Processing Backlogged Events Taking a Long Time_Security Logs

Hello,

Observing below alert frequently in my SCOM 2012R2 from different servers due to large number of  the security logs. Can any one help me the exact solution to resolve this alert? Any possibility of increase the threshold interval? It can be gone by clearing the logs in the server but looking for a permanent solution.

Processing Backlogged Events Taking a Long Time
Alert Description

The Windows Event Log Provider monitoring the Security Event Log is 6781 minutes behind in processing
events. This can occur when the provider is restarted after being offline for some time, or there
are too many events to be handled by the workflow.


August 30th, 2015 1:53pm

There are sereval reason for receiving this errro
1. Computer where the agent is installed may be low on resources. Check the resources on the computer - memory,CPU.
2. The computer is logging several events per minute. Check the event log to see if there is an application or event logging these events.
3. If the health service was stopped on the computer then when it is started, it has to process all the events from the last one it processed.
Roger
Free Windows Admin Tool Kit Click here and download it now
August 30th, 2015 10:37pm

There are sereval reason for receiving this errro
1. Computer where the agent is installed may be low on resources. Check the resources on the computer - memory,CPU.
2. The computer is logging several events per minute. Check the event log to see if there is an application or event logging these events.
3. If the health service was stopped on the computer then when it is started, it has to process all the events from the last one it processed.
Roger
August 31st, 2015 2:36am

There are sereval reason for receiving this errro
1. Computer where the agent is installed may be low on resources. Check the resources on the computer - memory,CPU.
2. The computer is logging several events per minute. Check the event log to see if there is an application or event logging these events.
3. If the health service was stopped on the computer then when it is started, it has to process all the events from the last one it processed.
Roger
Free Windows Admin Tool Kit Click here and download it now
August 31st, 2015 2:36am

This topic is archived. No further replies will be accepted.

Other recent topics Other recent topics