Applications Systems
AppInsight for Active Directory performance counters appear as Unknown and fail during SAM polling
This article describes how a Windows issue related to the NTDS category can cause AppInsight for Active Directory performance counters to appear as Unknown and fail when polling domain controllers in SolarWinds SAM. It includes a workaround that involves rebuilding Windows NT Directory Services (NTDS) performance counters.
First published date
Last published date
Overview
This article provides information about an issue where AppInsights for Active Directory fails to poll domain controllers properly. In some scenarios, the following behavior or symptoms may be found:
- AppInsight for Active Directory fails with the message of "Performance counter is not found. the specified object is not found in the system"
- In the APM log at C:\ProgramData\SolarWinds\Logs\APM, the message appears "ErrorCode:Unhandled, OSError:0x80131500. Message: Unable to collect WMI mapping information for given category value: NTDS"
Product section
Cause
This issue occurs because the NTDS performance counters are missing, and SolarWinds Platform is unable to poll information from the domain controller. There are multiple reasons why the performance counters are missing, but not limited to the following:
- Role removal or incomplete promotion or demotion
- NTDS DLL registration issues
- Corrupted or incomplete performance counter registry entries
- Permissions or security hardening
- Counters manually disabled (or disabled by monitoring tools)
- Windows updates or patches
Microsoft recommends rebuilding the counter immediately to resolve the issue. If the problem persists, it is recommended to discuss it with Microsoft to understand why performance counters are missing.
Resolution
To resolve this issue, rebuild NTDS performance counters using the Microsoft documentation below.
SolarWinds recommends the following posts for reference: