The MP Microsoft System Center Advisor Advanced Threat Analytics events seems to try to collect events from the Microsoft ATA event log on all your servers, but that event log only exists on the ATA center and GW servers. Result is unhealth SCOM management Group and event ID 26005 is logged in the OpsMgr event log saying The Windows Event Log Provider was unable to open the Microsoft ATA event log on computer <computer name> for reading.11 votes
As a workaround you can create an override to stop these events.
A future update to the agent will fix this issue.
When I activate the WireData solution because I want to see the data from 10 Servers, the solution will collect data from all Servers.
Allow to define from which Servers i want to collect which data.3 votes
Try the preivew of solution targeting and let us know what you think:
Operation managers Health and assessment will be a good report with which we can review and identify how the SCOM monitoring system is monitoring the systems.
Management Servers are already connected to Azure Ops Insights to send the data ,so collecting this information should be easy.14 votes
The SCOM Assessment solution is currently in preview.
Try it out and let us know what you think.
- Don't see your idea?