Sentry II Version 8.5.00

March 13, 2008

Installing the New Version:

  • Run the ‘SentryII_Fullsetup.exe’.  It will self-extract and launch the Setup. 

  • Setup will prompt to stop the Sentry II Server service, click OK, only the appropriate files are updated.

  • The Installer will then prompt you to restart the Sentry II Server service, click NO and do not restart the service as you will need to enter a new license key.

To Apply the License Key:

  1. Run the MonitorIT Server as a foreground application;

  2. Go to the menu item "Help->Purchase/Upgrade License" dialogue box;

  3. Cut & paste (or type in) this license key to the 'Registration Key' field.

If currently running MonitorIT as a service:

  1. Go to the Windows Services utility and stop the MonitorIT Server service;

  2. Start the MonitorIT Server as a foreground application (double-click the MonitorIT Server 'spider-web' icon),

  3. Enter the license key as described above;

  4. Exit the foreground application and restart the MonitorIT Server service.

  • At this point you should be up and running Sentry II version 8.5.00.

  • Update the Agents using ‘Manage Agents’ to complete the setup.

Detailed Changes:

  • Performance enhancements to ‘Eligible Watches’ in ‘Configure->Servers/Agents & Devices’; enhance performance in the CounterWatch Alert cache processing;

  • Fix Agent Update OS version check issue; only download ‘WSNMP32.dll’ if NT 4.0;
    Change SNMP Query counter to handle unsigned 32-bit values;

  • Fix ‘Configure->Groups’ confirm prompt box; don’t show the servers/devices to avoid a prompt box that is too big to display properly;

  • Clean-up ‘Request CounterWatch Monitoring’ processing use of semaphore previously shared with Agent logon processing;

  • Update ‘InstallAgent.asp’ to skip downloading ‘WNSMP32.dll’ for all systems except NT where this file is not available by default; also, display the drive and folder where the file are being downloaded and saved;

  • Update the ‘Watch Report’ in ‘Configure->Watches/Alerts’ with options to selectively exclude various details to provide more of a summary;

  • Fix ‘Eligible Watches’ so a server can be added to multiple WinServiceWatches which have the same service; this is a result of no longer restricting a service to one Watch;

  • Enhance ‘Monitor->System Monitor’ with a new column that displays the Agent logon counts (‘LgCt’); abnormal Agent logon counts are indicative of a problem such as multiple Agents using the same name to logon;

  • Enhance Agent logon processing to monitor and handle Agents logging on too frequently or when they are already logged on; block Agents with varying delays when logging on too frequently, and insure previously used sockets and resources are freed when Agents connect and log on when already previously connected and logged on, all indicative of some problem either with Agent connectivity or installation;

  • Enhance ‘Archive->EventLog View/Archive & Report->View Archive Events’ and ‘View Current Events’ with a new ‘Exclude Description/Category’ option; this will skip the Event Description and Category lookups which can be very expensive in terms of performance; using the interactive ‘Viewer’, one can enable the Description & Category lookup when they have determined the events they want to drill-down on for details;

  • Enhance the ‘tool-tip’ pop-ups and other displays in MonitorIT that include the OS information so the user-friendly Windows OS name and version is displayed rather than the technical OS name;

  • Change WinServicesWatch so that one can define multiple Watches on the same service thereby proving additional flexibility in alerting and handling options;

  • Fix ‘Configure->Groups’ so that ‘ServerWatch’ is handled correctly when adding or deleting a server/device for a Group with a ServerWatch assigned; also fix the ‘Verify Consistency’ check with respect to ServerWatch; previously it was not handling this correctly;

  • Widen the ‘Watch/Alert Name’ field and list box in ‘Configure Watches/Alerts’;

  • Set the ‘.asp’ pages with the ‘mega’ tag to insure the page ‘charset’ is set to ‘Windows-1252’;

  • Fix the Logical Drive Free Space percentage in the Network Status Display details and in the email alert text; previously the percentage was incorrectly displayed as 0;

  • Add a new macro &C for substitution with the Group ‘Description’;

  • Fix ‘Monitor->HDD Monitor’ display for Linux/Unix drives; the values were previously incorrectly display as increased by a factor of 1024;

  • Fix ‘WinServicesWatch’ so that a change to the ‘Delay’ parameter will result in the appropriate Agents being notified of the change; previously, if this was the only change to the WinServicesWatch, the Agent was not notified;

  • Fix ‘WinServicesWatch’ so it now treats the service name and display name in conjunction, and creates new entries for unique display names even if the associated service name already exists under another display name in MonitorIT’s database;  this usually occurs when services are updated from a vendor; they may change the service display name but the underlying service name remains the same; the associated ‘WinServiceWatches’ are also updated accordingly to reflect the correct display name for a service on the particular servers;  previously, if a service name already existed in MonitorIT’s database, it did not update the display name and this could lead to confusion because one could not find the newer display name in the ‘WinServicesWatch’ display list of services, although the service was available for that server under the original, older display name;

