Windows Rule Syntax for Service Monitoring Events | ||
---|---|---|
Rule Format: alert_level;service_regex;min;max;comment_or_description;regen_boolean | ||
Field | Example Values | Notes |
alert_level | red | yellow | The level of alert that will be generated if this process falls outside of specified parameters. |
service_regex | Fax Service |
The string or simple regular expression that will match the Windows service you wish to monitor. If you wish to make sure that the matching service is NOT running, simply put a "!" in front of the process_regex. |
min | 1 | Not used on Windows - defaults to 1 |
max | 0 | Not used on Windows - defaults to 0 |
comment_or_description | Optional comment or description that will appear if this alert is triggered. | |
regen_boolean (optional) | true | false | This is the boolean flag that tells the Sensor whether you want to restart the Service if it is found to not be running. However in order for this service to be restarted, an identical copy of the "service_regex" for this rule MUST be in the "regen.cmds" file in the "conf" directory on the Sensor in which this command will be executed. This is for your safety, as commands have the potential to be run as a privileged user. |
Unix | Win32 | ||