SIEM, Vulnerability Scanning, Server Monitoring and Compliance Training for IT Professionals
Table of Contents

Windows Monitor Templates

Available Templates

TypeDescription
Resources
CPU MonitorMonitor CPU load over a period of time (e.g. Get notified when CPU load exceeds 50% for 10 minutes).
Memory MonitorMonitor memory consumption over a period of time (e.g. Get notified when memory consumption exceeds 75% for 10 minutes).
Disk Space MonitorMonitor free disk space (e.g. Every hour check the available disk space on all logical disks).
General
Account Lockout MonitorConfigure the frequency to scan Active Directory for domain account lockouts and the frequency to scan servers for local account lockouts.
Audit Policy MonitorSet, monitor and maintain the Windows Audit Policy (e.g. Notify and update when an Audit Policy deviates from your baseline).
Logon MonitorMonitor Windows logon events (e.g. Get notified when any domain administrator logs on to a server).
Performance Counter MonitorMonitor Windows Performance Counters (e.g. Trigger an alert when IO latency is greater than 20ms).
PowerShellRun a PowerShell command or script, parse results, trigger alerts and report results.
Process MonitorMonitor Windows Processes and the resources they consume (e.g. Restart a process when it consumes more than 4 GBs of memory).
RDP Session MonitorMonitor RDP sessions beyond the Windows Session Time Limits. (e.g. Log off idle non-Administrator sessions or sessions that download over 1 GiB of data).
Registry Value MonitorMonitor a Windows Registry Value (e.g. Get notified when a Registry Value is changed to an unexpected value).
Service MonitorMonitor Windows Services and the resources they consume (e.g. Restart a service when it consumes more than 4 GBs of memory).
SMART Disk MonitorMonitor SMART Predictive Disk Failure status (e.g. Check SMART status every hour).
System Security MonitorExecute secedit, parse results, trigger alerts, report results and scan for vulnerabilities (e.g. Scan for DISA STIG Vulnerabilities).
Windows UpdateSearch, filter, notify, report and install Windows Updates (e.g. Automatically install all .Net Desktop Runtime updates).
Windows Management Instrumentation (WMI) QueryQuery a WMI class, parse results, trigger alerts, report results and scan for vulnerabilities (e.g. Scan for DISA STIG Vulnerabilities).
Tasks
Clock SynchronizationSynchronize clock time with a Network Time Protocol (NTP) server (e.g. Synchronize the clocks on all your once a week).
Defragment NTFS DisksSchedule the service to remote execute disk defragmentation (e.g. Defragment production disks once a week).
Task SchedulerStart, stop or restart an application or script (e.g. Launch a PowerShell script on a managed server)

Related Topics

Template Properties