SOLVED

Some Windows events are not being analyzed

%3CLINGO-SUB%20id%3D%22lingo-sub-2211230%22%20slang%3D%22en-US%22%3ESome%20Windows%20events%20are%20not%20being%20analyzed%3C%2FLINGO-SUB%3E%3CLINGO-BODY%20id%3D%22lingo-body-2211230%22%20slang%3D%22en-US%22%3E%3CP%3EWe%20are%20seeing%20%22Some%20Windows%20events%20are%20not%20being%20analyzed%22%20health%20alert%20getting%20generated%20and%20auto-closed%20in%20our%20tenant.%20Would%20like%20to%20understand%20what%20the%20threshold%20is%20for%20windows%20events%20passing%20a%20sensor.%20The%20Microsoft%20documentation%20available%20here%20(%3CA%20href%3D%22https%3A%2F%2Fdocs.microsoft.com%2Fen-us%2Fdefender-for-identity%2Fhealth-alerts%23some-windows-events-are-not-being-analyzed%22%20target%3D%22_blank%22%20rel%3D%22noopener%20noreferrer%22%3Ehttps%3A%2F%2Fdocs.microsoft.com%2Fen-us%2Fdefender-for-identity%2Fhealth-alerts%23some-windows-events-are-not-being-analyzed%3C%2FA%3E)%20does%20not%20provide%20a%20clue.%20Hoping%20to%20get%20an%20answer%20soon!%26nbsp%3B%3CA%20href%3D%22https%3A%2F%2Ftechcommunity.microsoft.com%2Ft5%2Fuser%2Fviewprofilepage%2Fuser-id%2F106935%22%20target%3D%22_blank%22%3E%40Eli%20Ofek%3C%2FA%3E%26nbsp%3BAny%20ideas%20are%20appreciated!%3C%2FP%3E%3C%2FLINGO-BODY%3E
Occasional Contributor

We are seeing "Some Windows events are not being analyzed" health alert getting generated and auto-closed in our tenant. Would like to understand what the threshold is for windows events passing a sensor. The Microsoft documentation available here (https://docs.microsoft.com/en-us/defender-for-identity/health-alerts#some-windows-events-are-not-bei...) does not provide a clue. Hoping to get an answer soon! @Eli Ofek Any ideas are appreciated!

2 Replies
best response confirmed by mesaqee (Occasional Contributor)
Solution

@mesaqee For now, the alert trigger is a certain percentage of events loss.

The number is not really that important also because it can change without notice, we see it as implementation detail. We are also experimenting with ML code that (if eventually works well) will alert for each customer in a different way.

 

The main take from this alert is that you are losing detection data, and that's need to be fixed.

The main thing to check is that your spec is in line with what was estimated in the sizing tool, if it's not, fix it first... them make sure you are optimized  correctly as described in the docs (power plan, Hyper threading, VM resource reservation etc). Once you have covered all those "basics", go with a support ticket. for some cases additional resources might be needs on top of the sizing tool estimation due to traffic/data mix. The support engineer also has additional telemetry that can be checked from the backend that might give more clues...

Thanks for a quick response! Will check what sizing tool has to say further around this.