Windows Monitoring

Unlock the full potential of your Windows environment.

Tracking server performance, managing events, and overseeing applications becomes a breeze.

Say goodbye to complicated setups - our agentless system is as straightforward as it gets, paving the way for a seamless, stress-free monitoring experience.

Complete Windows Monitoring

NetCrunch is a comprehensive monitoring solution with over 675 out-of-the-box monitoring targets, custom script capabilities, and an SNMP compiler. This versatile tool efficiently covers multiple layers, including devices, hardware, and operating systems such as Windows and Linux. It extends to virtualization platforms like ESXi and Hyper-V, as well as cloud services and applications.

Designed to be adaptive and scalable, NetCrunch caters to various monitoring needs, making it ideal for both small networks and large enterprises. Its extensive monitoring capabilities allow for real-time insights and alerts, ensuring the smooth operation of your systems.

Whether managing a small network or overseeing a large enterprise, NetCrunch's robust and flexible design provides a one-stop solution for all your monitoring requirements. It offers unparalleled versatility and comprehensive coverage across numerous layers of your IT environment.

Comprehensive Windows Monitoring

  • Performance Monitoring

    NetCrunch allows you to monitor numerous metrics using native Windows performance counters or WMI objects

    NetCrunch's performance monitoring for Windows systems is a sophisticated feature that leverages a variety of advanced triggers and alerting mechanisms. This ensures comprehensive oversight and efficient management of Windows environments.

    Variety of Event Triggers

    NetCrunch offers an extensive set of event triggers for performance monitoring. These include threshold, deviation threshold, baseline threshold, state trigger, flat value, value missing/existing, delta, and range triggers. Each of these triggers serves a unique purpose, such as tracking deviations from expected behavior, monitoring discrete value changes, or detecting specific conditions like over-utilization or under-utilization of resources.

    Baseline Threshold Triggers

    A notable feature in NetCrunch is the Baseline Threshold trigger. It enables setting thresholds based on deviations from previously observed behavior on specified counters. NetCrunch collects data over time, establishing hourly averages for each day, which serve as a baseline. This is particularly useful for monitoring metrics like % Committed Memory in Windows servers, allowing for detecting spikes or drops in utilization.

    Benefits of NetCrunch Performance Monitoring:

    • Proactive System Management With real-time and historical data analysis, NetCrunch enables proactive management of Windows systems, preventing issues before they escalate.
    • Customized Response to Events The flexibility in setting up alerts and triggers allows for a tailored response to specific system events, enhancing system reliability and performance.
    • Data-Driven Insight: NetCrunch's comprehensive monitoring and alerting system provides valuable insights into system performance, aiding in informed decision-making and strategic planning.

    @Performance

    In summary, NetCrunch's performance monitoring for Windows is a powerful tool that offers detailed, customizable, and proactive monitoring and alerting capabilities, ensuring optimal performance and reliability of Windows environments.

  • Enhanced Windows Event Log Monitoring

    NetCrunch monitors events on the Windows system with WMI and predefined Monitoring Packs

    NetCrunch's capabilities in monitoring Windows Event Logs are a critical component of comprehensive Windows monitoring. Through remote gathering, filtering, and analysis of data from multiple Windows machines using WMI (Windows Management Instrumentation), NetCrunch offers a powerful and efficient way to oversee and manage your network's health and security.

    Why Windows Event Log Monitoring is Important

    1. Security Monitoring Event logs are a goldmine of information regarding network security. Monitoring logs can reveal unauthorized access attempts, security policy changes, and other potential security breaches.

    2. System Health Tracking Logs provide insights into the health of your systems. This includes monitoring for signs of system or hardware failure, application errors, or other critical system issues.

    3. Compliance and Auditing For many organizations, keeping detailed logs is not just good practice—it's a regulatory requirement. Monitoring event logs helps in maintaining compliance with various standards and regulations.

    4. Operational Troubleshooting Event logs are instrumental in troubleshooting issues within the network. They offer detailed error messages and operational logs that can help diagnose and resolve problems.

    Types of Events Monitored:

    • Application Logs Track events logged by applications or programs. For example, a database application might report a file error when attempting to open a database file.

    • System Logs Contain events logged by the Windows system components. These can be events related to system setup, drivers, or other system components.

    • Security Logs Record events such as valid and invalid login attempts as well as events related to resource use like creating, opening, or deleting files or other objects.

    • Setup Logs Particularly useful in diagnosing issues during the installation of applications and operating system updates.

