SCOM Audit Collect Services DB Performance

Posted on 2014-08-27
Last Modified: 2014-09-09
Windows Server 2012 R2

SCOM 2012 using Audit Collection Services

SQL Server 2012 for the OpsMngr Database Collector

All on the same 64bit box with two processors @ 2.7Ghz and 16GB RAM

I have just set up ACS for the first time and learning about it.

Right now I have three servers with the Audit Collection Forwarding Service Agent installed on each of them. So they all are forwarding security audits to my Collector SQL DB.

My problem is that with only three forwarders sending events to my collector I am still seeing the "DB Backoff Threshold" and "Disconnect Threshold" maxed out. Which is causing one of my three forwarding agents to be dropped every now and again.

If you observe the screen shots I have attached you will notice that this is very odd problem to have with only three forwarding agents. Especially with such low events per second. The most traffic there has been was about 500 events according to the report shown in screenshot (Hourly_Event_Report)

So why am I having this issue when the DB_Queue (screenshot shown) is flat zero! There should be no reason for my thresholds to be maxing out and staying maxed out especially.

Please help!
Question by:ryanmaves

    Accepted Solution

    To answer my own question, it's actually a misunderstanding of how SCOM displays information graphically.

    I was confused why my thresholds were maxed out with only one or two forwarding agents sending very little events to be logged.

    Turns out these thresholds have a line across whatever the "set" threshold is within the registry. In other words, the line represented in my backoff threshold and disconnect threshold makes it look like my thresholds are being maxed out the entire time but it is actually only representing the value of my max threshold.

    Really silly for Microsoft not to make an obvious disclaimer in their book (which I read up and down on ACS chapters about this trying to find an answer).

    So the issue with some of my forwarders dropping off is actually not because of SCOM thresholds exceeding but instead because those forwarders are Server2008 and the WMI on Server2008 is very buggy. So my focus has been on SCOM when the problem is with my individual forwarders.

    whew! Hope this helps someone else that is new to SCOM not be so confused by the thresholds.


    Author Closing Comment

    Wish there was more support for SCOM ACS somewhere on the web. Looks pretty dry out there in the www for this topic unfortunately not a lot of people talking.

    Write Comment

    Please enter a first name

    Please enter a last name

    We will never share this with anyone.

    Featured Post

    IT, Stop Being Called Into Every Meeting

    Highfive is so simple that setting up every meeting room takes just minutes and every employee will be able to start or join a call from any room with ease. Never be called into a meeting just to get it started again. This is how video conferencing should work!

    Sometimes drives fill up and we don't know why.  If you don't understand the best way to use the tools available, you may end up being stumped as to why your drive says it's not full when you have no space left!  Here's how you can find out...
    The Delta outage: 650 cancelled flights, more than 1200 delayed flights, thousands of frustrated customers, tens of millions of dollars in damages – plus untold reputational damage to one of the world’s most trusted airlines. All due to a catastroph…
    This tutorial will walk an individual through the process of configuring basic necessities in order to use the 2010 version of Data Protection Manager. These include storage, agents, and protection jobs. Launch Data Protection Manager from the deskt…
    Viewers will learn how to use the SELECT statement in SQL to return specific rows and columns, with various degrees of sorting and limits in place.

    759 members asked questions and received personalized solutions in the past 7 days.

    Join the community of 500,000 technology professionals and ask your questions.

    Join & Ask a Question

    Need Help in Real-Time?

    Connect with top rated Experts

    10 Experts available now in Live!

    Get 1:1 Help Now