Skip to content

Instantly share code, notes, and snippets.

@mazoutte

mazoutte/windows.yml

Last active Apr 28, 2020
Embed
What would you like to do?
Metricbeat 7.4.2 - Active Directory - All NTDS perfmon counters 2012R2/+ - DNS examples
### Metricbeat 7.6.2 ###
- module: windows
metricsets: ["perfmon"]
period: 10s
perfmon.ignore_non_existent_counters: true
perfmon.group_measurements_by_instance: true
perfmon.counters:
# NTDS
- instance_label: "instance.name"
instance_name: "NTDS"
measurement_label: "ntds.ab.anr.sec"
query: '\DirectoryServices(NTDS)\AB ANR/sec'
- instance_label: "instance.name"
instance_name: "NTDS"
measurement_label: "ntds.ab.browses.sec"
query: '\DirectoryServices(NTDS)\AB Browses/sec'
- instance_label: "instance.name"
instance_name: "NTDS"
measurement_label: "ntds.ab.client.sessions"
query: '\DirectoryServices(NTDS)\AB Client Sessions'
- instance_label: "instance.name"
instance_name: "NTDS"
measurement_label: "ntds.ab.matches.sec"
query: '\DirectoryServices(NTDS)\AB Matches/sec'
- instance_label: "instance.name"
instance_name: "NTDS"
measurement_label: "ntds.ab.prop.reads.sec"
query: '\DirectoryServices(NTDS)\AB Property Reads/sec'
- instance_label: "instance.name"
instance_name: "NTDS"
measurement_label: "ntds.ab.proxy.lookups.sec"
query: '\DirectoryServices(NTDS)\AB Proxy Lookups/sec'
- instance_label: "instance.name"
instance_name: "NTDS"
measurement_label: "ntds.ab.searches.sec"
query: '\DirectoryServices(NTDS)\AB Searches/sec'
- instance_label: "instance.name"
instance_name: "NTDS"
measurement_label: "ntds.approx.highest.dnt"
query: '\DirectoryServices(NTDS)\Approximate highest DNT'
- instance_label: "instance.name"
instance_name: "NTDS"
measurement_label: "ntds.atq.estimated.queue.delay"
query: '\DirectoryServices(NTDS)\ATQ Estimated Queue Delay'
- instance_label: "instance.name"
instance_name: "NTDS"
measurement_label: "ntds.atq.outstanding.queued.requests"
query: '\DirectoryServices(NTDS)\ATQ Outstanding Queued Requests'
- instance_label: "instance.name"
instance_name: "NTDS"
measurement_label: "ntds.atq.request.latency"
query: '\DirectoryServices(NTDS)\ATQ Request Latency'
- instance_label: "instance.name"
instance_name: "NTDS"
measurement_label: "ntds.atq.threads.ldap"
query: '\DirectoryServices(NTDS)\ATQ Threads LDAP'
- instance_label: "instance.name"
instance_name: "NTDS"
measurement_label: "ntds.atq.threads.other"
query: '\DirectoryServices(NTDS)\ATQ Threads Other'
- instance_label: "instance.name"
instance_name: "NTDS"
measurement_label: "ntds.atq.threads.total"
query: '\DirectoryServices(NTDS)\ATQ Threads Total'
- instance_label: "instance.name"
instance_name: "NTDS"
measurement_label: "ntds.db.searches.sec"
query: '\DirectoryServices(NTDS)\Base searches/sec'
- instance_label: "instance.name"
instance_name: "NTDS"
measurement_label: "ntds.db.adds.sec"
query: '\DirectoryServices(NTDS)\Database adds/sec'
- instance_label: "instance.name"
instance_name: "NTDS"
measurement_label: "ntds.db.deletes.sec"
query: '\DirectoryServices(NTDS)\Database deletes/sec'
- instance_label: "instance.name"
instance_name: "NTDS"
measurement_label: "ntds.db.modifys.sec"
query: '\DirectoryServices(NTDS)\Database modifys/sec'
- instance_label: "instance.name"
instance_name: "NTDS"
measurement_label: "ntds.db.recycles.sec"
query: '\DirectoryServices(NTDS)\Database recycles/sec'
