Monitoring Benefit
The Service Status test checks that the Windows services you have chosen to monitor are running on each server, and changes state when one is not.
Its value is in catching the gap between "the server is up" and "the server is working". A machine can respond to everything, pass its resource checks and look entirely healthy while the one service that matters has stopped. Nothing else on the dashboard will notice, because everything else is fine — and that is exactly the outage that gets discovered by a user rather than by monitoring.
It is also the check that most often catches the aftermath of a change. Services that fail to come back after a reboot, an update or a credential change are a large share of real incidents, and they are invisible until someone tries to use the thing.
How to use it
Monitor the services that matter, not every service. A long list produces noise from services that are stopped legitimately, and noise is how a genuine stop gets missed. The services worth watching are the ones whose absence constitutes an outage for that server's role.
Mind the start-up type. A service set to Manual or Disabled is not running by design, and monitoring it as though it should be produces a permanent red indicator. Confirm the intended start-up type before treating a stopped service as a fault.
A service that restarts itself is still a finding. Windows recovery options can restart a failed service automatically, so the indicator may clear before anyone looks. If a service appears to fail and recover repeatedly, the underlying fault is still there and the event log is where to find it.
How do we verify the monitoring test results?
From EMS 8.0 onward these results are held in the ENow SQL database rather than in a file on the web server. Open the monitoring page for this server in the ENow console to review what ENow recorded.
How do we verify the results received on the ENow Client?
The ENow Client queries the service control manager periodically. This information is not logged, but the agent's collected results are cached on the monitored server alongside its other results:
\Program Files (x86)\ENow\Mailscape Agent\Cache\
To capture the same information manually, run the following in PowerShell on that server:
Get-Service | Where-Object Status -ne 'Running' |
Select-Object Name, DisplayName, Status, StartType |
Sort-Object StartType, Name
To check one service, including the account it runs under — which is the usual culprit after a credential change:
Get-CimInstance Win32_Service -Filter "Name='<service name>'" |
Select-Object Name, State, StartMode, StartName, ExitCode, ProcessId
An ExitCode other than 0 tells you the service stopped because it failed rather than because someone stopped it.
To see why it stopped, look at what Windows logged around that time:
Get-WinEvent -FilterHashtable @{LogName='System'; ProviderName='Service Control Manager'} -MaxEvents 40 |
Format-List TimeCreated, Id, LevelDisplayName, Message
Common warning or error results, and potential solutions
| Result | Potential solution |
|---|---|
| A service is stopped and set to Manual or Disabled | Working as intended. Remove it from monitoring on that server rather than leaving a known-red indicator. |
| A service failed to start after a reboot | Check its dependencies and its log-on account. Services that depend on the network or on a database often start before what they need is ready. |
| Several services stopped on one server at once | Look for a common log-on account whose password changed or whose "log on as a service" right was removed, rather than investigating each service. |
| A service stops repeatedly and restarts | Windows recovery is masking a real fault. Work the Service Control Manager events, not the indicator. |
| No results at all for a server | Usually the monitoring account's rights on that server rather than the services. Confirm the server is reporting at all — see Server Connectivity - Connectivity Status. |
| A monitored service no longer exists | The service was removed by an upgrade or a role change. Update the monitored list to match what the server now runs. |
| Service running but the application is still broken | A running service is not a working one. Use the application's own check for that role rather than this one. |
Comments
0 comments
Article is closed for comments.