Time
  • Show
Clear All
new posts
  • krzysztof.tech
    Junior Member
    • Mar 2023
    • 8

    #1

    Problem with services "cbdhsvc" and "webthreatdefusersvc" but only on windows 11

    Hello community, I have a significant problem with the Zabbix active controller when it comes to two processes from Windows 11 Pro-based hosts.

    The problem concerns the "cbdhsvc" and "webthreatdefusersvc" services: Zabbix reports:

    "cbdhsvc_b56ea40" (Clipboard User Serviceb56ea40) is not running (startup type automatic delayed)
    "webthreatdefusersvc_b56ea40" (User service Web Threat Defense_b56ea40) is not running (startup type automatic)

    Of course, the "cbdhsvc" process occurs several times on one host with different numbers, for example, "cbdhsvc_4f9cbb75" - "cbdhsvc_d85cd" - "cbdhsvc_35e998fe"
    Attempts to manually raise the service or change the registry key for "Start" to 4 in HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\servic es have not been successful.

    I don't want to change the trigger; I want to know why these two services report an error to Zabbix and why only on Windows 11.

    Does anyone have knowledge of how to fix this?

    Best regards, Krzysztof
  • Zabbix_Forums_John
    Junior Member
    • Apr 2023
    • 1

    #2
    so services like this get spun up when a new user logs into the machine.

    typically i just create a filter to ignore these types of services but in this case that's not work either.....

    Here is the link to creating a filter.

    Comment

    • dre0477
      Junior Member
      • Aug 2022
      • 1

      #3
      Hi, if you don't solve the Problem all ready, here is the solution for you.

      You have to go to the Windows by Zabbix Agent or Windows by Zabbix Agent active Template, it depends on which template you use. But you can configure both.
      Go to Macros and look for the {$SERVICE.NAME.NOT_MATCHES} , next step is, enter |webthreatdefusersvc_.+|cbdhsvc_.+| in the value field as additional values. Click on update.
      Then goto to your host(s) with the problems end execute the discovery Rule "Windows services discovery". After the execution there should be to items wie an yellow exclamation mark, delete this items, the problem should be solved.

      Comment

      • msz@kommunekredit.dk
        Junior Member
        • Jun 2024
        • 7

        #4
        The real problem is to be able to see that the service is running regardless of the ID.
        The "Web Threat Defense User Service_xxxxxxxx" is relevant to monitor, it has changed the _xxxxxxxx part 3 times this week.

        Comment

        Working...