- instance_label: "instance.name"
instance_name: "NTDS"
measurement_label: "ntds.digest.binds.sec"
query: '\DirectoryServices(NTDS)\Digest Binds/sec'
- instance_label: "instance.name"
instance_name: "NTDS"
measurement_label: "ntds.dirsync.session.throttling.rate"
query: '\DirectoryServices(NTDS)\DirSync session throttling rate'
- instance_label: "instance.name"
instance_name: "NTDS"
measurement_label: "ntds.dirsync.sessions.inprogress"
query: '\DirectoryServices(NTDS)\DirSync sessions in progress'
- instance_label: "instance.name"
instance_name: "NTDS"
measurement_label: "ntds.dra.highest.usn.committed.highpart"
query: '\DirectoryServices(NTDS)\DRA Highest USN Committed (High part)'
- instance_label: "instance.name"
instance_name: "NTDS"
measurement_label: "ntds.dra.highest.usn.committed.lowpart"
query: '\DirectoryServices(NTDS)\DRA Highest USN Committed (Low part)'
- instance_label: "instance.name"
instance_name: "NTDS"
measurement_label: "ntds.dra.highest.usn.issued.highpart"
query: '\DirectoryServices(NTDS)\DRA Highest USN Issued (High part)'
- instance_label: "instance.name"
instance_name: "NTDS"
measurement_label: "ntds.dra.highest.usn.issued.lowpart"
query: '\DirectoryServices(NTDS)\DRA Highest USN Issued (Low part)'
- instance_label: "instance.name"
instance_name: "NTDS"
measurement_label: "ntds.dra.inbound.bytes.comp.intersite.aftercomp.boot"
query: '\DirectoryServices(NTDS)\DRA Inbound Bytes Compressed (Between Sites, After Compression) Since Boot'
- instance_label: "instance.name"
instance_name: "NTDS"
measurement_label: "ntds.dra.inbound.bytes.comp.intersite.aftercomp.sec"
query: '\DirectoryServices(NTDS)\DRA Inbound Bytes Compressed (Between Sites, After Compression)/sec'
- instance_label: "instance.name"
instance_name: "NTDS"
measurement_label: "ntds.dra.inbound.bytes.comp.intersite.beforecomp.boot"
query: '\DirectoryServices(NTDS)\DRA Inbound Bytes Compressed (Between Sites, Before Compression) Since Boot'
- instance_label: "instance.name"
instance_name: "NTDS"
measurement_label: "ntds.dra.inbound.bytes.comp.intersite.beforecomp.sec"
query: '\DirectoryServices(NTDS)\DRA Inbound Bytes Compressed (Between Sites, Before Compression)/sec'
- instance_label: "instance.name"
instance_name: "NTDS"
measurement_label: "ntds.dra.inbound.bytes.notcomp.intrasite.boot"
query: '\DirectoryServices(NTDS)\DRA Inbound Bytes Not Compressed (Within Site) Since Boot'
- instance_label: "instance.name"
instance_name: "NTDS"
measurement_label: "ntds.dra.inbound.bytes.notcomp.intrasite.sec"
query: '\DirectoryServices(NTDS)\DRA Inbound Bytes Not Compressed (Within Site)/sec'
- instance_label: "instance.name"
instance_name: "NTDS"
measurement_label: "ntds.dra.inbound.bytes.total.boot"
query: '\DirectoryServices(NTDS)\DRA Inbound Bytes Total Since Boot'
- instance_label: "instance.name"
instance_name: "NTDS"
measurement_label: "ntds.dra.inbound.bytes.total.sec"
query: '\DirectoryServices(NTDS)\DRA Inbound Bytes Total/sec'
- instance_label: "instance.name"
instance_name: "NTDS"
measurement_label: "ntds.dra.inbound.fullsync.objectsremaining"
query: '\DirectoryServices(NTDS)\DRA Inbound Full Sync Objects Remaining'
- instance_label: "instance.name"
instance_name: "NTDS"
measurement_label: "ntds.dra.inbound.link.updates.remaining.inpacket"
query: '\DirectoryServices(NTDS)\DRA Inbound Link Value Updates Remaining in Packet'
