Operating System Monitoring
Read about monitoring Windows, macOS, Linux, BSD, Solaris, and ESXi systems.
NetCrunch monitors all operating systems without installing any agents. It's convenient but sometimes requires extra settings to be set on monitored systems.
Windows
Monitoring Windows computers without agents depends on two factors:
- Correct Windows setup – allowing remote access to the system and retrieving performance information.
- Setting
OS Monitoringin node properties – it must be enabled and set to Windows.
Secure and Credential-Aware Monitoring
NetCrunch is designed to monitor Windows systems securely. It:
- Uses Kerberos authentication when operating in Active Directory environments.
- Falls back to NTLM or local credentials if needed.
- Uses a combination of native Windows protocols (RPC, SMB) and WMI depending on the task and available access.
- Applies least-privilege credential use by supporting multiple credential profiles per node.
This ensures compatibility across Windows versions and deployments, even with strict domain policies.
Windows Setup for Monitoring
Windows is the most common desktop OS, but its security configuration can complicate monitoring. Many challenges are automatically resolved when systems operate in an AD domain.
Before enabling monitoring, review the detailed setup steps in the Windows Monitoring Setup topic. We also provide a shell script for configuring standalone systems.
What can be monitored
Windows monitoring includes Windows services, Event Logs, and performance counters. Additional insights are possible with WMI sensors for software, hotfixes, and hardware. You can explore example configurations in the available Monitoring Packs for Windows.
Enable Windows-specific monitoring via:
Node Settings Monitoring Windows
Windows Services
Windows Services monitoring tracks both service states and installation lifecycle.
NetCrunch observes and alerts on the following service states:
- Service is Running
- Service is Paused
- Service is Stopped
- Service is not Running
It also detects service installation or removal events, which are distinct from state changes:
- Service Installed – the service appeared in the system
- Service Uninstalled – the service disappeared from the system
These are treated as event-based alerts, not state-based ones. This distinction is important for software that installs new versions by uninstalling and reinstalling the service — where NetCrunch captures that transitional moment.
Alerts can be defined for:
- A specific service name
- Services matching a regular expression
- All services
Manual service inspection is available at:
Node Status Windows Windows Services
Config Sensors (Device Inventory)
NetCrunch provides a set of configuration sensors (formerly inventory monitor) for monitoring hardware and software configuration changes. Although Windows machines can be monitored with RPC, these sensors require access to WMI, so make sure WMI is enabled and not blocked on the destination machine.
Hardware (WMI)
Using this sensor, you can download and monitor for changes in the hardware configuration of Windows-based hosts. The hardware configuration includes information about the processor, memory, installed disks (storage), video (graphic card), and monitor.
Software (WMI)
The sensor collects information about installed software, including installation date, version, and vendor. It can notify you when new software is installed, uninstalled, or updated.
Hotfixes (WMI)
The sensor collects information about installed hotfixes. It can notify you when a hotfix is installed or uninstalled.
Windows Event Log
NetCrunch can monitor Event Log entries on a given computer. It does it with a WQL query that NetCrunch automatically builds upon your parameters. You can set up this monitoring by adding an alert to the Windows Event Log sensor in Node SettingsMonitoring. Many of the predefined Monitoring Packs also enable Event Log monitoring.
Specify the narrowest query possible. Windows Event Log entries are large, and monitoring all Windows Event Log entries, even on a relatively small number of computers, might overload the NetCruch Event Log database.
Hyper-V Monitoring
NetCrunch allows monitoring Hyper-V services, but you must configure the node to monitor Windows first as it runs on Windows. Then, NetCrunch automatically detects the system is running Hyper-V services and ads.
WMI Sensors
NetCrunch provides several WMI sensors that include executing custom query and monitoring processes, performance counters, or file shares.
Performance Counters
Windows offers many built-in performance counters, which the installed applications extend. NetCrunch allows the defining several types of Event Triggers for Counters on Windows counters. You can set up triggers by adding a new alert to a node or the Monitoring Pack. Settings Alerting & Notifications Monitoring Packs and Policies
Windows OS Monitoring Packs
There are several Monitoring Packs that you can use for monitoring different aspects of your Windows environment.
- Active Directory (automatic)
- Observe Replication and Service errors. Watch Active Directory services status. The operating System must be Windows Server. Monitored network services list contains LDAP, LDAPS
- Active Directory Signs of Compromise
- Monitors for security events signaling potential security breach related to security event pattern, replay attack or audit policy change that need to be investigated
- Basic Windows Monitoring (automatic)
- Provides basic workstation monitoring. Observe processor utilization, memory usage, and free disk space.
Operating System must be Windows Workstation.
