Symptoms

The LDAP Searched Per Second, LDAP Client Sessions and LDAP Bind Time monitoring indicators are flashing red and appear to be over the limit.


Cause

The LDAP performance thresholds for the following may need to be adjusted to meet the needs of your specific environment.

  • LDAP Searches/sec - The number of search operations per second performed by LDAP clients. If the environment is balanced, the values should be near the same across all of your domain controllers.  If it is not, then an abnormal value may suggest that a specific domain controller is underperforming or that restructuring of the network is required to balance the load to other domain controllers.
  • LDAP Client Sessions - The number of sessions of connected LDAP clients.  In an environment that is balanced, the measurements should be similar for each domain controller.
  • LDAP Bind Time - The time (in milliseconds) required for the completion of the last successful LDAP binding.  Typically you want to have times measured to be under 5 seconds.  Bind times that start to exceed 15 or 30 seconds may be an indication network issues are present.


Resolution

  1. Open the Admin Console and select Server>Tuning Policy>Agent Options>NetworkAgent (scroll down to select).
  2. Once the Network Agent section is expanded, then scroll down to specify the LDAP performance thresholds.
  3. After adjusting the settings for each test, then select Save to apply the changes to the Policy.