- instance_label: "instance.name"
instance_name: "NTDS"
measurement_label: "ntds.dra.inbound.object.updates.remaining.inpacket"
query: '\DirectoryServices(NTDS)\DRA Inbound Object Updates Remaining in Packet'
- instance_label: "instance.name"
instance_name: "NTDS"
measurement_label: "ntds.dra.inbound.objects.applied.sec"
query: '\DirectoryServices(NTDS)\DRA Inbound Objects Applied/sec'
- instance_label: "instance.name"
instance_name: "NTDS"
measurement_label: "ntds.dra.inbound.objects.filtered.sec"
query: '\DirectoryServices(NTDS)\DRA Inbound Objects Filtered/sec'
- instance_label: "instance.name"
instance_name: "NTDS"
measurement_label: "ntds.dra.inbound.objects.sec"
query: '\DirectoryServices(NTDS)\DRA Inbound Objects/sec'
- instance_label: "instance.name"
instance_name: "NTDS"
measurement_label: "ntds.dra.inbound.prop.applied.sec"
query: '\DirectoryServices(NTDS)\DRA Inbound Properties Applied/sec'
- instance_label: "instance.name"
instance_name: "NTDS"
measurement_label: "ntds.dra.inbound.prop.filtered.sec"
query: '\DirectoryServices(NTDS)\DRA Inbound Properties Filtered/sec'
- instance_label: "instance.name"
instance_name: "NTDS"
measurement_label: "ntds.dra.inbound.prop.total.sec"
query: '\DirectoryServices(NTDS)\DRA Inbound Properties Total/sec'
- instance_label: "instance.name"
instance_name: "NTDS"
measurement_label: "ntds.dra.inbound.sync.link.deletion.sec"
query: '\DirectoryServices(NTDS)\DRA Inbound Sync Link Deletion/sec'
- instance_label: "instance.name"
instance_name: "NTDS"
measurement_label: "ntds.dra.inbound.total.updates.remaining.inpacket"
query: '\DirectoryServices(NTDS)\DRA Inbound Total Updates Remaining in Packet'
- instance_label: "instance.name"
instance_name: "NTDS"
measurement_label: "ntds.dra.inbound.values.dnonly.sec"
query: '\DirectoryServices(NTDS)\DRA Inbound Values (DNs only)/sec'
- instance_label: "instance.name"
instance_name: "NTDS"
measurement_label: "ntds.dra.inbound.values.total.sec"
query: '\DirectoryServices(NTDS)\DRA Inbound Values Total/sec'
- instance_label: "instance.name"
instance_name: "NTDS"
measurement_label: "ntds.dra.outbound.bytes.comp.intersite.aftercomp.boot"
query: '\DirectoryServices(NTDS)\DRA Outbound Bytes Compressed (Between Sites, After Compression) Since Boot'
- instance_label: "instance.name"
instance_name: "NTDS"
measurement_label: "ntds.dra.outbound.bytes.comp.intersite.aftercomp.sec"
query: '\DirectoryServices(NTDS)\DRA Outbound Bytes Compressed (Between Sites, After Compression)/sec'
- instance_label: "instance.name"
instance_name: "NTDS"
measurement_label: "ntds.dra.outbound.bytes.comp.intersite.beforecomp.boot"
query: '\DirectoryServices(NTDS)\DRA Outbound Bytes Compressed (Between Sites, Before Compression) Since Boot'
- instance_label: "instance.name"
instance_name: "NTDS"
measurement_label: "ntds.dra.outbound.bytes.comp.intersite.beforecomp.sec"
query: '\DirectoryServices(NTDS)\DRA Outbound Bytes Compressed (Between Sites, Before Compression)/sec'
- instance_label: "instance.name"
instance_name: "NTDS"
measurement_label: "ntds.dra.outbound.bytes.notcomp.intrasite.boot"
query: '\DirectoryServices(NTDS)\DRA Outbound Bytes Not Compressed (Within Site) Since Boot'
- instance_label: "instance.name"
instance_name: "NTDS"
measurement_label: "ntds.dra.outbound.bytes.notcomp.intrasite.sec"