    • Forwarded Events These logs are forwarded from other machines in the network, providing a centralized view of event logs.

    Simplified Alert Management

    NetCrunch simplifies the process of converting event log events into actionable NetCrunch alerts. Users can define simple alert filters that are automatically converted into appropriate WQL (WMI Query Language) queries. This feature eliminates manual coding, making it accessible for administrators of all skill levels.

    By utilizing NetCrunch for Windows Event Log monitoring, administrators can proactively manage and respond to a wide array of system events, ensuring the smooth and secure operation of their IT infrastructure.

  • Windows Service Monitoring

    Monitor Windows services out-of-the-box and get alerted when service stopped or is not running.

    NetCrunch offers an advanced Windows Services Monitoring feature, designed to provide comprehensive oversight and management of Windows service statuses. This monitoring is crucial for ensuring the reliability and smooth functioning of key services on Windows servers and workstations.

    Key Monitoring Alerts:

    NetCrunch allows administrators to set up specific alerts for various states of Windows services, ensuring immediate awareness and response to critical changes. The monitoring covers:

    1. Service is Paused Receives an alert when a monitored service is in a paused state, which could indicate intentional or unintentional interruptions affecting the service's functionality.

    2. Service is Running Generates an alert when a service starts running, useful for confirming the successful start of essential services after maintenance or a system restart.

    3. Service is Stopped Triggers an alert when a service stops running, which is crucial for identifying unexpected shutdowns or failures in critical services.

    4. Service is Not Running Alerts when a specified service isn't running, encompassing both stopped and paused states, ensuring that any deviation from the normal running state is promptly addressed.

    Advanced Alert Customization:

    • Single Service Monitoring Set alerts for individual services, allowing for targeted monitoring of critical components in your IT environment.

    • Group Monitoring with Regex For broader oversight, NetCrunch enables alerts for groups of services matching a given regex pattern. This feature is particularly useful for monitoring multiple related services or services following a naming convention, streamlining the management of large-scale or complex environments.

    NetCrunch's Windows Services Monitoring is a powerful tool for IT administrators, providing essential insights and control over the service statuses on Windows systems. By promptly responding to these alerts, administrators can maintain operational continuity, prevent downtime, and ensure the efficient running of their network services.

  • System Views for Windows Devices

    NetCrunch's System Views offer a complete snapshot of Windows devices, covering services, processes, hardware, software, and more for streamlined management.

    NetCrunch offers a suite of system views tailored for comprehensive monitoring of Windows devices. These views provide detailed insights into various aspects of your Windows environment, ensuring efficient and proactive management.

    • Services Monitor the status and health of Windows services. Easily track which services are running, stopped, or in a paused state, and receive alerts for any critical changes.

    • Processes Gain visibility into active processes on your Windows devices. Monitor resource usage, identify resource-intensive processes, and manage process lifecycles effectively.

    • Sessions Keep tabs on user sessions, including login times and session durations. This view is crucial for security and operational efficiency.

    • Scheduled Tasks Oversee all scheduled tasks within your Windows environment. Ensure that critical tasks are running as planned and troubleshoot any issues with task execution.

    • Hardware Monitoring Get detailed information about the hardware components of your Windows devices. This includes monitoring of CPUs, memory, disks, and other critical hardware elements.

    • Software and Hotfixes Stay updated on all installed software and hotfixes. This view allows you to manage software versions and ensure that necessary updates and security patches are applied.

    • Updates Track Windows updates and their status. This is vital for maintaining system security and functionality.

    • Virtual Machines For environments using virtualization, this view provides insights into the performance and health of virtual machines hosted on Windows servers.

    @Windows Processes

    Each of these system views is designed to offer deep insights into the respective areas, helping administrators manage and optimize Windows devices effectively. NetCrunch’s intuitive interface ensures that accessing and interpreting this data is straightforward, aiding in quick decision-making and proactive system management.

  • Monitoring Windows Processes with NetCrunch

    NetCrunch allows you to monitor a single process or a group of processes

    NetCrunch's Windows Process Monitoring feature is a robust tool designed to offer detailed insights into the resource utilization of processes on Windows systems. This monitoring is essential for maintaining optimal performance and stability in your IT environment.

    Monitoring Capabilities

    Process Sensor

    This sensor is adept at monitoring a single Windows process, providing critical data on various aspects such as processor utilization, number of handles, instances, memory usage, and threads. This detailed monitoring is invaluable for diagnosing issues related to specific processes, ensuring they are running efficiently and not consuming excessive system resources.

