AD WMI overload issue

cancel
Showing results for 
Show  only  | Search instead for 
Did you mean: 
Announcements
Please sign in to see details of an important advisory in our Customer Advisories area.

AD WMI overload issue

Not applicable

Hello,

Configuration on my Palo Alto is causing AD to overload and crash because of the WMI query load. When i checked AD for the logs, i saw that its getting the logs in UTC timezone. This is causing an issue because im in GMT+3 timezone. I also have a Palo Alto in GMT+6 timezone. Once there's log traffic is initiated, PA is sending 3 hours of logs locally, which makes my other location to send 6 hours of log. Considering this log query, when there's a log traffic between AD and Palo Alto, its asking for all logs even if the time is just an hour later plus the 2to5 hour logs even it has already acquired. This makes me think that the log traffic is not incremental. I was wondering if there's a solution that i can implement to avoid my AD to overload with this traffic or am i doing something wrong with the configuration. I'd appreciate if you could help me with this.

PA version is 5.0.10

Below is the AD log;

ProviderInfo for GroupOperationId = 4775374; Operation = Provider::ExecQuery - MS_NT_EVENTLOG_PROVIDER : select __RELPATH, EventIdentifier, InsertionStrings, TimeGenerated from Win32_NTLogEvent where (((((((((EventIdentifier = 4624 OR EventIdentifier = 4768) OR EventIdentifier = 4769) OR EventIdentifier = 4770) OR EventIdentifier = 540) OR EventIdentifier = 672) OR EventIdentifier = 673) OR EventIdentifier = 674) AND LogFile = "Security") AND TimeGenerated > "20140421070506.988000+000"); HostID = 4284; ProviderName = MS_NT_EVENTLOG_PROVIDER; ProviderGuid = {FD4F53E0-65DC-11d1-AB64-00C04FD9159E}; Path = %systemroot%\system32\wbem\ntevt.dll

0 REPLIES 0
  • 1730 Views
  • 0 replies
  • 0 Likes
Like what you see?

Show your appreciation!

Click Like if a post is helpful to you or if you just want to show your support.

Click Accept as Solution to acknowledge that the answer to your question has been provided.

The button appears next to the replies on topics you’ve started. The member who gave the solution and all future visitors to this topic will appreciate it!

These simple actions take just seconds of your time, but go a long way in showing appreciation for community members and the LIVEcommunity as a whole!

The LIVEcommunity thanks you for your participation!