How do we verify the results received on the Compass client?
The Compass client runs a WMI query and collects data from the performance counters periodically to determine the status of LSASS. Note that not all of this information is logged, but the results are stored in the following folder location:
\Program Files (x86)\ENow\Mailscape Agent\Cache\NetworkAgentMessage.xml
To capture the LSASS usage from the DC or RODC manually, run the following in PowerShell on that server:
Get-Counter -Counter "\Process(lsass)\% Processor Time" -SampleInterval 2 -MaxSamples 4 | Select-Object @{Name = "CPUUsage"; Expression = {$_.CounterSamples[0].CookedValue}}
Based on how Compass functions, the status of the test is dependent upon the LSASS usage and the threshold set in the console.
Below is sample output. Values will differ in your environment.
PS C:\Users\Administrator> Get-Counter -Counter "\Process(lsass)\% Processor Time" -SampleInterval 2 -MaxSamples 4 | Select-Object @{Name = "CPUUsage"; Expression = {$_.CounterSamples[0].CookedValue}}
CPUUsage
--------
0
0.772521587590451
0
0
Comments
0 comments
Article is closed for comments.