PDF

What can I monitor?

NetCrunch can monitor nearly anything: devices, applications, systems, databases, and files. The program can be extended using scripts; data from various sources can be sent to NetCrunch or polled from files, databases, or websites.

There are many different usage scenarios for NetCrunch. In general, NetCrunch retrieves and processes three types of data:

Events
Information about some occurrences generated by NetCrunch or external sources such as Windows Event Log, SYSLOG, or SNMP trap.
Performance Counters (Metrics)
Numerical values (64-bit integer or floating-point)
Status
The status of various objects in NetCrunch, such as nodes, services, monitoring engines, etc.

The server allows you to set various conditions to filter incoming events or set alerts on performance counters. You can even create new calculated counters. See the Managing Calculated Performance Counters topic for details.

Network Infrastructure (SNMP)

NetCrunch can be used solely for network monitoring, focusing mainly on SNMP devices such as printers, switches, routers, cameras, and others. NetCrunch supports SNMP v1/v2c/v3, including encryption and authentication.

Connectivity & Response Monitoring

NetCrunch monitors the availability of over 70 predefined TCP/UDP network services, including DNS, FTP, HTTP, POP3, SMTP, and more.

The program can monitor network service performance by counting the number of packets sent and received, calculating response times, and calculating the percentage of packets lost and received.

The program checks connectivity, validates service response, and measures response time for each monitored service. For each sensor, the program allows monitoring of various conditions (e.g., whether the text contains a pattern, whether a file exists, and so on) and performance metrics (e.g., response time or data size).

You can create custom service definitions or duplicate an existing definition and change its port. Services support TCP, UDP, and SSL connections. Response patterns can be defined as text, binary data, or regular expressions.

Node Up/Down Status

NetCrunch determines node up/down status based on network service status and other monitors (for servers). When a node is down, only the leading service is being monitored. A node is considered "down" when no services respond, and "up" when the leading service responds.

DNS Health Monitoring

DNS is the most critical service in a network. Without it, nothing works at all. Therefore, monitoring the DNS service to check its availability is an obvious task for a monitoring system. However, availability monitoring only verifies whether the service is responding and the response time.

In addition to pure availability monitoring, NetCrunch allows you to verify DNS responses to given queries, which can enable you to discover unexpected (unauthorized) DNS changes.

Switch and Router Monitoring

NetCrunch supports switch and router monitoring, including network interface status, error and discard monitoring, and bandwidth monitoring. It allows traffic to be monitored on interfaces and port mappings, and to create Layer 2 graphical maps.

NetCrunch allows you to monitor Cisco IP SLA operations. The program tracks the status of operations and also their performance metrics. Cisco IPSLA allows you to monitor VOIP jitter and other protocols and parameters.

Vendor-Specific Monitoring via SNMP

SNMP is ubiquitous, but implementations vary. NetCrunch includes an MIB compiler that lets you add vendor-specific MIBs.

Since basic MIBs have been only partially defined in RFCs, vendor MIBs can be tricky to compile. If you have no experience compiling MIBs and find it difficult, please ask AdRem support for help. We will try to help you, and if the device is popular on the market, we can add it to the precompiled MIB set. Please note that NetCrunch's built-in database already contains more than 8,850 vendor MIBs.

Servers and Applications

NetCrunch supports agentless monitoring of the major operating systems, including Windows, macOS, Linux, BSD, Solaris, and VMWare ESXi. Additionally, the Windows system supports application monitoring by monitoring its performance parameters and service status.

You can also use SNMP to monitor these systems, but please be advised that using SNMPv2 can create a security loophole in operating systems, as SNMPv2 transmits data in plain text.

Windows Monitoring

Performance Counters

NetCrunch allows you to monitor all Windows performance counters, including disk counters, remotely. The list of available counters depends on the specific system and installed applications. Nine different trigger types can be used to set alert triggers on counters.

Event Triggers for Counters

Windows Services

Monitoring Windows services is essential for monitoring most applications installed on Windows Server. The most frequent alert set on services is Service is not running. NetCrunch also offers a Windows services view in the node status window, allowing remote service control.

Windows Event Log

NetCrunch can remotely gather, filter, and analyze data from multiple Windows machines using WMI.

The program allows you to define simple alert filters to convert event log events into NetCrunch alerts. These filters are automatically converted into complex WQL queries.

WMI Sensors

NetCrunch includes 16 WMI sensors. WMI Perform resembles perfmon using the WMI protocol, WMI Query object allows you to write your query, and then you can add alert triggers on the result object properties. Process and Process Group summaries are handy for monitoring processes and their resources. Using the Process Group Summary sensor, you can easily track the total resources used by a web browser or other program using multiple process instances.

