mdatp_audisp_plugin

%3CLINGO-SUB%20id%3D%22lingo-sub-2342840%22%20slang%3D%22en-US%22%3Emdatp_audisp_plugin%3C%2FLINGO-SUB%3E%3CLINGO-BODY%20id%3D%22lingo-body-2342840%22%20slang%3D%22en-US%22%3E%3CP%3EI%20was%20wondering%20if%20anyone%20knows%20what%26nbsp%3B%2Fopt%2Fmicrosoft%2Fmdatp%2Fsbin%2Fmdatp_audisp_plugin%26nbsp%3B%20is%20used%20for%20on%20RHEL.%3C%2FP%3E%3CP%3E%26nbsp%3B%3C%2FP%3E%3CP%3EI've%20noticed%20it%20can%20consume%20allot%20of%20resources%20in%20some%20cases%20and%20hoping%20to%20find%20some%20documentation%20on%20this%20Microsoft%20Defender%20RHEL%20plugin.%3C%2FP%3E%3C%2FLINGO-BODY%3E%3CLINGO-SUB%20id%3D%22lingo-sub-2568347%22%20slang%3D%22en-US%22%3ERe%3A%20mdatp_audisp_plugin%3C%2FLINGO-SUB%3E%3CLINGO-BODY%20id%3D%22lingo-body-2568347%22%20slang%3D%22en-US%22%3E%3CP%3E%3CA%20href%3D%22https%3A%2F%2Ftechcommunity.microsoft.com%2Ft5%2Fuser%2Fviewprofilepage%2Fuser-id%2F955509%22%20target%3D%22_blank%22%3E%40roger_jr%3C%2FA%3E%26nbsp%3B%20%3CSPAN%3EIf%20you%20find%20out%20the%20answer%20to%20this%20query%2C%20please%20let%20me%20know%3C%2FSPAN%3E%3C%2FP%3E%3C%2FLINGO-BODY%3E%3CLINGO-SUB%20id%3D%22lingo-sub-2634730%22%20slang%3D%22en-US%22%3ERe%3A%20mdatp_audisp_plugin%3C%2FLINGO-SUB%3E%3CLINGO-BODY%20id%3D%22lingo-body-2634730%22%20slang%3D%22en-US%22%3ESure%2C%20will%20open%20a%20ticket%20with%20Microsoft.%20Thanks%20Roger%3CBR%20%2F%3E%3C%2FLINGO-BODY%3E
Occasional Contributor

I was wondering if anyone knows what /opt/microsoft/mdatp/sbin/mdatp_audisp_plugin  is used for on RHEL.

 

I've noticed it can consume allot of resources in some cases and hoping to find some documentation on this Microsoft Defender RHEL plugin.

4 Replies

@roger_jr  If you find out the answer to this query, please let me know

@kalyan190 mdatp_audisp_plugin
The issue is, mdatp_audisp_plugin has a bug which the plugin might ingest unnecessary logs from audit logs.

My suggestion is open a ticket with Microsoft TAC and they can provide a work around.



Sure, will open a ticket with Microsoft. Thanks Roger

@kalyan190 Hi Kalyan, were you able to get any workaround for the issue. 

We are currently getting similar issue in Ubuntu 16.04 where below errors  in /var/log/syslog are quickly filling up the hard drive. 

Oct 8 00:35:15 hatchdpdeceallocator01 audispd: Starting reconfigure
Oct 8 00:35:15 hatchdpdeceallocator01 audispd: priority_boost_parser called with: 4
Oct 8 00:35:15 hatchdpdeceallocator01 audispd: max_restarts_parser called with: 10