Solved

Qradar - how to monitor windows server disk space?

Posted on 2013-10-23
3
1,014 Views
Last Modified: 2014-05-21
Hello Qradar gurus!  Really need your help on this one. And before you respond --> I know there are many drive-space monitoring solutions out there! I want to utilize a system that I already own to monitor drive space and not introduce ...'yet another utility or process'.

Can someone tell me how to configure Qradar to monitor available hard drive space on a Windows 2003 Server?  

I know that the Windows Server System Event Log generates an event ID of 2013 when a disk is at or near capacity. Any way to use Qradar to look for that event and generate an email alert?
0
Comment
Question by:JohnArmstrong
  • 2
3 Comments
 
LVL 35

Expert Comment

by:David Todd
ID: 39596021
Hi,

Is the windows event in sufficient time? That is, if memory serves me correctly, when there really is almost no available disk left. Wouldn't you want an alert for 20% free space or 10% free space?

I have a powershell script that stores these values in a SQL database, and I query that database each morning as part of my daily checks.

Regards
  David
0
 
LVL 1

Author Comment

by:JohnArmstrong
ID: 39631463
Hi David, What values are you pulling from Windows server?  Are you pulling the info using WMI and piping it into a dbase?
0
 
LVL 35

Accepted Solution

by:
David Todd earned 500 total points
ID: 39631675
Hi,

Yes I'm using WMI

There are a couple of servers that WMI isn't responding on, so I filter them out of my list.

foreach( $s in Invoke-Sqlcmd -Query ‘select distinct ss.FQDN as ServerName from dbo.SQLServer ss where isWMIWorking = 1 and ( DateDecommissioned is null or DateDecommissioned > dateadd( day, datediff( day, 0, getdate()), 0 ))’ -Database SomeDatabase -ServerInstance SomeServer) {
    $d = Get-WmiObject -computername ( $s.ServerName ) Win32_LogicalDisk -filter "DriveType=3" | foreach { 
        add-member -in $_ -membertype noteproperty UsageDT $((Get-Date).ToString("yyyy-MM-dd HH:mm:ss")) 
        add-member -in $_ -membertype noteproperty SizeGB $([math]::round(($_.Size/1GB),2)) 
        add-member -in $_ -membertype noteproperty UsedGB $([math]::round((($_.Size - $_.FreeSpace ) /1GB ), 2 ))
        add-member -in $_ -membertype noteproperty FreeGB $([math]::round(($_.FreeSpace/1GB),2)) 
        add-member -in $_ -membertype noteproperty PercentUsed $([math]::round(((1 - [float]$_.FreeSpace/[float]$_.Size) * 100),2)) -passThru 
        } | Select UsageDT, SystemName, Caption, VolumeName, SizeGB, UsedGB, FreeGB, PercentUsed | out-DataTable       
    ;

Open in new window


out-DataTable is by Chad Miller
http://thepowershellguy.com/blogs/posh/archive/2007/01/21/powershell-gui-scripblock-monitor-script.aspx 

HTH
  David
0

Featured Post

Free Tool: IP Lookup

Get more info about an IP address or domain name, such as organization, abuse contacts and geolocation.

One of a set of tools we are providing to everyone as a way of saying thank you for being a part of the community.

Question has a verified solution.

If you are experiencing a similar issue, please ask a related question

Knowing where your website is hosted is as important as the features you receive, the monthly fee, and the support you receive. Due diligence should be done when choosing your next hosting provider.
It’s the first day of March, the weather is starting to warm up and the excitement of the upcoming St. Patrick’s Day holiday can be felt throughout the world.
Sending a Secure fax is easy with eFax Corporate (http://www.enterprise.efax.com). First, Just open a new email message.  In the To field, type your recipient's fax number @efaxsend.com. You can even send a secure international fax — just include t…
Get a first impression of how PRTG looks and learn how it works.   This video is a short introduction to PRTG, as an initial overview or as a quick start for new PRTG users.

860 members asked questions and received personalized solutions in the past 7 days.

Join the community of 500,000 technology professionals and ask your questions.

Join & Ask a Question