Simplified Monitoring must be Disabled. - CPU (automatic)
- Observe CPU utilization.
- DHCP Server
- Observe the DHCP Server service, its errors, and warnings.
- Disk (automatic)
- Observe Windows Disk performance.
- Distributed File System (DFS)
- Observe Windows Event Log for specific DFSR warnings and errors.
- Distributed File System Replication (DFSR)
- Monitor the Windows event log for specific DFSR warnings and errors, and collect performance and capacity data of namespaces and replicated folders.
- DNS Server (automatic)
- Observe DNS errors. Watch DNS network service and Windows service status.
The operating System must be Windows Server.
The monitored network services list contains DNS. - End of Life (automatic)
- Observe Windows system End of Life status.
- Hyper-V Hypervisor
- Observe the overall processor utilization of the Hyper-V environment, and watch its Windows services' status and the Hypervisor state.
- Hyper-V/VM
- Track operational status, guest processor usage, guest memory, virtual processor usage, as well as any failure events.
- Memory (automatic)
- Observe system memory utilization.
- Network (automatic)
- Provides network utilization reports. Observes outbound traffic
- Network Services Health (automatic)
- Watch for DHCP, DNS, WINS, Remote Access, or other TCP/IP errors.
- Processes (Windows)
- It allows for collecting information for processes.
- Security Audit
- Watch for Account events, login, and password problems.
- Terminal Services
- Watch the number of Active and Inactive sessions.
- Windows Print Queue
- Monitor any print queue errors reported by the device.
- MSMQ - Window Message Queuing
- Monitors Windows message queue
- NVIDIA Quadro GPU Dedicated to NVIDIA Quadro graphic cards.
- Alerts about high GPU, Memory, and Bus usage. Shows metrics also from the Core Clock, Fan Speed, Temperature, and Power Consumption.
- RDP Services
- Monitors status of Windows Services related to RDP, additionally shows the number of sessions on a given machine.
- Basic Windows Authorization Monitoring
- Generating an alert in case of multiple failed login events happening over a short time, when a login attempt was made with explicit credentials or with special privileges assigned.
In specific cases, you may need to modify Windows security monitoring packs to prevent alert floods in environments with high numbers of privileged users' logons. - Basic Windows GPO Monitoring
- Tracking changes in Group/Domain/Authorization Policies, generating an alert when such an event occurs.
In specific cases, you may need to modify Windows security monitoring packs to prevent alert floods in environments with high numbers of privileged users' logons.
Windows Applications
- Exchange 2007-2010 Mailbox Access Server
- Monitor key Windows services and performance counters of the Mailbox Access Server.
- Exchange 2007 - 2010 Transport Access Server
- Monitor key Windows services and performance counters of the Transport Access Server, it contains SMTP availability report.
- Exchange 2013 Client Access Role
- Monitor key Windows services and performance counters of the Client Access Server. It contains reports about IMAP4, SMTP, UMCallRouter, and POP3.
- Exchange 2013 Mailbox Role
- Monitor key Windows services and performance counters of the Mailbox Access Server.
- Exchange 2016-2019
- Monitor key Windows services and performance counters of Exchange servers and related services
- IIS
- Monitor key IIS performance metrics such as ASP requests, IIS Private Bytes, and monitor the Windows event log for ASP, SMTP, and WWW errors.
- MS Dynamics NAV Server
- Monitor key Windows Services of the MS Dynamics NAV Server.
- MS Project Server 2013
- Monitor key Windows Services of the MS Project Server 2013.
- MS Project Server 2016
- Monitor key Windows Services of the MS Project Server 2016.
- MS SQL Server 2012-2019
- Monitor key performance metrics, Windows and Network Services, MS SQL event log warnings, and errors. It contains several reports such as:
Processor Bottleneck Analysis, Disk Usage and Performance, Memory Usage Analysis, MS SQL Server 2012-2017 CPU Performance, MS SQL Server 2012-2017 Memory, MS SQL Server 2012-2017 I/O Report - SharePoint 2010
- Watch the status of SharePoint Windows Services, the number of rejected requests, cache size, and the number of queued requests.
- SharePoint 2013
- Watch the status of SharePoint Windows Services, the number of rejected requests, cache size, and the number of queued requests.
- SharePoint 2016
- Watch the status of SharePoint Windows Services, the number of rejected requests, cache size, and the number of queued requests.
Actions
- Run Windows Program
- The program can be copied to and executed on the desired machine.
- Run Windows Script
- Run the script that can be copied to and executed on the desired machine by a given scripting host.
- Terminate Windows Process
- Terminates the process by its name.
- Start, Stop, Pause Windows Service
- Perform control action on a given service. (Specify service by its name or select from the list of running services).
