Skip to content
New issue

Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.

By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.

Already on GitHub? Sign in to your account

Agent event queue is flooded. Check the agent configuration. #879

Open
cortera opened this issue Apr 30, 2024 · 0 comments
Open

Agent event queue is flooded. Check the agent configuration. #879

cortera opened this issue Apr 30, 2024 · 0 comments

Comments

@cortera
Copy link

cortera commented Apr 30, 2024

Hi everyone,

I recently implemented Wazuh in our company, with approximately 180 active agents, including both Mac and Windows devices. The agents were enrolled via Intune Azure Active Directory.

I'm encountering an overwhelming alert: "Agent event queue is flooded. Check the agent configuration." It appears that most of these alerts are related to application and system errors.

It's worth noting that all the agents triggering these alerts are Windows-based; no Mac agents have reported any similar issues.

I've reviewed the documentation regarding increasing the EPS (Events Per Second). Is there a way to adjust the EPS specifically for Windows agents from the Wazuh server and then push these updates to the agents?

Alternatively, would it be possible to disable application logs and Windows health-checks logs? Any suggestions would be appreciated.

Thank you for your assistance.

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment
Labels
None yet
Projects
None yet
Development

No branches or pull requests

1 participant