query: '\DirectoryServices(NTDS)\DRA Outbound Bytes Not Compressed (Within Site)/sec'
- instance_label: "instance.name"
instance_name: "NTDS"
measurement_label: "ntds.dra.outbound.bytes.total.boot"
query: '\DirectoryServices(NTDS)\DRA Outbound Bytes Total Since Boot'
- instance_label: "instance.name"
instance_name: "NTDS"
measurement_label: "ntds.dra.outbound.bytes.total.sec"
query: '\DirectoryServices(NTDS)\DRA Outbound Bytes Total/sec'
- instance_label: "instance.name"
instance_name: "NTDS"
measurement_label: "ntds.dra.outbound.objects.filtered.sec"
query: '\DirectoryServices(NTDS)\DRA Outbound Objects Filtered/sec'
- instance_label: "instance.name"
instance_name: "NTDS"
measurement_label: "ntds.dra.outbound.objects.sec"
query: '\DirectoryServices(NTDS)\DRA Outbound Objects/sec'
- instance_label: "instance.name"
instance_name: "NTDS"
measurement_label: "ntds.dra.outbound.prop.sec"
query: '\DirectoryServices(NTDS)\DRA Outbound Properties/sec'
- instance_label: "instance.name"
instance_name: "NTDS"
measurement_label: "ntds.dra.outbound.values.dnonly.sec"
query: '\DirectoryServices(NTDS)\DRA Outbound Values (DNs only)/sec'
- instance_label: "instance.name"
instance_name: "NTDS"
measurement_label: "ntds.dra.outbound.values.total.sec"
query: '\DirectoryServices(NTDS)\DRA Outbound Values Total/sec'
- instance_label: "instance.name"
instance_name: "NTDS"
measurement_label: "ntds.dra.pending.outbound.repl.operations"
query: '\DirectoryServices(NTDS)\DRA Pending Replication Operations'
- instance_label: "instance.name"
instance_name: "NTDS"
measurement_label: "ntds.dra.pending.outbound.repl.sync"
query: '\DirectoryServices(NTDS)\DRA Pending Replication Synchronizations'
- instance_label: "instance.name"
instance_name: "NTDS"
measurement_label: "ntds.dra.sync.failures.schema.mismatch"
query: '\DirectoryServices(NTDS)\DRA Sync Failures on Schema Mismatch'
- instance_label: "instance.name"
instance_name: "NTDS"
measurement_label: "ntds.dra.sync.requests.made"
query: '\DirectoryServices(NTDS)\DRA Sync Requests Made'
- instance_label: "instance.name"
instance_name: "NTDS"
measurement_label: "ntds.dra.sync.requests.success"
query: '\DirectoryServices(NTDS)\DRA Sync Requests Successful'
- instance_label: "instance.name"
instance_name: "NTDS"
measurement_label: "ntds.dra.threads.nc.changes.all"
query: '\DirectoryServices(NTDS)\DRA Threads Getting NC Changes'
- instance_label: "instance.name"
instance_name: "NTDS"
measurement_label: "ntds.dra.threads.nc.changes.holding.semaphore"
query: '\DirectoryServices(NTDS)\DRA Threads Getting NC Changes Holding Semaphore'
- instance_label: "instance.name"
instance_name: "NTDS"
measurement_label: "ntds.ds.pct.reads.dra"
query: '\DirectoryServices(NTDS)\DS % Reads from DRA'
- instance_label: "instance.name"
instance_name: "NTDS"
measurement_label: "ntds.ds.pct.reads.kcc"
query: '\DirectoryServices(NTDS)\DS % Reads from KCC'
- instance_label: "instance.name"
instance_name: "NTDS"
measurement_label: "ntds.ds.pct.reads.lsa"
query: '\DirectoryServices(NTDS)\DS % Reads from LSA'
- instance_label: "instance.name"
instance_name: "NTDS"
measurement_label: "ntds.ds.pct.reads.nspi"
query: '\DirectoryServices(NTDS)\DS % Reads from NSPI'
- instance_label: "instance.name"
instance_name: "NTDS"
measurement_label: "ntds.ds.pct.reads.ntdsapi"
