You can use a predefined query to create an alert when a critical process stops. You can use the default keyed list only or you can supplement it with your own values. Predefined values include the following: lsass.exe, winlogon.exe, dns.exe, ldap.exe, httpd, smbd, sshd, syslogd, KSecDD, and IPSec Services.
To customize the list, you identify the processes that are critical to maintain in a running state and add them to this keyed list. The query that uses this keyed list is Critical Process Down.
If you create a custom query that uses this key, define the filter as follows:
Column |
Operator |
Value |
---|---|---|
source_processname |
Keyed |
Critical_Processes |
To customize keyed values for Critical_Processes
A list of keys to which you add user-defined values is displayed at the bottom of the main pane.
The predefined values appear.
If you have already scheduled an action alert for the query Critical Process Down, that alert will be generated based on the evaluation of all values in your modified keyed list for Critical_Processes.
Copyright © 2010 CA. All rights reserved. | Email CA Technologies about this topic |