  • Fix the Agent so that if Win64 then the calls to the WOW64 routines are made to turn-off the System32 redirection when reading the event ‘Description’ message file and category file and to restore the redirection when finished;

  • ToolTip enhancement to the various status display screens when hovering with the mouse over the server/device name; now the tool tip will display as long as the mouse hovers and the data is no longer truncated particular if long Notes; in the Network Status Display, in addition, the tool tip is fixed until another is selected or the tool tip is closed so that it is easy to select & copy information from it;

  • Fix problem with Archive Event Logs which would not name the archive file correctly if the Agent was using a name different from the machine name; since the uploaded archive files were not named correctly, the Archive Viewer would not ‘find’ them;

  • Fix problem with SNMP monitoring when setting a checkbox for an SNMP Counter in the ‘Monitored Object’ tree view of ‘CounterWatch Graphs’; previously setting the checkbox would not cause the counter to be monitored until the Agent was restarted/reconnected;

  • Fix problem with ProcessWatch in that some incorrect alert notifications were generated;

  • Fix problem with entering/editing ‘Custom OIDs’ in SNMPTrap Watches in ‘Configure->Watches/Alerts’;

  • Fix crash problem with ‘Edit’, ‘Duplicate’, and ‘New’ CounterWatch in ‘Configure->Watches/Alerts’ that would occur once number of servers exceeded approximately 700;

  • Fix problem caused by an Agent logging on with a blank name that would lead to duplicate bogus blank server entries that could not be deleted, or bogus entries named ‘New Computer 1’, ‘New Computer 2’, etc; now an Agent attempting to login with a blank name is rejected, and on startup any previous blank name entries in the database are purged;

  • Add a new Security settings of ‘Full Rights’ and ‘View Only’ to the ‘Allow Server/Device Maintenance’ setting in ‘Configure->Security’; ‘View Only’ rights on this setting means a user can view ‘Server/Device maintenance’ plans but cannot create and edit new plans or delete existing plans;

  • Enhance ‘Monitor->Memory Monitor’ with a new ‘Meter’ option that allows the user to specify the Caution and Critical Thresholds for the display meter, and to specify Units in either Percentage or Megabytes;

  • Enhance the ‘ServerWatch-AGENT Check’ type Watch in ‘Configure->Watches/Alerts’ so it now also supports an option to set the ‘VM’ Threshold as either a Percentage or as Megabytes for the Virtual Memory/Page File/Swap File monitoring;

  • Significant performance enhancement to the ‘Set CounterWatch Alert Cache’ operation; this cache is configured on startup, and whenever a CounterWatch changes;  the performance enhancement means functions that depend on using this cache, such as ‘Eligible Watches’ and working with CounterWatches, are usable and fast almost immediately after startup;

  • Fix problem with ‘Configure->Servers/Agents & Devices->Manage SNMP’ that would cause the ‘proxy’ Agent assignment for a non-Windows server or device to be deleted when making any changes to the SNMP configuration information for that  non-Windows server or device;

  • Fix problem with ‘Scheduled Periodic Reports’ with enhancement introduced in the previous version which would cause the ‘Logical Drive Utilization’, ‘Memory Utilization’, and the other build-in ‘snapshot’ reports to skip running;

  • Fix problem with the HDD check of Linux/Unix logical drives; previously, if any drive in the list of drives for a server had zero total bytes capacity, then all subsequent drives in the list for that server were not checked;

  • With the Linux/Unix Memory info, ignore negative values and skip processing Memory info until next reading;

  • With the Linux/Unix HDD Info, filter out drives that are mounted on ‘/mnt’ as these are removable drives;

  • Enhance the ‘Network Status Display’ with a ‘Show Faults Only’ option;

  • Clarify the ‘Configure->Groups’ handling of the pop-up option message and only show it when Severs, Watches and/or Reports have actually been removed from a Group; also don’t allow any Assigns until a New Group has been saved;

  • Enhance ‘Monitor->HDD Monitor’ with a new ‘Meter’ option that allows the user to specify the Caution and Critical Thresholds for the display meter, and to specify Units in either Percentage or Megabytes;

  • Enhance the ‘ServerWatch-AGENT Check’ type Watch in ‘Configure->Watches/Alerts’ so it now also supports an option to set the ‘Logical Drive’ Threshold as either a Percentage or as Megabytes;

  • Optimize loading of the EventLog, Syslog & SNMPTrap Displays and eliminate the occasional script error about an executing script taking too long;

  • Enhance ‘Schedule Periodic Reports’ so that the ‘Exclude Time Periods’ will now cause a scheduled report run to be skipped if the entire report period falls within an Excluded Time period; previously the report would run but there would be no data because it was all excluded;

