The sensor I set up is EventLog sensor with a filter of EventID = 1. Generally, this sensor has 0.02 events per second. But I observed the following:
5/27/2013 9:50:00 AM − 9:55:00 AM 5 # 0.02 #/s 0 % 100 % 5/27/2013 9:45:00 AM − 9:50:00 AM 939,094,499 # 3,130,419 #/s 0 % 100 % 5/27/2013 9:40:00 AM − 9:45:00 AM 1,100,501,365 # 3,668,338 #/s 0 % 100 % 5/27/2013 9:35:00 AM − 9:40:00 AM 1,100,501,365 # 3,668,338 #/s 0 % 100 % 5/27/2013 9:30:00 AM − 9:35:00 AM 1,100,501,365 # 3,668,338 #/s 5/27/2013 9:25:00 AM − 9:30:00 AM 54,364,772 # 181,216 #/s 0 % 100 % 5/27/2013 9:20:00 AM − 9:25:00 AM 5 # 0.02 #/s 0 % 100 %
In 5 minutes, it is not possible to have 1,100,501,365 Events (EventID==1). I checked the other events in the same time period but they are just a few.
Do you have any idea?
Add comment