    Process Group Summary Sensor

    Building on the Process Sensor's capabilities, this sensor allows for the monitoring of multiple processes simultaneously. It utilizes a wildcard (*) for process name inclusion and supports the addition of multiple name patterns separated by commas. This extended functionality is crucial for overseeing groups of related processes or for systems where multiple instances of similar processes run concurrently.

    Key Benefits

    • Enhanced Performance Analysis By monitoring the resource utilization of individual and groups of processes, administrators can identify processes that are consuming excessive resources, potentially impacting system performance.

    • Proactive Problem Resolution The ability to monitor various process parameters enables IT teams to proactively address issues before they escalate into more significant problems affecting system availability or performance.

    • Customized Monitoring The flexibility to monitor specific processes or groups of processes using pattern matching allows for tailored monitoring that aligns with the unique needs of your IT environment.

    • Real-Time Insights NetCrunch provides real-time data, offering immediate visibility into the health and performance of Windows processes, crucial for timely decision-making and action.

    @Top Processes

  • SQL Server Monitoring with NetCrunch

    With SQL data sensor you can monitor SQL Server database connection and the server performance data

    NetCrunch offers a comprehensive monitoring solution for Microsoft SQL Server, ensuring high performance and reliability of your database systems. This feature-rich toolset is designed to keep a close watch on various critical aspects of SQL Server operations.

    Broad Monitoring Scope

    • SQL Data Sensor Monitor SQL Server database connections and server performance data. This sensor is crucial for ensuring that your database is accessible and running efficiently.

    SQL Monitoring Pack

    • Performance Metrics Monitoring Keep track of key performance metrics to identify potential bottlenecks or inefficiencies in your SQL Server operations.
    • Windows and Network Services Monitoring Extend monitoring to include the health and status of associated Windows and network services, ensuring a comprehensive overview of your SQL environment.
    • Event Log Analysis Automatically track MS SQL event log warnings and errors, providing valuable insights into potential issues and areas for improvement.
    • Detailed Reports Access a variety of reports, such as Processor Bottleneck Analysis, Disk Usage and Performance, Memory Usage Analysis, SQL Server CPU Performance, and SQL Server Memory. These reports are invaluable for in-depth analysis and proactive management of your SQL Server environment.

    SQL Protocol Check (Network Service)

    • Application Protocol Monitoring NetCrunch's ability to recognize and check the availability of over 70 application protocols includes the SQL Server protocol, ensuring your database's availability and responsiveness.

    SQL Query Sensors

    • Advanced Data Querying Utilize two distinct sensors to query data from SQL Server. These sensors can be used for various purposes, including checking authentication processes, retrieving system table data, or querying specific database information.

    • Native Client Connection Support: NetCrunch supports native client connections to SQL Server, facilitating efficient and direct communication with your database.

    NetCrunch's SQL Server Monitoring feature provides a vital layer of insight and control, helping database administrators maintain optimal performance and swiftly address any issues. The integrated approach of monitoring, combined with detailed reporting and query capabilities, makes NetCrunch an essential tool for managing SQL Server environments.

  • Hyper-V Monitoring

    NetCrunch includes monitoring of Hyper-v hosts and virtual machines

    NetCrunch provides an in-depth monitoring solution for Hyper-V environments, focusing on both Hyper-V hosts and virtual machines. This monitoring ensures efficient management and high availability of your virtualized infrastructure.

    Hyper-V Hosts Monitoring

    • Automatic Detection and Monitoring NetCrunch automatically recognizes systems running Hyper-V services and integrates Hyper-V Server Monitoring Packs. These packs are designed to track the state and performance of Hyper-V services effectively.
    • Host State Monitoring Keep a close watch on the operational state of Hyper-V hosts, ensuring they are functioning optimally and are free from critical issues.

    Virtual Machine Monitoring

    • Seamless Integration with Virtual Machines When monitoring a Hyper-V host, NetCrunch detects virtual machines running on the server. This allows for detailed monitoring of each VM's status and performance.
    • Customizable Alerts for VMs Configure alerts specific to the state and parameters of virtual machines, enabling proactive management and quick response to potential issues.
    • Enhanced Visibility Gain in insights into your virtual machines and hosts with grid views for a specific group of nodes, offering a clear overview of your virtualized environment.

    Why Monitor Hyper-V with NetCrunch?