query: '\DirectoryServices(NTDS)\DS % Reads from NTDSAPI'
- instance_label: "instance.name"
instance_name: "NTDS"
measurement_label: "ntds.ds.pct.reads.sam"
query: '\DirectoryServices(NTDS)\DS % Reads from SAM'
- instance_label: "instance.name"
instance_name: "NTDS"
measurement_label: "ntds.ds.pct.reads.other"
query: '\DirectoryServices(NTDS)\DS % Reads Other'
- instance_label: "instance.name"
instance_name: "NTDS"
measurement_label: "ntds.ds.pct.searches.dra"
query: '\DirectoryServices(NTDS)\DS % Searches from DRA'
- instance_label: "instance.name"
instance_name: "NTDS"
measurement_label: "ntds.ds.pct.searches.kcc"
query: '\DirectoryServices(NTDS)\DS % Searches from KCC'
- instance_label: "instance.name"
instance_name: "NTDS"
measurement_label: "ntds.ds.pct.searches.lsa"
query: '\DirectoryServices(NTDS)\DS % Searches from LSA'
- instance_label: "instance.name"
instance_name: "NTDS"
measurement_label: "ntds.ds.pct.searches.nspi"
query: '\DirectoryServices(NTDS)\DS % Searches from NSPI'
- instance_label: "instance.name"
instance_name: "NTDS"
measurement_label: "ntds.ds.pct.searches.ntdsapi"
query: '\DirectoryServices(NTDS)\DS % Searches from NTDSAPI'
- instance_label: "instance.name"
instance_name: "NTDS"
measurement_label: "ntds.ds.pct.searches.sam"
query: '\DirectoryServices(NTDS)\DS % Searches from SAM'
- instance_label: "instance.name"
instance_name: "NTDS"
measurement_label: "ntds.ds.pct.searches.other"
query: '\DirectoryServices(NTDS)\DS % Searches Other'
- instance_label: "instance.name"
instance_name: "NTDS"
measurement_label: "ntds.ds.pct.writes.dra"
query: '\DirectoryServices(NTDS)\DS % Writes from DRA'
- instance_label: "instance.name"
instance_name: "NTDS"
measurement_label: "ntds.ds.pct.writes.kcc"
query: '\DirectoryServices(NTDS)\DS % Writes from KCC'
- instance_label: "instance.name"
instance_name: "NTDS"
measurement_label: "ntds.ds.pct.writes.lsa"
query: '\DirectoryServices(NTDS)\DS % Writes from LSA'
- instance_label: "instance.name"
instance_name: "NTDS"
measurement_label: "ntds.ds.pct.writes.nspi"
query: '\DirectoryServices(NTDS)\DS % Writes from NSPI'
- instance_label: "instance.name"
instance_name: "NTDS"
measurement_label: "ntds.ds.pct.writes.ntdsapi"
query: '\DirectoryServices(NTDS)\DS % Writes from NTDSAPI'
- instance_label: "instance.name"
instance_name: "NTDS"
measurement_label: "ntds.ds.pct.writes.sam"
query: '\DirectoryServices(NTDS)\DS % Writes from SAM'
- instance_label: "instance.name"
instance_name: "NTDS"
measurement_label: "ntds.ds.pct.writes.other"
query: '\DirectoryServices(NTDS)\DS % Writes Other'
- instance_label: "instance.name"
instance_name: "NTDS"
measurement_label: "ntds.ds.client.binds.sec"
query: '\DirectoryServices(NTDS)\DS Client Binds/sec'
- instance_label: "instance.name"
instance_name: "NTDS"
measurement_label: "ntds.ds.client.name.translations.sec"
query: '\DirectoryServices(NTDS)\DS Client Name Translations/sec'
- instance_label: "instance.name"
instance_name: "NTDS"
measurement_label: "ntds.ds.directory.reads.sec"
query: '\DirectoryServices(NTDS)\DS Directory Reads/sec'
- instance_label: "instance.name"
instance_name: "NTDS"
measurement_label: "ntds.ds.directory.searches.sec"
query: '\DirectoryServices(NTDS)\DS Directory Searches/sec'
- instance_label: "instance.name"
instance_name: "NTDS"
measurement_label: "ntds.ds.directory.writes.sec"
