Ad Widget

Collapse

High CPU by Windows log event collecting

Collapse
X
 
  • Time
  • Show
Clear All
new posts
  • EHRETic
    Member
    • Jan 2021
    • 45

    #1

    High CPU by Windows log event collecting

    Hi there,

    Don't know if it is an expected problem or a performance problem but here is the thing...
    As I'm building up Zabbix config more and more, I've started to audit my Domain Controllers in a deeper way.
    For that I'm implementing the templates from Alexei (https://share.zabbix.com/owner/g_109492255263695218277)

    But for both "Attack Detection" and "Security Audit", I have every 5 minutes CPU peaks (relates to schedule). Here I have disabled both templates on that host @10:15, confirming it is related to event collection.

    Click image for larger version

Name:	2021-05-01 10_23_0.png
Views:	1164
Size:	148.5 KB
ID:	423925

    What is consistent with both templates is there are only collecting events in Security Logs.

    Are you experiencing the same for other types of logs? Or maybe you have a solution?

    For now, it is in my lab and I'd like to keep my CPU as low as possible, but I can't imagine putting that in production where I have thousands of logs every seconds!
  • gofree
    Senior Member
    Zabbix Certified SpecialistZabbix Certified Professional
    • Dec 2017
    • 400

    #2
    Ive experienced such thing in my past with eventlog on security logs - if the logging setup on the server is high it was killing the machine. Simply too many and too general requests on whole lot of data caused this behavior.

    There are couple things you might try without big pain

    - shorten the interval to 1m or less ( its 5m in those templates ) less data to process or go through - no guarantees it will help and will not cause trouble in the future
    - think what items are really needed - its not always necessary to see everything
    - make sure you have installed latest agent version - preferably Zabbix agent 2 - just to feel good that you're using latest thing
    - try to play with setting in eventlog item , especially with the mode parameter - use skip processing of older data ( affects only newly created items !!! ) , no need to reread the whole log as it grows https://www.zabbix.com/documentation...agent/win_keys

    Dont try to turn Zabbix in log management system ist not yet there - aiming for version 6.4 https://www.zabbix.com/roadmap



    Comment

    • EHRETic
      Member
      • Jan 2021
      • 45

      #3
      Originally posted by gofree
      Ive experienced such thing in my past with eventlog on security logs - if the logging setup on the server is high it was killing the machine. Simply too many and too general requests on whole lot of data caused this behavior.

      There are couple things you might try without big pain

      - shorten the interval to 1m or less ( its 5m in those templates ) less data to process or go through - no guarantees it will help and will not cause trouble in the future
      - think what items are really needed - its not always necessary to see everything
      - make sure you have installed latest agent version - preferably Zabbix agent 2 - just to feel good that you're using latest thing
      - try to play with setting in eventlog item , especially with the mode parameter - use skip processing of older data ( affects only newly created items !!! ) , no need to reread the whole log as it grows https://www.zabbix.com/documentation...agent/win_keys
      I'll try all of that but from the event list, there is not so many I can get "rid off" and I don't think it is an issue with the amount of events, but the amount of events to read in the log.
      But the configuration of agent seems promissing by not processing past events as I've seen in AD health template that it was reading out events from 2019 in other logs!!!

      Thanks for those tips!
      Last edited by EHRETic; 01-05-2021, 12:20.

      Comment

      • EHRETic
        Member
        • Jan 2021
        • 45

        #4
        Originally posted by gofree
        - try to play with setting in eventlog item , especially with the mode parameter - use skip processing of older data ( affects only newly created items !!! ) , no need to reread the whole log as it grows https://www.zabbix.com/documentation...agent/win_keys

        Dont try to turn Zabbix in log management system ist not yet there - aiming for version 6.4 https://www.zabbix.com/roadmap
        Well, I've tried but didn't success, I guess I have to wait a little or put some effort in my SIEM's alerting capabilities!

        Thanks again for the help!

        Comment

        Working...