    1. Ensure High Availability Monitoring with NetCrunch helps maintain the high availability of your virtual machines and hosts, which is crucial for business continuity.
    2. Performance Optimization Real-time monitoring and alerts enable you to optimize the performance of your Hyper-V infrastructure, ensuring efficient resource utilization.
    3. Troubleshooting and Management NetCrunch's detailed data collection and reporting capabilities make troubleshooting issues and managing your Hyper-V environment easier.


    NetCrunch's Hyper-V Monitoring is a vital tool for administrators managing virtualized environments, providing the necessary insights and controls to maintain optimal operations.

    For more detailed information and configuration guidelines, visit NetCrunch Hyper-V Monitoring.

    @Hyper-V/VM @Windows Config

  • Monitoring Windows Updates and Pending Reboots

    NetCrunch provides easy-to-use sensors for monitoring updates and reboots

    NetCrunch enhances network management with intuitive sensors designed to monitor Windows updates and system reboots, ensuring your Windows environments are up-to-date and stable.

    Windows Updates Sensor

    Comprehensive Update Tracking

    This sensor is specifically designed to monitor the status of Windows updates on any selected computer. It provides crucial data, including:

    • The number of installed updates.
    • Updates that are available for installation.
    • The number of updates pending installation.

    This level of detail helps administrators stay informed about the update status of each machine, ensuring that all systems are current with the latest security patches and feature updates.

    Pending Reboot Sensor

    • Reboot Status Monitoring The Pending Reboot Sensor utilizes WMI (Windows Management Instrumentation) to check if a Windows machine requires a reboot. This sensor is essential for:

      • Maintaining system stability and performance after updates or changes.
      • Ensuring that critical updates are fully implemented, which often requires a system reboot.
    • Alerts for Action The sensor is configured to trigger an alert when a pending reboot is detected. This enables administrators to reboot the system immediately, minimizing downtime and disruption.

    Read more in Monitoring Windows Updates and Pending Reboots

  • WMI Sensors

    Leverage the power of WMI without a need for scripting with 17 ready-to-use sensors

    NetCrunch's WMI Sensors empower network administrators to harness the capabilities of Windows Management Instrumentation (WMI) without the complexity of scripting. With 17 ready-to-use sensors, NetCrunch offers various monitoring options from essential to advanced functionalities.

    • WMI Perfmon Offers an alternative to native performance data monitoring. This sensor simplifies the process by automatically mapping WMI objects and classes, eliminating the need to deal with complex WMI class names.

    • File Shares Monitors the status of Windows shares, providing options to manually enter or select share names from a list.

    • Process and Process Group Summary Enables monitoring of individual processes or multiple processes simultaneously, extending the capabilities of essential process monitoring.

    • AD Replication Checks Windows Domain Controllers for replication errors, crucial for maintaining the integrity of your domain environment.

    • Pending Reboot Sensors Identifies if a machine is awaiting a reboot due to updates, helping to ensure timely system restarts for update completions.

    • Windows Updates Monitors the status of Windows updates on a computer, with the functionality to alert on failed updates.

    • Registry Sensor Monitors the Windows registry for changes or specific values. For example, it allows detecting alterations in system startup programs.

    • Registry Counters Sensor Tracks performance-related data from the Windows registry. For example, you can track values that are not available via WMI or Performance counters, such as the total number of user profiles.

    • Remote Ping Tests connectivity from a remote system by executing a Ping command remotely, which is helpful for network diagnostics.

    • Time Difference Measures the time difference between a remote machine and a reference machine (NetCrunch Server or NTP server), ensuring time synchronization across the network.

    • WMI HDD Health Monitors HDD disk health, utilizing SMART technology to predict potential failures.

    • WMI Battery Tracks the health and status of system batteries.

    • WMI Data and WMI Object These sensors allow the monitoring of specific WMI classes, instances, and objects, providing detailed insights without needing to write WQL queries.

    • WQL Query:Object Offers the ability to run custom WQL queries and process the results for advanced WMI data retrieval.

    • Windows Task Scheduler Sensor Keeps track of the status of tasks within the Windows Task Scheduler, ensuring scheduled tasks are running as expected.

    NetCrunch's suite of WMI Sensors provides a comprehensive toolset for detailed monitoring and management of a wide range of network components and services, enhancing network performance and reliability.

    Read more in WMI Sensors

  • Enhancing Monitoring with PowerShell Scripts in NetCrunch

    NetCrunch offers extensive monitoring features, but PowerShell can provide additional functionality.

