DX Unified Infrastructure Management

  • 1.  NTEVL probe not working as per the expectations

    Posted Oct 10, 2016 09:50 AM

    Hi Guys,

     

    We have configured ntevl probe in our environment for capturing the event ID (Example) 4732 and 4733 which gets generated when one or more user being added\deleted into\from the Admin group.

     

    What is happening here is if Windows team is adding or deleting more than one user on the same time stamp, we are only recieving single alert however when i checked the status bar of the ntevl configuration pop up window, i can see the three logs. I have worked on SCOM also but never face such issue. Now we have migrated from SCOM to CA Tool but i don't know if there is any workaround except removing the suppression. Practically we can't remove the suppression from NAS just for capturing few event id's related alerts because this will flood our console and multiple tickets for single issue. So this is not possible.

     

    Second, Ntevl probe is capturing the information from the details tab and not from the general tab. This is also causing problem because in details tab we don't see required information. We need three entries in the message description:

    1) Who is adding\deleting user

    2) User ID which has been added\deleted

    3) Group name in which the ID has been added\deleted

     

    Now, in details tab we don't have number 2 information in readable format and we don't know which user id has been added or deleted. This information is also important to capture otherwise not use to enable this kind of monitoring.

     

    I don't know if someone has ever noticed or face this problem or not but I need some workaround in this as quick as possible and will appreciate if someone can help me in fixing this issue.

     

    Thanks & Regards,

    Imran Khan



  • 2.  Re: NTEVL probe not working as per the expectations

    Broadcom Employee
    Posted Oct 10, 2016 10:43 AM

    I reviewed the documentation and the probe and I do not see how you could do what you are wanting to with the current probe.

    This would look to be an enhancement request that needs to be submitted on the idea wall for product management to consider.

     

    Maybe some others have an idea of a work around but needing three variables filled to capture the information you need I am not sure can be done if any of the information and length changes with each line.



  • 3.  Re: NTEVL probe not working as per the expectations

    Broadcom Employee
    Posted Oct 12, 2016 12:41 PM

    How about setting the suppression key at probe level itself ?



  • 4.  Re: NTEVL probe not working as per the expectations

    Posted Oct 13, 2016 04:59 AM

    Hi Sinab,

     

    Setting the suppression key at probe level will make more manual work. Let it be with NAS.



  • 5.  Re: NTEVL probe not working as per the expectations

    Posted Oct 20, 2016 03:45 AM

    Could you pls share the configuration screenshot



  • 6.  Re: NTEVL probe not working as per the expectations

    Posted Oct 20, 2016 04:09 AM

    Hi Issac,

     

    Kindly specify, Which tab / part of the configuration you want to see?

     

    Regards,

    Imran