query: '\DirectoryServices(NTDS)\DS Directory Writes/sec'
- instance_label: "instance.name"
instance_name: "NTDS"
measurement_label: "ntds.ds.mon.list.size"
query: '\DirectoryServices(NTDS)\DS Monitor List Size'
- instance_label: "instance.name"
instance_name: "NTDS"
measurement_label: "ntds.ds.name.cache.hit.rate"
query: '\DirectoryServices(NTDS)\DS Name Cache hit rate'
- instance_label: "instance.name"
instance_name: "NTDS"
measurement_label: "ntds.ds.notify.queue.size"
query: '\DirectoryServices(NTDS)\DS Notify Queue Size'
- instance_label: "instance.name"
instance_name: "NTDS"
measurement_label: "ntds.ds.search.subop.sec"
query: '\DirectoryServices(NTDS)\DS Search sub-operations/sec'
- instance_label: "instance.name"
instance_name: "NTDS"
measurement_label: "ntds.ds.security.desc.prop.events"
query: '\DirectoryServices(NTDS)\DS Security Descriptor Propagations Events'
- instance_label: "instance.name"
instance_name: "NTDS"
measurement_label: "ntds.ds.security.desc.prop.ave.excl.time"
query: '\DirectoryServices(NTDS)\DS Security Descriptor Propagator Average Exclusion Time'
- instance_label: "instance.name"
instance_name: "NTDS"
measurement_label: "ntds.ds.security.desc.prop.runtime.queue"
query: '\DirectoryServices(NTDS)\DS Security Descriptor Propagator Runtime Queue'
- instance_label: "instance.name"
instance_name: "NTDS"
measurement_label: "ntds.ds.security.desc.subop.sec"
query: '\DirectoryServices(NTDS)\DS Security Descriptor sub-operations/sec'
- instance_label: "instance.name"
instance_name: "NTDS"
measurement_label: "ntds.ds.server.binds.sec"
query: '\DirectoryServices(NTDS)\DS Server Binds/sec'
- instance_label: "instance.name"
instance_name: "NTDS"
measurement_label: "ntds.ds.server.name.translations.sec"
query: '\DirectoryServices(NTDS)\DS Server Name Translations/sec'
- instance_label: "instance.name"
instance_name: "NTDS"
measurement_label: "ntds.ds.threads"
query: '\DirectoryServices(NTDS)\DS Threads in Use'
- instance_label: "instance.name"
instance_name: "NTDS"
measurement_label: "ntds.external.binds.sec"
query: '\DirectoryServices(NTDS)\External Binds/sec'
- instance_label: "instance.name"
instance_name: "NTDS"
measurement_label: "ntds.fast.binds.sec"
query: '\DirectoryServices(NTDS)\Fast Binds/sec'
- instance_label: "instance.name"
instance_name: "NTDS"
measurement_label: "ntds.ldap.active.threads"
query: '\DirectoryServices(NTDS)\LDAP Active Threads'
- instance_label: "instance.name"
instance_name: "NTDS"
measurement_label: "ntds.ldap.bind.time"
query: '\DirectoryServices(NTDS)\LDAP Bind Time'
- instance_label: "instance.name"
instance_name: "NTDS"
measurement_label: "ntds.ldap.client.sessions"
query: '\DirectoryServices(NTDS)\LDAP Client Sessions'
- instance_label: "instance.name"
instance_name: "NTDS"
measurement_label: "ntds.ldap.closed.connections.sec"
query: '\DirectoryServices(NTDS)\LDAP Closed Connections/sec'
- instance_label: "instance.name"
instance_name: "NTDS"
measurement_label: "ntds.ldap.new.connections.sec"
query: '\DirectoryServices(NTDS)\LDAP New Connections/sec'
- instance_label: "instance.name"
instance_name: "NTDS"
measurement_label: "ntds.ldap.new.ssl.connections.sec"
query: '\DirectoryServices(NTDS)\LDAP New SSL Connections/sec'
- instance_label: "instance.name"
instance_name: "NTDS"
measurement_label: "ntds.ldap.searches.sec"
