Ad Widget

Collapse

Huge delay in active monitoring

Collapse
X
 
  • Time
  • Show
Clear All
new posts
  • twoolley
    Junior Member
    • Apr 2023
    • 4

    #1

    Huge delay in active monitoring

    Hi all,

    I'm experiencing an issue where my active monitoring doesn't seem to be pushing logs immediately. I'm trying to get alerts set up when a certain eventid is triggered on the monitored host, but experiencing a ~16 hour time delay between the event happening and the Zabbix server displaying the data. I was under the impression that this would happen at the update interval, which I currently have set to 1m?

    Sample of my items:

    Click image for larger version

Name:	2023-04-20-134040_1716x157_scrot.png
Views:	708
Size:	38.8 KB
ID:	463335

    I can see the logs being created in the EventViewer on the DC.

    Thanks
  • cyber
    Senior Member
    Zabbix Certified SpecialistZabbix Certified Professional
    • Dec 2006
    • 4807

    #2
    Your assumption is correct, if new data comes in, trigger is recalculated and you should have an event. But item collection in 1m interval is one thing... what's your trigger config..?

    Comment

    • twoolley
      Junior Member
      • Apr 2023
      • 4

      #3
      Thanks for your response.

      The trigger is:
      Code:
      count(/{HOSTNAME}/eventlog[security,,,,4767,,],5)>0
      I appreciate this probably isn't the best, but it was something that seemed to create a problem immediately when an event was generated. If we can get best practice for this trigger nipped too then perfect, however I think the issue might be different here. Very open to being told I'm wrong though :-)

      From the Latest Data page I'm seeing:

      Click image for larger version

Name:	image.png
Views:	717
Size:	21.5 KB
ID:	463390

      Looking at the history I'm getting the following. Notice the huge discrepency between the timestamp of the Zabbix event of the left, and of the log (accurate to when I disabled the test account). I'm getting this as history of the item even without any triggers enabled.

      Click image for larger version

Name:	image.png
Views:	680
Size:	14.2 KB
ID:	463391
      Thanks again

      Comment

      • cyber
        Senior Member
        Zabbix Certified SpecialistZabbix Certified Professional
        • Dec 2006
        • 4807

        #4
        "count of item values within last 5 checks is more than 0".. This trigger will always be true. It can never be false..
        I'm getting this as history of the item even without any triggers enabled.
        Item collection takes place even if no triggers are added...

        But here is really a big delay in data... I am not too familiar with windows.. How big those logfiles are? Maybe it just is not able to process incoming stuff ? Would it work better, if you delete existing item and recreate it with "skip" option, so it would start reading logs from the end and not process all existing data?

        Comment

        • twoolley
          Junior Member
          • Apr 2023
          • 4

          #5
          Adding the skip did help, so now the delay is only ~2 hours. Still not ideal, but a LOT better so thanks for that. I guess I'll look into the incoming data and see if I can get it processed more efficiently.

          Thank you for your time and your responses - Greatly appreciated.

          Comment


          • AndersonACC
            AndersonACC commented
            Editing a comment
            Hello Twoolley! I have the same issue, Can you help-me?
        Working...