Hi there,
Don't know if it is an expected problem or a performance problem but here is the thing...
As I'm building up Zabbix config more and more, I've started to audit my Domain Controllers in a deeper way.
For that I'm implementing the templates from Alexei (https://share.zabbix.com/owner/g_109492255263695218277)
But for both "Attack Detection" and "Security Audit", I have every 5 minutes CPU peaks (relates to schedule). Here I have disabled both templates on that host @10:15, confirming it is related to event collection.

What is consistent with both templates is there are only collecting events in Security Logs.
Are you experiencing the same for other types of logs? Or maybe you have a solution?
For now, it is in my lab and I'd like to keep my CPU as low as possible, but I can't imagine putting that in production where I have thousands of logs every seconds!
Don't know if it is an expected problem or a performance problem but here is the thing...
As I'm building up Zabbix config more and more, I've started to audit my Domain Controllers in a deeper way.
For that I'm implementing the templates from Alexei (https://share.zabbix.com/owner/g_109492255263695218277)
But for both "Attack Detection" and "Security Audit", I have every 5 minutes CPU peaks (relates to schedule). Here I have disabled both templates on that host @10:15, confirming it is related to event collection.
What is consistent with both templates is there are only collecting events in Security Logs.
Are you experiencing the same for other types of logs? Or maybe you have a solution?
For now, it is in my lab and I'd like to keep my CPU as low as possible, but I can't imagine putting that in production where I have thousands of logs every seconds!
Comment