Ad Widget

Collapse

Monitoring Antivirus on Windows

Collapse
X
 
  • Time
  • Show
Clear All
new posts
  • rs26
    Member
    • Jan 2008
    • 42

    #1

    Monitoring Antivirus on Windows

    Hi,


    I would like to monitor the antivirus system installed on client computers (Windows XP/Vista).

    The Antivirus is TrendMicro. How monitor it ?

    EDIT : The service's name is "tmlisten".

    Can I monitor this service ? How ?

    Thanks.
    Last edited by rs26; 26-02-2008, 14:51.
  • Tenzer
    Senior Member
    • Nov 2007
    • 316

    #2
    What would you like to monitor?
    That the service is running?
    That the virus definitions are up-to-date?
    If the service has found any viruses?

    Comment

    • rs26
      Member
      • Jan 2008
      • 42

      #3
      I want to know if the service is running or not. I've a Antivirus Server but the web interface is not running very well.

      But if it's possible to do more that monitoring service

      Comment

      • siemt74
        Junior Member
        • Jan 2008
        • 11

        #4
        Hi,
        You can use this item with Windows Service State Value map:

        service_state[tmlisten]

        Comment

        • rs26
          Member
          • Jan 2008
          • 42

          #5
          I'm going to use it. I tell you if it's running. Thanks

          Comment

          • rs26
            Member
            • Jan 2008
            • 42

            #6
            Thanks, it works perfectly !

            Comment

            • rs26
              Member
              • Jan 2008
              • 42

              #7
              I would like to do the same operation with emule.

              I want to know if users are using the p2p program.

              But there is no service with emule. It's just a process.

              Any idea ?

              Comment

              • sdwilders
                Member
                • Feb 2008
                • 33

                #8
                Antivirus Definitions

                I can monitor antivirus services are running quite easily and I understand it is quite easy to enable a trigger if a file changes - but how do you run a trigger if a file isn't changed?

                I want to fire a trigger if a virus definition file isn't changed in say 7 days.

                Comment

                • rolandsym
                  Member
                  • Jul 2007
                  • 76

                  #9
                  from a command prompt you can run this....

                  wmic /NAMESPACE:\\root\SecurityCenter PATH AntiVirusProduct get productUptoDate

                  If the antivirus is security center aware than it will report whether it is up to date with a true and a false when it is not. you can also "Get DisplayName" or "Get versionNumber"


                  Hope this helps,
                  RolandSym

                  Comment

                  • sdwilders
                    Member
                    • Feb 2008
                    • 33

                    #10
                    Super, that gives me the required response from a command line. Is there an "easy" way to add an item in Zabbix that will execute and collect the result of this? or would I need to add a custom script to each and every agent? (bearing in mind there are thousands!)

                    Comment

                    • rolandsym
                      Member
                      • Jul 2007
                      • 76

                      #11
                      zabbix_agentd.conf

                      UserParameter=antivirus.uptodate,wmic /NAMESPACE:\\root\SecurityCenter PATH AntiVirusProduct GET productuptoDate | findstr /V "productUptoDate"

                      this will get you just true or false and not the extra line.

                      would be example of the line you would add to the end of zabbix_agentd.conf which can be done with a simple echo command and >>.

                      It would be great if there were some predefined WMI items that zabbix could grab because Vista and 2008 have a lot more WMI information. I've been playing with the zabbix_client a little but not much luck.

                      Hope it helps,
                      RolandSym

                      Comment

                      • sdwilders
                        Member
                        • Feb 2008
                        • 33

                        #12
                        There are only a set number of different antivirus programmes between all my clients so I think I will try and create a trigger that fires if the definition file checksum is unchanged for say 7 days. I'll see if I can get this going and post back my item/trigger that I used.

                        Comment

                        • Jason
                          Senior Member
                          • Nov 2007
                          • 430

                          #13
                          Hmmm Is this example for servers or just XP?

                          I just get an invalid namespace when I try this on a server. It'd be really useful to have this working for servers somehow
                          Last edited by Jason; 29-04-2008, 15:32.

                          Comment

                          • rolandsym
                            Member
                            • Jul 2007
                            • 76

                            #14
                            not server

                            yes for xp pro sp2, vista... and I believe win 2008. Windows 2003 doesn't have a security center. I don't recall off the top of my head whether Win 2003 R2 has security center or not.

                            Rolandsym

                            Comment

                            • rolandsym
                              Member
                              • Jul 2007
                              • 76

                              #15
                              not server

                              yes for xp pro sp2, vista... and I believe win 2008. Windows 2003 doesn't have a security center. I don't recall off the top of my head whether Win 2003 R2 has security center or not.

                              Rolandsym

                              Comment

                              Working...