Submit a ticketCall us

AnnouncementsChange Is Inevitable

Get valuable help when it comes to tracking and monitoring changes. SolarWinds® Server Configuration Monitor (SCM) is designed to help you: detect, track, and receive alerts when changes occur, correlate system performance against configuration changes, compare server and application configuration against custom baselines, and verify application and system changes.

Learn more.

Home > Success Center > Network Performance Monitor (NPM) > NPM - Knowledgebase Articles > WMI polling causes the Windows Security Event log to fill up

WMI polling causes the Windows Security Event log to fill up

Table of contents
Created by Tiarnan Stacke, last modified by MindTouch on Jun 23, 2016

Views: 1,610 Votes: 0 Revisions: 6

Overview

When polling Windows Servers via WMI, the Windows Security Event Log generates a lot of logs.

Environment

  • All NPM versions
  • All SAM versions

Detail

The cause of this is that Auditing is enabled on the target node. For information on how to configure this, please refer to Microsoft Documentation: Configuring Audit Policies.

When left on default settings, each Node Poll will generate a Logon/Logout event.

With SAM Polling, each component monitor within a template functions independently from the others. With Windows auditing enabled, each component monitor will generate one successful login and one successful logout event in the security event log each time it is polled.

 

Last modified

Tags

Classifications

Public