Linux
NetCrunch monitors Linux without agents using an SSH script, which is automatically copied to a remote machine.
Preparing Node for Linux Monitoring
-
Open Node Settings > Monitoring and enable OS monitoring by selecting Linux from the drop-down menu.
-
Now, you can see the parameters to monitor Linux. Enter SSH credentials unless you use default settings for Linux or add a new credentials profile.
Linux Monitoring Packs
Monitor the most important Linux performance indicators such as processor and memory utilization, free disk space, and available swap, and create a Linux Server Report.
- Linux Status (automatic)
- Observes connection and authentication errors of Linux monitor.
- CPU (automatic)
- Observe CPU utilization.
- Disk (automatic)
- Observe disk utilization, swap available, and the volumes' free space.
- Memory (automatic)
- Observe Available Memory.
- CPU (SNMP)
- It requires SNMP to be enabled. Observe CPU Load and % CPU Time.
- Disk (SNMP)
- It requires SNMP to be enabled. Observe disk utilization, swap available, volumes' free space, and physical disk I/O operations.
- Memory (SNMP)
- It requires SNMP to be enabled. Observe system memory utilization.
- Network Traffic (Linux)
- It allows for collecting network traffic data.
- Processes (Linux)
- It allows for collecting information for processes.
Actions
- Run SSH Script
- Run script using SSH connection can be copied to and executed on the desired machine by a given scripting host.
Scripts
- Shutdown Linux Machine
- Reboot Linux Machine
- Restart Linux SNMP Daemon
- Mount CD-ROM
- Dismount CD-ROM
BSD
NetCrunch monitors BSD without agents using an SSH script, which is automatically copied to a remote machine.
Monitoring Packs
Monitor the most important BSD performance indicators, such as processor and memory utilization, and free disk space, and create a BSD Report.
- BSD Status (automatic)
- Observes connection and authentication errors of BSD monitor.
- CPU (automatic)
- Observe CPU utilization.
- Disk (automatic)
- Observe disk utilization, and volume free space.
- Memory (automatic)
- Observe Available Memory.
- Network Traffic (BSD)
- It allows for collecting network traffic data.
- Processes (BSD)
- It allows for collecting information for processes.
Actions
- Run SSH Script
- Run script using SSH connection can be copied to and executed on the desired machine by a given scripting host.
Solaris
NetCrunch monitors Solaris without agents using only an SSH script, automatically uploaded to the remote machine.
Monitoring Packs
Monitor most important Solaris performance indicators such as processor and memory utilization, and free disk space, and create Solaris Report.
- Solaris Status (automatic)
- Tracks connection and authentication errors of Solaris monitor.
- CPU (automatic)
- Observe CPU utilization.
- Disk (automatic)
- Observe disk utilization, volumes' free space, and swap available
- Memory (automatic)
- Observe Available Memory
- Network Traffic (Solaris)
- It allows for collecting network traffic data.
- Processes (Solaris)
- It allows for collecting information for processes.
- Solaris (SNMP)
- It requires SNMP to be enabled. It monitors CPU Load, Load Check, Minimum Swap Space, and Swap Space.
Actions
- Run SSH Script
- Run script using SSH connection can be copied to and executed on the desired machine by a given scripting host.
macOS
NetCrunch monitors macOS without agents using only an SSH script, automatically uploaded to the remote machine.
Monitoring Packs
Monitor the most important macOS performance indicators. Such as processor and memory utilization, and free disk space, and then create a macOS Report.
- macOS Status (automatic)
- Observes connection and authentication errors of macOS monitor.
- CPU (automatic)
- Observe CPU utilization.
- Disk (automatic)
- Observe disk utilization and volume of free space.
- Memory (automatic)
- Observe Available Memory.
- Processes (macOS)
- It allows for collecting information for processes.
Actions
- Run SSH Script
- Run script using SSH connection can be copied to and executed on the desired machine by a given scripting host.
Other Operating Systems
VMware ESXi
NetCrunch supports direct monitoring of ESXi or using vCenter. Read more in VMware Monitoring.
Legacy Systems
IBM AIX and AS/400
IBM AIX and AS/400 systems can be monitored via SNMP.
IBM Monitoring Packs
- IBM IMM (SNMP)
- Monitors hardware parameters and health condition information related to the components of the system.
- IBM System x Disk (SNMP)
- Shows the status of the physical drive and volume.
- IBM System x System Health (SNMP)
- Monitors the health status of the memory and system. It also shows information about temperature, voltage, and fan speed.
Novell NetWare
As each NetWare system has a pre-installed SNMP agent, monitoring is possible using SNMP.
NetWare Monitoring Pack
Invalid Reference @monitoring-packs:NetWare