query: '\DirectoryServices(NTDS)\LDAP Searches/sec'
- instance_label: "instance.name"
instance_name: "NTDS"
measurement_label: "ntds.ldap.successful.binds.sec"
query: '\DirectoryServices(NTDS)\LDAP Successful Binds/sec'
- instance_label: "instance.name"
instance_name: "NTDS"
measurement_label: "ntds.ldap.udp.operations.sec"
query: '\DirectoryServices(NTDS)\LDAP UDP operations/sec'
- instance_label: "instance.name"
instance_name: "NTDS"
measurement_label: "ntds.ldap.writes.sec"
query: '\DirectoryServices(NTDS)\LDAP Writes/sec'
- instance_label: "instance.name"
instance_name: "NTDS"
measurement_label: "ntds.link.values.cleaned.sec"
query: '\DirectoryServices(NTDS)\Link Values Cleaned/sec'
- instance_label: "instance.name"
instance_name: "NTDS"
measurement_label: "ntds.negotiated.binds.sec"
query: '\DirectoryServices(NTDS)\Negotiated Binds/sec'
- instance_label: "instance.name"
instance_name: "NTDS"
measurement_label: "ntds.ntlm.binds.sec"
query: '\DirectoryServices(NTDS)\NTLM Binds/sec'
- instance_label: "instance.name"
instance_name: "NTDS"
measurement_label: "ntds.onelevel.searches.sec"
query: '\DirectoryServices(NTDS)\Onelevel searches/sec'
- instance_label: "instance.name"
instance_name: "NTDS"
measurement_label: "ntds.phantoms.cleaned.sec"
query: '\DirectoryServices(NTDS)\Phantoms Cleaned/sec'
- instance_label: "instance.name"
instance_name: "NTDS"
measurement_label: "ntds.phantoms.visited.sec"
query: '\DirectoryServices(NTDS)\Phantoms Visited/sec'
- instance_label: "instance.name"
instance_name: "NTDS"
measurement_label: "ntds.sam.acc.group.eval.latency"
query: '\DirectoryServices(NTDS)\SAM Account Group Evaluation Latency'
- instance_label: "instance.name"
instance_name: "NTDS"
measurement_label: "ntds.sam.display.info.queries.sec"
query: '\DirectoryServices(NTDS)\SAM Display Information Queries/sec'
- instance_label: "instance.name"
instance_name: "NTDS"
measurement_label: "ntds.sam.dl.membership.eval.sec"
query: '\DirectoryServices(NTDS)\SAM Domain Local Group Membership Evaluations/sec'
- instance_label: "instance.name"
instance_name: "NTDS"
measurement_label: "ntds.sam.enumerations.sec"
query: '\DirectoryServices(NTDS)\SAM Enumerations/sec'
- instance_label: "instance.name"
instance_name: "NTDS"
measurement_label: "ntds.sam.gc.eval.sec"
query: '\DirectoryServices(NTDS)\SAM GC Evaluations/sec'
- instance_label: "instance.name"
instance_name: "NTDS"
measurement_label: "ntds.sam.gg.membership.eval.sec"
query: '\DirectoryServices(NTDS)\SAM Global Group Membership Evaluations/sec'
- instance_label: "instance.name"
instance_name: "NTDS"
measurement_label: "ntds.sam.machine.creation.attempts.sec"
query: '\DirectoryServices(NTDS)\SAM Machine Creation Attempts/sec'
- instance_label: "instance.name"
instance_name: "NTDS"
measurement_label: "ntds.sam.membership.changes.sec"
query: '\DirectoryServices(NTDS)\SAM Membership Changes/sec'
- instance_label: "instance.name"
instance_name: "NTDS"
measurement_label: "ntds.sam.nontransitive.membership.eval.sec"
query: '\DirectoryServices(NTDS)\SAM Non-Transitive Membership Evaluations/sec'
- instance_label: "instance.name"
instance_name: "NTDS"
measurement_label: "ntds.sam.password.changes.sec"
query: '\DirectoryServices(NTDS)\SAM Password Changes/sec'
- instance_label: "instance.name"
instance_name: "NTDS"
measurement_label: "ntds.sam.ress.group.eval.latency"