Hardware and Software Inventory

NetCrunch can collect hardware and software inventory information from Windows computers. The program shows detailed information about each machine and lists installed fixes. NetCrunch lets you compare each audit and display hardware and software changes. The program includes a software summary view for multiple nodes.

Monitoring Files, Folders, and Text Logs

This type of monitoring is available for Linux (and other Unix family systems) and Windows. These file sensors allow you to monitor file presence, size, and modification time. It can also search file contents, find new text log entries, and convert them into NetCrunch alerts.

The Folder sensor allows you to monitor specific folder contents, such as when a new file is added or if any files are removed.

These sensors support FTP/s, HTTP/s, SSH/bash, SFTP, and Windows/SMB protocols.

Linux, macOS, Solaris, and BSD

NetCrunch can track over 100 performance counters to determine the health of Linux servers running kernel 2.4 or newer. The program has been tested to monitor the following Linux distributions: CentOS, Red Hat, Fedora, Novell OES, Ubuntu Desktop, and Server.

NetCrunch also offers fully integrated Mac OS monitoring. All macOS versions are supported, including the latest one.

The most important parameters being monitored:

  • System (uptime/downtime, logged-in users)
  • Processor utilization
  • Memory usage
  • Disk usage
  • Network interface statistics
  • Processes (CPU & memory per process utilization)
  • User (CPU & memory)
  • TCP statistics

Monitoring VMware

NetCrunch supports ESXi versions 5.5 and later. It can connect directly to ESXi servers or via vCenter. When NetCrunch works in vCenter mode, and vCenter becomes unavailable, it can automatically switch to direct ESXi monitoring if you provide proper credentials for each ESXi server.

NetCrunch includes preconfigured Automatic Monitoring Packs for ESX when the device type is set to ESX.

Mail Server, Mailbox, and Email Monitoring

NetCrunch allows monitoring of mailboxes (IMAP or POP3), checking email content (extracting data or events from emails) using the Data Email sensor, or checking full mail server functionality by sending and receiving control email (Email Round-Trip Sensor)

SQL Database Monitoring

NetCrunch offers two sensors. The first allows checking a single-row answer from the SQL query, which can be treated as a status object. The second can interpret multiple rows as a list of metrics. This way, NetCrunch can monitor database connectivity and authentication (with an empty SQL query), query execution time, and query results, which can be a single row representing a status object (so you can track changes in the state of properties) or metrics that can be kept for trend or used for performance triggers. NetCrunch natively supports Oracle, SQL Server, MySQL, MariaDB, and any ODBC (system) source.

Security Monitoring - SSL Certificate Sensor

Every web sensor in NetCrunch can report an invalid certificate. NetCrunch also includes a separate SSL Certificate sensor that can be used to validate any SSL/TLS-based protocol certificate. The sensor can be used for any TLS-based service, not just HTTP/S.

Monitoring Device Uptime

NetCrunch includes a universal sensor monitoring device that can be connected to using WMI, SSH, or SNMP protocols.

Monitoring Printers (SNMP)

The program allows monitoring printers using a printer sensor that retrieves all printer statuses and metrics.

RADIUS Sensor

The sensor checks the RADIUS protocol response and availability.

Cloud Monitoring

NetCrunch provides multiple sensors for monitoring Amazon Web Services, Azure, and Google Cloud. You can add each sensor by creating a Cloud Service node.

Device Configuration Monitoring

NetCrunch can collect, store, and detect changes in device configuration. The configuration is stored in a text file that can later be used for editing or restoring. The sensor and code are based on the Oxidized open-source project, ported to a NetCrunch environment.

Window Hardware Config

Similarly, NetCriunch collects the hardware configuration of Windows machines. The hardware configuration summary is available in the Nodes tab view.

Web Monitoring

Monitoring Web Pages or Applications

NetCrunch includes an advanced Web Page monitor that can load and render dynamic web pages containing JavaScript, as if a browser were loading them. It also allows you to check pages requiring the login (supporting standard HTML or custom login forms).

Available Web Page alerts:

  • page size or load time
  • page content change
  • alert if the text is present or missing
  • if a page does not exist
  • page load error
  • page resource load error
  • page authentication error

Available performance metrics:

  • % Availability
  • HTTP Status Code
  • JS Errors
  • Load Time
  • Main Frame Body Size
  • Resource Count
  • Resources Error Count
  • Total Size

Monitoring HTTP Requests

This sensor is more suited for sending REST requests, so it simply retrieves data over HTTP and checks the response. It also allows you to check the response content. It supports GET, HEAD, and POST requests.

Data Receiver Sensor

Allows defining a sensor on the node to receive data from an external source (a device, script, or app). Data can be sent using the REST API, and you can set alerts on collected metrics and status objects.

applicationcloudconfigmonitoringnetworkrest