SIEM, Vulnerability Scanning, Server Monitoring and Compliance Training for IT Professionals
Table of Contents

Windows Process Monitor Template

The Windows Process Monitor Template enables you to monitor a process's consumed resources and running state (e.g. Started or Stopped). Processes can, optionally, be stopped or started depending on state. This template is typically used by systems administrators to monitor non-service processes on servers for resource consumption and running state. The Windows Process Monitor Template uses WMI to query process information.

How to configure the Windows Process Monitor Template:

  • From the Menu Bar, select File | New. The Create New Object View displays.
  • From the Create New Object View, expand Templates | Windows Monitors then select Process Monitor. The New Template Properties View displays.
  • The Template Properties view contains 4 tabs.

The Options Tab

  • Use the Windows server or workstation drop-down to select the Windows host you would like to monitor.
Note
Once selected, the host is automatically assigned to this template.
  • Use the Processes drop-down to select the target process.
Note
When first dropped down, the drop-down asynchronously queries the selected host for the available processes. The drop-down contents may take a moment to display.
  • Use the Function drop-down to select the function. The following options are available:
OptionDescription
If running, monitor resourcesIf the process is running, monitors the trigger criteria, otherwise, the monitor fires critical actions.
Verify runningIf the process is not running, the monitor fires critical actions.
If stopped, startIf the process is not running, the monitor starts the process then fires critical actions.
Verify stoppedIf the process is running, the monitor fires critical actions.
If running, stopIf the process is running, the monitor stops the process then fires critical actions.
If running, restartIf the process is running, the monitor restarts the process then fires critical actions.
  • If starting or restarting the process, use the Arguments text box to include any required command-line parameters.
  • Use the Set monitor state to check box to override the critical monitor state when the function rule is triggered. Once checked, use the drop-down to select the desired state.
Note
To restart a process every night without triggering actions, set the monitor state to OK.
  • Use the Resource Consumption Trigger Thresholds controls to apply resource monitoring warning and critical trigger criteria.
Note
For more information on the available criteria, see Win32_Process Class.
This template includes an extra criteria not listed in Microsoft's documentation called 'CPUUtilization'. Use this criteria to calculate the CPU % utilization.
  • Click the Test button to verify the template is configured property and the monitor executes as expected.
  • Finally, select the General Tab, then click the click the Auto-Generate Name Auto-Generate Name Button button to auto-generate a name based on the configured settings.
Windows Process Monitor Properties View
Windows Process Monitor Properties View

Related Topics

General Tab

Actions Tab

Win32_Process Class

Windows Monitor Templates