File Watch rules monitor your files and folders for keywords/files, changes, size, and or existence on your Windows servers/workstations using our Goliath Intelligent Agent to alert on specified conditions in real-time.
Configure the Monitoring
- To create a new monitoring condition, navigate to the Management - Monitors page and click New.
- For the Group dropdown, select a group in which to store the rule. This is for organizational purposes in the Monitors display.
- In the Type dropdown, select Citrix XenServer Host.
- Name the Monitoring Rule via the Name field, as well as define the description and the severity.
- In the Devices tab, select the devices to assign to the monitor.
- Please note, a machine can only be applied to one VMware ESX/ESXi Host monitoring rule type at a time.
- The Options tab is where you will define condition(s) to be monitored.
- In the File Path Name field, define the fully qualified path for the file to be checked in this Monitoring Rule. The path includes the driver letter but does NOT include the machine name. For example, "C:\MyApplication\MyLogFiles\Log.txt" is a correct specification.
This parameter fully supports wild-cards for defining a Watch on a group of files matching the specification; this parameter also accepts a directory/folder name as a specification to monitor the entire folder for the specified conditions.- If none of the other optional parameters below are defined then GPM watches for the creation and existence of the specified file(s). If the ‘NOT Check’ checkbox is checked, GPM watches for the deletion of the file(s).
- You can exclude files from being part of a wild-card or folder check by following the ‘File Path Name’ spec with an exclamation point character (‘!’) and then the file to be excluded; you can specify multiple exclusions, and you can use a wild-card in an exclusion name. An example of a ‘File Path Name’ spec with multiple exclusions would look like this: C:\Log.* ! tx1 ! log.tx2 !*.tx3
- In the File Path Name field, define the fully qualified path for the file to be checked in this Monitoring Rule. The path includes the driver letter but does NOT include the machine name. For example, "C:\MyApplication\MyLogFiles\Log.txt" is a correct specification.
- The Change Size checkbox, when checked, the file's current size is determined, and any subsequent change to that size results in an alert condition.
- The Change D/T checkbox, when checked, the file's current last-modified date/time is determined, and any subsequent change to that last-modified date/time results in an alert condition.
- In the Search String field, if specified, the file is scanned for this sub-string, and if found, results in an alert condition. The file scanning is optimized so that only new data added to the file is scanned on each check.
- This field supports Boolean AND search with multiple substrings using the plus sign, and Boolean OR using the comma, for example, s1+s2,s3+s4, meaning if substrings s1 AND s2 are found OR s3 AND s4 are found then there is a match. Any combination of substrings using the plus and comma are accepted such as s1+s2+s3 or s1+s2,s3,s4, etc. The comma has the highest precedence meaning combinations separated by comma are parsed 1st, and then within that, combinations with plus are parsed.
- This field also supports comparing and testing a numerical value as part of the search substring. The syntax for checking a numeric value as part of a search substring is as follows: <#GT nnnn>, <#LT nnnn> or <#EQnnnn>. For example, you could specify your Search String as two substrings using the Boolean AND plus sign: MEM:<#GT 1024000>+-<#LT 300000>
- In the Max Size(KB) field, if specified, the file size in kilobytes (KB) is checked against this parameter and if it exceeds it, results in an alert condition.
- The Include Subfolders checkbox, when checked and the File Path Name specified is a folder name, then all the 1st level subfolders are also included for monitoring using the same specified parameters.
- The Include All checkbox, when checked and the File PathName specified uses a wild-card and the Max Size parameter is specified, then the total size of all files matching the wild-card is compared versus the ‘Maximum Size’; otherwise if not set, then each individual file’s size is compared versus the ‘Maximum Size’.
- When checked, and when the NOT Check checkbox is checked and the File Name specified uses a wild-card, then all files are included in the NOT check before the alert condition is triggered. For example, all files matching the wild-card spec must change before a change alert notification occurs, or all files must be deleted before the file delete (file does NOT exist) alert notification occurs.
- When checked and the Include Subfolders is checked, and the File Name specified is a folder name, then the Max Size and File Count Threshold parameters apply to the total size of the folder and its 1st level subfolders or the total count of the files in the folder and its 1st level subfolders.
- The NOT Check checkbox, when checked, that all the defined parameters are tested in the NOT condition. The simple example is the specified file does not exist (perhaps it has been deleted).
- For the Size Change, D/T Change, Max Size,and Search String parameters, if specified imply, the NOT of the parameter. For example, the Size and/or D/T have NOT changed, the File is less than the specified Maximum Size, or the File does NOT contain the specified Search String.
- The Duration field, optional parameter, if specified, defines the Duration in Minutes that the File conditions must exist in the 'matched' (that is, the Alert state) before the Alert notification is actually triggered.
- The AND Params checkbox, when checked, specifies that a match must occur on all of the parameter fields above that have been specified (Boolean AND); otherwise, if not set, a match can occur on any of the parameter fields above that have been specified (Boolean OR).
- The File Count Threshold optional field, if specified, the count of the files in the specified directory exceeds the specified threshold, results in an alert condition.
- The Schedule tab of a monitoring rule allows users to define how frequently the rule will alert. This can be done by adjusting the following fields:
- Alert Every Time: Defines whether an alert is generated every time the conditions are on the previous tab are met.
- When checked, an alert is generated every time the specified condition is met.
- When unchecked, the alert is only generated if the alert conditions are met, and the Minimal Notification Interval, see below, is exceeded since the last alert for this type.
- Minimal Notification Interval: Defines the minimum amount of time that must elapse between events for the specified condition before another alert will be generated.
- For example, if the interval is 15 minutes and the condition is being met every 3 mins, you will receive 1 alert every 15 minutes instead of being alerted at each occurrence.
- However, each alert occurrence is considered unique based on the details. For example, an Event Log alert is considered the same based on being the same Event Type and ID, from the same server/workstation.
- The Alert Every Time checkbox must be unchecked in order to use this option.
- For ServerWatch IP Services, this also defines the minimum elapsed time since a service is first detected as down or failed before an alert is generated.
- For example, if the interval is 15 minutes and the condition is being met every 3 mins, you will receive 1 alert every 15 minutes instead of being alerted at each occurrence.
- Maximum Notification Interval: Defines the maximum number of times you want to be notified during a continuous failure situation.
- The default value of '0' means infinite; no maximum is defined so you will continue to be notified according to your Alert Every Time and Minimal Notification Interval settings.
- A non-zero value means that after you have been notified the number of times defined in the Maximum Alert Notifications, and according to your Alert Every Time and Minimal Notification Interval settings, you will not be notified again.
- For example, if "5" is selected, the event will alert for the first 5 events and all additional events will be ignored.
- Notify On Restore: Defines whether a 'Restore' alert is generated if you have previously been alerted due to a failure.
- For example, if CPU has been 90%, and then dropped below the alert threshold, the notify on restore email will inform you that the condition has returned to a normal state.
- There is always a Notify on Restore for a ServerWatch type alerts.
- Service Check Frequency, Every: Defines the frequency with which the service specified for this Monitoring Rule is checked. It is no recommended to do this check any fewer then 3 mins.
- Alert 1st Time After X Failures: Define a value 1 or greater that defines how many successive failures should occur before the 1st alert notification 'Action' is executed.
- The Alert Every Time and Minimum Notification Interval settings do no become applicable until after this threshold setting is exceeded.
- The default value for this setting is blank which means not applicable. When not applicable, the Alert Every Time and Minimum Notification Interval settings are active immediately and the 1st alert does not occur until the Minimum Notification Interval threshold is equaled or exceeded if it is active.
Additional Configuration
For additional configuration options please see the following articles: