<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: User ID causing heavy load on domain controllers in General Topics</title>
    <link>https://live.paloaltonetworks.com/t5/general-topics/user-id-causing-heavy-load-on-domain-controllers/m-p/65195#M38953</link>
    <description>&lt;P&gt;Yes, I started using the firewall agent after the standalone agent stopped communicating with the PA. For some reason the PA&amp;nbsp;doesn't appear in the list, and I have tried re-installing it&lt;/P&gt;</description>
    <pubDate>Mon, 28 Sep 2015 15:10:29 GMT</pubDate>
    <dc:creator>Maxstr</dc:creator>
    <dc:date>2015-09-28T15:10:29Z</dc:date>
    <item>
      <title>User ID causing heavy load on domain controllers</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/user-id-causing-heavy-load-on-domain-controllers/m-p/65191#M38950</link>
      <description>&lt;P&gt;My domain controller is&amp;nbsp;seeing very high CPU and RAM usage caused by the event log settings (as required by User ID). It's currently at 427,000 events and it's using up about 60% CPU.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Is this normal?&lt;/P&gt;</description>
      <pubDate>Mon, 28 Sep 2015 14:23:25 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/user-id-causing-heavy-load-on-domain-controllers/m-p/65191#M38950</guid>
      <dc:creator>Maxstr</dc:creator>
      <dc:date>2015-09-28T14:23:25Z</dc:date>
    </item>
    <item>
      <title>Re: User ID causing heavy load on domain controllers</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/user-id-causing-heavy-load-on-domain-controllers/m-p/65193#M38951</link>
      <description>&lt;P&gt;Eventually yes,&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;Number of logs per seconds (not just logon events but all events) and resource constraints (CPU+RAM) on your domain controller may explain this.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;I suppose you are using FW embdded agent, Windows agent works differently and shall put less pressure on your domain controller.&lt;/P&gt;</description>
      <pubDate>Mon, 28 Sep 2015 14:48:17 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/user-id-causing-heavy-load-on-domain-controllers/m-p/65193#M38951</guid>
      <dc:creator>cpainchaud</dc:creator>
      <dc:date>2015-09-28T14:48:17Z</dc:date>
    </item>
    <item>
      <title>Re: User ID causing heavy load on domain controllers</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/user-id-causing-heavy-load-on-domain-controllers/m-p/65195#M38953</link>
      <description>&lt;P&gt;Yes, I started using the firewall agent after the standalone agent stopped communicating with the PA. For some reason the PA&amp;nbsp;doesn't appear in the list, and I have tried re-installing it&lt;/P&gt;</description>
      <pubDate>Mon, 28 Sep 2015 15:10:29 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/user-id-causing-heavy-load-on-domain-controllers/m-p/65195#M38953</guid>
      <dc:creator>Maxstr</dc:creator>
      <dc:date>2015-09-28T15:10:29Z</dc:date>
    </item>
    <item>
      <title>Re: User ID causing heavy load on domain controllers</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/user-id-causing-heavy-load-on-domain-controllers/m-p/65196#M38954</link>
      <description>&lt;P&gt;do you have stats of logs/second on your Domain Controller ?&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;can you describe its hardware ?&lt;/P&gt;</description>
      <pubDate>Mon, 28 Sep 2015 15:12:30 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/user-id-causing-heavy-load-on-domain-controllers/m-p/65196#M38954</guid>
      <dc:creator>cpainchaud</dc:creator>
      <dc:date>2015-09-28T15:12:30Z</dc:date>
    </item>
    <item>
      <title>Re: User ID causing heavy load on domain controllers</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/user-id-causing-heavy-load-on-domain-controllers/m-p/65199#M38957</link>
      <description>&lt;P&gt;It is a virtual machine, Win2008 R2, with 1vCPU and 8 GB ram. I was hoping not to throw more resources at it, especially since there are a total of 4 domain controllers. The other 3 do not seem to have this issue with the amount of logs, which leads me to believe there may be&amp;nbsp;a configuration issue&lt;/P&gt;</description>
      <pubDate>Mon, 28 Sep 2015 15:58:27 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/user-id-causing-heavy-load-on-domain-controllers/m-p/65199#M38957</guid>
      <dc:creator>Maxstr</dc:creator>
      <dc:date>2015-09-28T15:58:27Z</dc:date>
    </item>
    <item>
      <title>Re: User ID causing heavy load on domain controllers</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/user-id-causing-heavy-load-on-domain-controllers/m-p/65200#M38958</link>