    NetCrunch offers a comprehensive suite of monitoring tools, covering a wide range of needs through native counters and WMI. Its high-performance capabilities enable the efficient monitoring of thousands of machines. Yet, there are scenarios where the need for customization and flexibility arises, and this is where PowerShell scripting becomes invaluable.

    The Versatility of Script Sensors

    • Script Sensor This sensor is designed to run scripts or programs directly on the local NetCrunch Server machine, processing the results for insights. It offers the flexibility to:

      • Connect to and poll data from remote machines using various methods, including remote PowerShell execution.
      • Pass credentials securely to the script, enabling authenticated interactions with other systems.
    • Remote SSH Script Sensor Expanding the possibilities, this sensor executes scripts on remote machines via SSH. With SSH now available on Windows, this sensor provides a versatile and convenient method for remote scripting. It's particularly useful for:

      • Performing complex or custom monitoring tasks that go beyond the capabilities of standard sensors.
      • Integrating existing scripts into the NetCrunch monitoring framework, maximizing the use of already developed resources.

    The Power of Custom Scripting

    The integration of scripting within NetCrunch empowers administrators to tailor their monitoring strategy to their unique environment. Whether it's leveraging existing PowerShell scripts or creating new ones for specific tasks, these sensors provide the means to capture and analyze data that is not readily accessible through standard monitoring tools.

    NetCrunch's script sensors are key tools for advanced network management, offering the necessary flexibility to address the most specific and complex monitoring requirements.

    For more detailed information on utilizing PowerShell scripts with NetCrunch, visit the Scripting Sensors.

  • Comprehensive Windows Hardware & Software Inventory with NetCrunch

    Track all hardware components and installed software & hotfixes

    NetCrunch offers an efficient solution for managing and tracking the hardware and software inventory of Windows machines. This feature is essential for maintaining an up-to-date overview of your network's infrastructure and ensuring system integrity.

    Detailed Hardware Tracking

    This sensor enables you to monitor changes in the hardware configuration of Windows-based hosts, alerting you to any modifications. Key components covered include:

    • Processor
    • Memory
    • Storage
    • Video cards
    • Monitors

    Alerts

    Configuration Change Alerts

    Stay informed about any alterations in hardware setup, allowing for timely responses to potential issues or unauthorized changes.

    Software Inventory Sensor

    Collect comprehensive data on installed software across your network. This sensor provides capabilities to:

    • Alert on software installations, uninstallations, or updates.
    • Offer a summary view of installed software per node group, including version details and installation locations.

    Hotfixes Sensor

    Keep track of all installed hotfixes on your Windows machines. This sensor is designed to:

    • Alert on the installation and uninstallation of hotfixes.
    • Provide a detailed list of all applied hotfixes, aiding in compliance and security management.

    @Inventory View

  • Advanced Monitoring of Files and Folders on Windows with NetCrunch

    You can remotely monitor files and folders on Windows machines

    NetCrunch provides a robust solution for remotely monitoring files and folders on Windows machines, essential for ensuring data integrity, security, and compliance.

    File Sensor:

    This sensor is designed to track various file attributes and activities. Its capabilities include:

    • Monitor the file presence to ensure critical files are where they should be.
    • Tracking file size changes, alerting you to significant increases or decreases that could indicate data issues.
    • Detecting modifications with alerts on when a file was last altered is crucial for tracking changes in critical files.
    • Searching within file contents, particularly useful for log files and other text-based data.
    • Identifying new log entries and converting these into actionable NetCrunch alerts, enabling swift response to events as they are logged.

    Folder Sensor:

    The Folder sensor provides an overview of specific folder activities, allowing you to:

    • Monitor when new files are added to a folder, which is vital for directories where file creation is a significant event.
    • Track if any files are removed from the folder, ensuring no unexpected deletions occur, which could be vital for security and operational continuity.

    NetCrunch's files and folders monitoring feature is a key asset for network administrators, offering detailed insights into file system changes and activities. This monitoring is particularly beneficial for maintaining compliance with data handling policies, ensuring security against unauthorized changes, and keeping a vigilant eye on critical system and data files.

NetCrunch Performance Monitor

The easiest way to monitor your Windows and other servers and the whole network

NetCrunch Starter Packs

Discover the Power
of Modern Monitoring
with NetCrunch

NetCrunch is a beacon of innovation, seamlessly blending robust functionality with user-friendly design. Whether real-time analytics, customizable dashboards, or comprehensive coverage across your network, NetCrunch is the future of monitoring, available today.

Embrace the ease, the power, and the future – with NetCrunch, the last monitoring solution you'll ever need.

AdRem Software is a partner of