Monitor unlimited number of servers
Filter log events
Create email and web-based reports

Direct access to Microsoft articles
Customized keywords for major search engines
Access to premium content

Event ID: 1162 Source: InsightHostAgents

Threshold Insight Agent: Rising Threshold Passed. SNMP MIB Variable . has value 50 >= 50. Severity: Invalid; Description: None. Refer to the compaq MIB for a definition of the variable
For a MIB variable with 12 numbers, take off the last number and you get: This is the OID (OBJECT IDENTIFIER) which refers you to the OBJECT-TYPE = cpqHoCpuUtilFiveMin which states the CPU utilization as a percentage of the theoretical maximum changed during the last five minutes. This caused the Threshold Insight Agent: Rising Thresholds to be passed for CPU #1. #1 is the number we removed to get a 12 number MIB, but it identifies which CPU.

In order to keep this from happening: Upgrade the CPU or add RAM to handle current processing loads, and/or reduce processing or change the threshold limit. The value in this example is set at 50%.

See also compaq White Paper (page 10).

Windows Event Log Analysis Splunk App

Build a great reporting interface using Splunk, one of the leaders in the Security Information and Event Management (SIEM) field, linking the collected Windows events to



Cisco ASA Log Analyzer Splunk App

Obtain enhanced visibility into Cisco ASA firewall logs using the free Firegen for Cisco ASA Splunk App. Take advantage of dashboards built to optimize the threat analysis process.