      <description>&lt;P&gt;It's common to see some DC take a lot more load than others. many factors can explain that.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;anyway, you may want to add at least 1vCPU to your DC VM. if it's really busy then it's going to help it.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;but you are right, you should keep investigating what is being logged there, and the volume/hour&lt;/P&gt;</description>
      <pubDate>Mon, 28 Sep 2015 16:01:05 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/user-id-causing-heavy-load-on-domain-controllers/m-p/65200#M38958</guid>
      <dc:creator>cpainchaud</dc:creator>
      <dc:date>2015-09-28T16:01:05Z</dc:date>
    </item>
    <item>
      <title>Re: User ID causing heavy load on domain controllers</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/user-id-causing-heavy-load-on-domain-controllers/m-p/65207#M38960</link>
      <description>&lt;P&gt;&lt;FONT face="courier new,courier" size="2"&gt;Hi Max,&lt;/FONT&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&lt;FONT face="courier new,courier" size="2"&gt;&lt;SPAN&gt;Agentless User-ID utilizes WMI to connect directly from the Palo Alto Networks firewall to an AD server (or servers) and obtain user IP information. &lt;/SPAN&gt;&lt;/FONT&gt;&lt;BR /&gt;&lt;FONT face="courier new,courier" size="2"&gt;&lt;SPAN&gt;On some older servers (for example, Windows 2003), the memory allocation for WMI may be constrained, which then prevents the system from parsing the server security logs.&lt;/SPAN&gt;&lt;/FONT&gt;&lt;BR /&gt;&lt;FONT face="courier new,courier" size="2"&gt;&lt;SPAN&gt;Do take a look at the below article :&lt;/SPAN&gt;&lt;/FONT&gt;&lt;BR /&gt;&lt;FONT face="courier new,courier" size="2"&gt;&lt;A href="https://live.paloaltonetworks.com/t5/Management-Articles/Agentless-User-ID-Error-quot-failed-to-parse-security-log-buf/ta-p/58815" target="_blank"&gt;https://live.paloaltonetworks.com/t5/Management-Articles/Agentless-User-ID-Error-quot-failed-to-parse-security-log-buf/ta-p/58815&lt;/A&gt;&lt;/FONT&gt;&lt;BR /&gt;&lt;BR /&gt;&lt;FONT face="courier new,courier" size="2"&gt;&lt;SPAN&gt;You also have the option to use the User-ID Agent, which is a software application that runs on your DCs if agentless User-ID is not feasible for your network&lt;/SPAN&gt;&lt;/FONT&gt;&lt;/P&gt;&lt;P&gt;&lt;BR /&gt;&lt;FONT face="courier new,courier" size="2"&gt;&lt;SPAN&gt;You can install the agent directly on domain controller or another server where security logs will be read from. &lt;/SPAN&gt;&lt;/FONT&gt;&lt;BR /&gt;&lt;FONT face="courier new,courier" size="2"&gt;&lt;SPAN&gt;This is much lesser resource intensive for both the PA firewall and the Domain Controller, as it uses Microsoft RPC- which is native to Microsoft unlike WMI.&lt;/SPAN&gt;&lt;/FONT&gt;&lt;BR /&gt;&lt;BR /&gt;&lt;FONT face="courier new,courier" size="2"&gt;&lt;SPAN&gt;I was going through a Microsoft sites and came across issues being reported with "wmiprvse.exe" service in Windows server 2003 and ntdll.dll service when an external service tried to interact with these services. There is hot fix released to address wmiprvse service causing high CPU usage. &lt;/SPAN&gt;&lt;/FONT&gt;&lt;BR /&gt;&lt;FONT face="courier new,courier" size="2"&gt;&lt;SPAN&gt;The link for the fix is below: &lt;/SPAN&gt;&lt;/FONT&gt;&lt;BR /&gt;&lt;FONT face="courier new,courier" size="2"&gt;&lt;A href="http://www.microsoft.com/en-us/download/details.aspx?displaylang=en&amp;amp;id=1157" target="_blank"&gt;http://www.microsoft.com/en-us/download/details.aspx?displaylang=en&amp;amp;id=1157&lt;/A&gt; &lt;/FONT&gt;&lt;BR /&gt;&lt;BR /&gt;&lt;FONT face="courier new,courier" size="2"&gt;&lt;SPAN&gt;For the ntdll.dll service, there have been reported crashes of this service in windows 2008 R2 server and necessary steps and links to the documents addressing this issue has been provided in the following link: &lt;/SPAN&gt;&lt;/FONT&gt;&lt;BR /&gt;&lt;FONT face="courier new,courier" size="2"&gt;&lt;A href="http://social.technet.microsoft.com/Forums/windowsserver/en-US/164c5cc5-810a-47f5-97ba-91fa7982c123/ntdlldll-keeps-crashing-on-windows-2008-r2" target="_blank"&gt;http://social.technet.microsoft.com/Forums/windowsserver/en-US/164c5cc5-810a-47f5-97ba-91fa7982c123/ntdlldll-keeps-crashing-on-windows-2008-r2&lt;/A&gt; &lt;/FONT&gt;&lt;BR /&gt;&lt;FONT face="courier new,courier" size="2"&gt;&lt;SPAN&gt;There have been issues reported with these processes. &amp;nbsp;Check for any errors related to ntdll.dll service in the windows 2008 server ?&lt;/SPAN&gt;&lt;/FONT&gt;&lt;BR /&gt;&lt;BR /&gt;&lt;FONT face="courier new,courier"&gt;Thanks and Regards,&lt;/FONT&gt;&lt;/P&gt;&lt;P&gt;&lt;FONT face="courier new,courier"&gt;Kunal&lt;/FONT&gt;&lt;/P&gt;</description>
      <pubDate>Mon, 28 Sep 2015 18:41:46 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/user-id-causing-heavy-load-on-domain-controllers/m-p/65207#M38960</guid>
      <dc:creator>kbiswas</dc:creator>
      <dc:date>2015-09-28T18:41:46Z</dc:date>
    </item>
  </channel>
</rss>