query: '\DirectoryServices(NTDS)\SAM Resource Group Evaluation Latency'
- instance_label: "instance.name"
instance_name: "NTDS"
measurement_label: "ntds.sam.success.computer.creation.sec"
query: '\DirectoryServices(NTDS)\SAM Successful Computer Creations/sec: Includes all requests'
- instance_label: "instance.name"
instance_name: "NTDS"
measurement_label: "ntds.sam.success.user.creation.sec"
query: '\DirectoryServices(NTDS)\SAM Successful User Creations/sec'
- instance_label: "instance.name"
instance_name: "NTDS"
measurement_label: "ntds.sam.transitive.membership.eval.sec"
query: '\DirectoryServices(NTDS)\SAM Transitive Membership Evaluations/sec'
- instance_label: "instance.name"
instance_name: "NTDS"
measurement_label: "ntds.sam.ug.membership.eval.sec"
query: '\DirectoryServices(NTDS)\SAM Universal Group Membership Evaluations/sec'
- instance_label: "instance.name"
instance_name: "NTDS"
measurement_label: "ntds.sam.user.creation.attempts.sec"
query: '\DirectoryServices(NTDS)\SAM User Creation Attempts/sec'
- instance_label: "instance.name"
instance_name: "NTDS"
measurement_label: "ntds.simple.binds.sec"
query: '\DirectoryServices(NTDS)\Simple Binds/sec'
- instance_label: "instance.name"
instance_name: "NTDS"
measurement_label: "ntds.subtree.searches.sec"
query: '\DirectoryServices(NTDS)\Subtree searches/sec'
- instance_label: "instance.name"
instance_name: "NTDS"
measurement_label: "ntds.tombstones.garbage.col.sec"
query: '\DirectoryServices(NTDS)\Tombstones Garbage Collected/sec'
- instance_label: "instance.name"
instance_name: "NTDS"
measurement_label: "ntds.tombstones.visited.sec"
query: '\DirectoryServices(NTDS)\Tombstones Visited/sec'
- instance_label: "instance.name"
instance_name: "NTDS"
measurement_label: "ntds.transitive.operations.ms.run"
query: '\DirectoryServices(NTDS)\Transitive operations milliseconds run'
- instance_label: "instance.name"
instance_name: "NTDS"
measurement_label: "ntds.transitive.operations.sec"
query: '\DirectoryServices(NTDS)\Transitive operations/sec'
- instance_label: "instance.name"
instance_name: "NTDS"
measurement_label: "ntds.transitive.suboperations.sec"
query: '\DirectoryServices(NTDS)\Transitive suboperations/sec'
#DNS - You can replace instance_name: "NTDS" by "DNS", if you want to separate documents NTDS/DNS
- instance_label: "instance.name"
instance_name: "NTDS"
measurement_label: "dns.total.query.received.all"
query: '\DNS\Total Query Received'
- instance_label: "instance.name"
instance_name: "NTDS"
measurement_label: "dns.total.query.received.sec"
query: '\DNS\Total Query Received/sec'
- instance_label: "instance.name"
instance_name: "NTDS"
measurement_label: "dns.total.response.sent.all"
query: '\DNS\Total Response Sent'
- instance_label: "instance.name"
instance_name: "NTDS"
measurement_label: "dns.total.response.sent.sec"
query: '\DNS\Total Response Sent/sec'
@mazoutte

This comment has been minimized.

Copy link
Owner Author

@mazoutte mazoutte commented Apr 28, 2020

New update :
I had some troubles with 2 DNS counters (response/query per sec) and 1 AD Counter (DRA Threads Getting NC Changes Holding Semaphore).
These fields were in fact nested to another field ; which was causing trouble. I had ".all" value to the 'fake' parent fields to avoid trouble.

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment