Submit a ticketCall us

AnnouncementsTHWACKcamp 2018 is here

2018 is the seventh year for THWACKcamp™, and once again we’ll be live October 17 – 18 with packed session tracks covering everything from network monitoring and management, to change control, application management, storage, cloud and DevOps, security, automation, virtualization, mapping, logging, and more.

Register for online sessions.

Home > Success Center > Network Performance Monitor (NPM) > NPM - Knowledgebase Articles > WMI polling causes the Windows Security Event log to fill up

WMI polling causes the Windows Security Event log to fill up

Table of contents
Created by Tiarnan Stacke, last modified by MindTouch on Jun 23, 2016

Views: 1,600 Votes: 0 Revisions: 6

Overview

When polling Windows Servers via WMI, the Windows Security Event Log generates a lot of logs.

Environment

  • All NPM versions
  • All SAM versions

Detail

The cause of this is that Auditing is enabled on the target node. For information on how to configure this, please refer to Microsoft Documentation: Configuring Audit Policies.

When left on default settings, each Node Poll will generate a Logon/Logout event.

With SAM Polling, each component monitor within a template functions independently from the others. With Windows auditing enabled, each component monitor will generate one successful login and one successful logout event in the security event log each time it is polled.

 

Last modified

Tags

Classifications

Public