Solved

Qradar - how to monitor windows server disk space?

Posted on 2013-10-23
3
986 Views
Last Modified: 2014-05-21
Hello Qradar gurus!  Really need your help on this one. And before you respond --> I know there are many drive-space monitoring solutions out there! I want to utilize a system that I already own to monitor drive space and not introduce ...'yet another utility or process'.

Can someone tell me how to configure Qradar to monitor available hard drive space on a Windows 2003 Server?  

I know that the Windows Server System Event Log generates an event ID of 2013 when a disk is at or near capacity. Any way to use Qradar to look for that event and generate an email alert?
0
Comment
Question by:JohnArmstrong
  • 2
3 Comments
 
LVL 35

Expert Comment

by:David Todd
ID: 39596021
Hi,

Is the windows event in sufficient time? That is, if memory serves me correctly, when there really is almost no available disk left. Wouldn't you want an alert for 20% free space or 10% free space?

I have a powershell script that stores these values in a SQL database, and I query that database each morning as part of my daily checks.

Regards
  David
0
 
LVL 1

Author Comment

by:JohnArmstrong
ID: 39631463
Hi David, What values are you pulling from Windows server?  Are you pulling the info using WMI and piping it into a dbase?
0
 
LVL 35

Accepted Solution

by:
David Todd earned 500 total points
ID: 39631675
Hi,

Yes I'm using WMI

There are a couple of servers that WMI isn't responding on, so I filter them out of my list.

foreach( $s in Invoke-Sqlcmd -Query ‘select distinct ss.FQDN as ServerName from dbo.SQLServer ss where isWMIWorking = 1 and ( DateDecommissioned is null or DateDecommissioned > dateadd( day, datediff( day, 0, getdate()), 0 ))’ -Database SomeDatabase -ServerInstance SomeServer) {
    $d = Get-WmiObject -computername ( $s.ServerName ) Win32_LogicalDisk -filter "DriveType=3" | foreach { 
        add-member -in $_ -membertype noteproperty UsageDT $((Get-Date).ToString("yyyy-MM-dd HH:mm:ss")) 
        add-member -in $_ -membertype noteproperty SizeGB $([math]::round(($_.Size/1GB),2)) 
        add-member -in $_ -membertype noteproperty UsedGB $([math]::round((($_.Size - $_.FreeSpace ) /1GB ), 2 ))
        add-member -in $_ -membertype noteproperty FreeGB $([math]::round(($_.FreeSpace/1GB),2)) 
        add-member -in $_ -membertype noteproperty PercentUsed $([math]::round(((1 - [float]$_.FreeSpace/[float]$_.Size) * 100),2)) -passThru 
        } | Select UsageDT, SystemName, Caption, VolumeName, SizeGB, UsedGB, FreeGB, PercentUsed | out-DataTable       
    ;

Open in new window


out-DataTable is by Chad Miller
http://thepowershellguy.com/blogs/posh/archive/2007/01/21/powershell-gui-scripblock-monitor-script.aspx

HTH
  David
0

Featured Post

How your wiki can always stay up-to-date

Quip doubles as a “living” wiki and a project management tool that evolves with your organization. As you finish projects in Quip, the work remains, easily accessible to all team members, new and old.
- Increase transparency
- Onboard new hires faster
- Access from mobile/offline

Join & Write a Comment

By this time the large percentage of day-to-day transactions have shifted to mobile banking; here are some overriding areas QAs must investigate while testing mobile banking apps.  
This article explains in simple steps how to renew expiring Exchange Server Internal Transport Certificate.
Get a first impression of how PRTG looks and learn how it works.   This video is a short introduction to PRTG, as an initial overview or as a quick start for new PRTG users.
This video gives you a great overview about bandwidth monitoring with SNMP and WMI with our network monitoring solution PRTG Network Monitor (https://www.paessler.com/prtg). If you're looking for how to monitor bandwidth using netflow or packet s…

707 members asked questions and received personalized solutions in the past 7 days.

Join the community of 500,000 technology professionals and ask your questions.

Join & Ask a Question

Need Help in Real-Time?

Connect with top rated Experts

11 Experts available now in Live!

Get 1:1 Help Now