- Access exclusive content
- Connect with peers
- Share your expertise
- Find support resources
04-21-2014 01:46 AM
Hello,
Configuration on my Palo Alto is causing AD to overload and crash because of the WMI query load. When i checked AD for the logs, i saw that its getting the logs in UTC timezone. This is causing an issue because im in GMT+3 timezone. I also have a Palo Alto in GMT+6 timezone. Once there's log traffic is initiated, PA is sending 3 hours of logs locally, which makes my other location to send 6 hours of log. Considering this log query, when there's a log traffic between AD and Palo Alto, its asking for all logs even if the time is just an hour later plus the 2to5 hour logs even it has already acquired. This makes me think that the log traffic is not incremental. I was wondering if there's a solution that i can implement to avoid my AD to overload with this traffic or am i doing something wrong with the configuration. I'd appreciate if you could help me with this.
PA version is 5.0.10
Below is the AD log;
ProviderInfo for GroupOperationId = 4775374; Operation = Provider::ExecQuery - MS_NT_EVENTLOG_PROVIDER : select __RELPATH, EventIdentifier, InsertionStrings, TimeGenerated from Win32_NTLogEvent where (((((((((EventIdentifier = 4624 OR EventIdentifier = 4768) OR EventIdentifier = 4769) OR EventIdentifier = 4770) OR EventIdentifier = 540) OR EventIdentifier = 672) OR EventIdentifier = 673) OR EventIdentifier = 674) AND LogFile = "Security") AND TimeGenerated > "20140421070506.988000+000"); HostID = 4284; ProviderName = MS_NT_EVENTLOG_PROVIDER; ProviderGuid = {FD4F53E0-65DC-11d1-AB64-00C04FD9159E}; Path = %systemroot%\system32\wbem\ntevt.dll
Click Accept as Solution to acknowledge that the answer to your question has been provided.
The button appears next to the replies on topics you’ve started. The member who gave the solution and all future visitors to this topic will appreciate it!
These simple actions take just seconds of your time, but go a long way in showing appreciation for community members and the LIVEcommunity as a whole!
The LIVEcommunity thanks you for your participation!