NetCrunch Knowledge Base

How-tos, troubleshooting and answers about NetCrunch.

How to start monitoring Windows Event Log

I don't see the full Windows Event Logs in the NetCrunch Console UI. I see the settings where I can adjust some things regarding the logs, but I don't see where they are displayed unless you have to manually add filters to have them show on the alerts tab.

Applies to 12.x 11.x 10.x

NetCrunch can monitor some logs out-of-the-box, others need to be configured by the user. We do not recommend collecting all possible Windows Event Log entries - as some events are heavy and the Windows system tends to send lots of them, you may soon overwhelm your system, network, and database if you try to save all of them from multiple Windows machines.

Parameters monitored by NetCrunch out-of-the-box

NetCrunch has many preconfigured Monitoring Packs. Some of them contain predefined alerts based on Windows Event Log entries. Examples of monitoring packs of this type are 'Basic Windows Authorization Monitoring' and 'Basic Windows GPO Monitoring' (of course, there are more, we encourage you to read about them). These monitoring packs include predefined alerts, e.g. "Account failed to log on 5 times in last 3 minutes", or "Domain Policy changed". In order for this type of event to be monitored, it is enough to assign nodes on which we want to check these events to appropriate monitoring packs.

Monitoring of other Windows Event Log entries

It is possible to monitor also other Windows Event Logs rather than those predefined in NetCrunch.

To do this you have to:

  1. Add a new monitoring pack, then ad an alert definition to it.
  2. Select "New Event for Received Windows Event Log Entry" from the Windows group
  3. In the "Windows Event Log file" field, choose one from the list, or leave "<any>"
  4. In the "Expression" field, you can indicate what conditions must be met by the Windows Event Log entry for an alert to be generated.

For example, if we want to get an alert while any Error appears in the Security log, we can set the following:

  1. select Security in the "Windows Event Log file" field
  2. in the "Expression" field, set the condition Event Type equals Error

The definition of the alert can be even more complex - in this way you ensure that alerts are raised for very specific events (e.g. the previously mentioned "Failed to log on" when "Event Identifier equals 4625"), they can also be more generic and generate alerts in more common situations (e.g. "Event Code greater than 100").

It is recommended to avoid defining alerts for very generic events. Generating alerts from many events of Windows Event Log on multiple machines can badly affect database performance!

All Windows Event Logs related to alerts (predefined or ones you have defined your self) will appear in the Alerts tab.

NetCrunch. Answers not just pictures

Maps → Alerts → Automation → Intelligence