Ad Widget

Collapse

Why is Zabbix collecting Windows Event Log data late?

Collapse
X
 
  • Time
  • Show
Clear All
new posts
  • ZabTheo
    Member
    • Apr 2023
    • 62

    #1

    Why is Zabbix collecting Windows Event Log data late?

    Hello,

    I have the following items applied to all domain controllers to monitor security events.
    Click image for larger version

Name:	2024-04-05 17_21_03-Window.png
Views:	165
Size:	481.5 KB
ID:	481950



    Here are the corresponding triggers:
    Click image for larger version

Name:	2024-04-05 17_22_46-Window.png
Views:	265
Size:	92.4 KB
ID:	481948


    However the time that the event occurred on the domain controller (Local time), compared to the time Zabbix saw the event is always several hours later. This is causing the alert to trigger way past the event.

    Click image for larger version

Name:	2024-04-05 17_24_28-Window.png
Views:	170
Size:	31.9 KB
ID:	481951


    Here is the domain controllers latest data showing the time it last checked. I assume this is when Zabbix pulled the log and caused the problem alert above.

    Click image for larger version

Name:	2024-04-05 17_28_14-Window.png
Views:	177
Size:	30.5 KB
ID:	481953


    Any idea why this is happening? The item is an active check set to 1 second. I would expect Zabbix to get the info from the domain controller straight away.
    Thanks!
    Attached Files
  • ZabTheo
    Member
    • Apr 2023
    • 62

    #2
    Doing some further investigation on this issue, it seems to be a common occurrence. There are quite a few posts where people are having the same issue.
    Is this expected due to the number of log entries Zabbix is trying to process from the domain controllers?

    Comment

    • ZabTheo
      Member
      • Apr 2023
      • 62

      #3
      So I adjusted the update interval from 1 second to 10 seconds and they now seem to be alerting within a few minutes.

      Comment

      Working...