Ad Widget

Collapse

PROBLEM: Monitor Scheduled Shadow Copy services on a Windows Server

Collapse
X
 
  • Time
  • Show
Clear All
new posts
  • danieru
    Junior Member
    • Sep 2023
    • 2

    #1

    PROBLEM: Monitor Scheduled Shadow Copy services on a Windows Server

    Hello!

    I have a request from a client of mine to add a monitoring parameter to the scheduled Shadow Copy runs that the server runs at 07:00, 12:00, 16:00, and at 20:00 on weekdays and only at 20:00 on weekends for drive F:\.
    On drive G:\ the job runs at 07:00 and 12:00 on all weekdays, skipping weekends.

    I've tried manually setting up a trigger for the alarm, and its item and trigger created are as follows:

    Item
    • Key: service_state[Volume Shadow Copy]
    • Information type: Numeric (unsigned)
    • Show value: I've tried both "Service state" and "Windows service state"
    • Applications: Shadow Copy
    Trigger
    • Expression: {MRHFS01:service_state[Volume Shadow Copy].last(25h)}<>0
      • I'm using a 30h downtime since the service stops for at most 24 hours, between Friday 20:00 and Saturday 20:00
      • I've experimented using both the service name and the executable name (vssvc.exe) for the item, but neither results have been favourable.
    I've been mostly either getting contantly 255 service status, or service state 6 with no interruptions, which is undesirable considering the job is scheduled.

    I remember being able to gather somewhat precise metrics back in May, but it deregulated and I was never able to get similar results again with this. The only thing wrong with the metrics at the time is that it was detecting an activation of the service at 01:00, which was not included in the schedule, but otherwise, all other schedules were precise, weekends included. As you can see on the graph below, you had the service state line continuously at state=6, with dips to state=0 on the times that the service started. If there were no "dips" for more than 24 hours in a row, the trigger would go off indicating that a scheduled Shadow Copy job did not run.
    I've tried doing some extra stuff, like creating a discovery rule for all Windows Services to see if it could detect the VSS service, but it was also not successful. Checking on the actual VSS service inside the server, we saw that the service has been continuously fine, with no schedule breaks.

    Click image for larger version

Name:	MayMRHFS01 Metrics.png
Views:	553
Size:	62.4 KB
ID:	470947


    Does anyone know how I can faithfully monitor the service status during the shceduled times without the state being perpetually stuck at 255 or 6? I've tried to the best of my capabilities to revert the configurations i've made to the ones in May, but despite being able to revert the trigger configuration, the graphs did not respond the same way as it did back then.

    I appreciate any given input.

    Best regards,
    Daniel​
Working...