  • Fix ‘Cancel’ in ‘Server/Device Maintenance’ so that all selected servers/devices on an Edit or Duplicate are reset on the cancel; previously the selected servers/devices were left set;

  • Enhance the status line of the ‘System Monitor’ display so that it includes the time, Syslog Status, and the Agent count;

  • Change the ‘Return to Normal’ message on the subject of an Email alert so that it is at then end of the Email Subject; previously it was at the beginning;

  • Enhance ‘Schedule Periodic Reports’ so that the ‘Exclude Time Periods’ will now cause a scheduled report run to be skipped if the entire report period falls within an Excluded Time period; previously the report would run but there would be no data because it was all excluded;

  • Fix ‘Cancel’ in ‘Server/Device Maintenance’ so that all selected servers/devices on an Edit or Duplicate are reset on the cancel; previously the selected servers/devices were left set;

  • Enhance the status line of the ‘System Monitor’ display so that it includes the time, Syslog Status, and the Agent count;

  • Change the ‘Return to Normal’ message on the subject of an Email alert so that it is at then end of the Email Subject; previously it was at the beginning;

  • Change ‘Memory Monitor’ so that an entry is displayed even if the configured Swap File space was zero; previously this was suppressed as invalid for Windows but it is possible for Linux/Unix;

  • Fix to the Agent Update process to extend the download time-out for each file; create the new download file images with Read/Write/Delete share so these images can be deleted on a subsequent update if the previous update is aborted for any reason leaving these new download images in place; previously if these images were left from an aborted update, it would block subsequent updates; also, have the AgentService.exe attempt to retry starting the Agent after an update switch up to 5 times if the initial service restart fails, and don’t abort if the rename of the downloaded files fails;

  • And on update, skip ‘WSNMP32.DLL’ if not NT4;

  • Fix problem in the Active Directory tree display when names had an apostrophe embedded; previously this would be misinterpreted in the ‘html’ causing a glitch in the tree display;

  • Fix problem with the left pane menu display; previously when using IE7 and switch between MonitorIT console displays, the menu pane would not always fully repaint;

  • Fix problem with the CounterWatch Graphs display; previously when exiting, IE would sometimes fault;

  • Enhance Server/Device Maintenance with Edit and Duplicate functions so now existing Maintenance Schedules can be edited,  or duplicated to use in creating a new Maintenance Schedule;

  • Fix problem in ‘Eligible Watches’ where previously not all available ServerWatch types, under some circumstances, would be displayed; and previously when switching from one ServerWatch of a particular type such as AGENT, to another of the same type, the new assignment would, again under some circumstances, not be saved;

  • Add e new Event Type option of ‘NONE’ to EventLogWatch; there are some existing applications that generate events that don’t specify the supported types of ‘Warning’, ‘Error’, ‘Information’, etc, rather they don’t specify any Type and so this is treated as ‘NONE’;

  • Enhance the FileWatch alert notification for a Size or Date/Time change alert; now it includes the previous size and date/time as well as the new size and date/time properties;

  • Enhance the Agent with a new Registry setting called ‘CounterWatch’ that can be set to OFF to suppress CounterWatch monitoring; in very rare circumstances, a call to Windows to query Objects/Counters hangs the Agent with high CPU; the fault lies with Windows as Performance Monitor (PERFMON) hangs the same way; see Microsoft Knowledge Base Article ID 196712;

  • Fix to CounterWatch Object/Counter database inventory handling so that it now self-corrects if Object/Counter indexes change, possibly due to the Object/Counter being toggled between enabled and disabled so that when they are re-enabled they have different local indexes which MonitorIT was not detecting; the symptom would be that CounterWatch data would not be captured because the Agent could not match up the Object that it was being told to monitor based on the previous obsolete index information coming from the MonitorIT database inventory;

  • Add new stand-alone Report entries for ‘EventLog Data’ and ‘Syslog Data’ in ‘Schedule Periodic Reports’ and ‘Run/analyze & View Reports’;

  • Fix ‘Group’ Report so that the Groups are sorted alphabetically;

  • Fix potential error loading Groups into the left-pane ‘Tree’ view in ‘Monitor->CounterWatch Graphs’;

  • Fix problem where under certain timing conditions an Agent that reconnects due to a server reboot may not be notified to begin CounterWatch monitoring; problem introduced with version 8.0.21 in May 07;

  • Fix problem in ‘Report->Schedule Periodic Reports’ when editing an ‘IP Services Availability & Performance’ Report and selecting specific servers/devices; previously the corresponding Watches would not expand;

  • Fix problem with the CounterWatch ‘tree view’ of Object and Counters in ‘Configure->Watches/Alerts’ and ‘Custom Collection Sets’ and ‘Create CounterWatch Reports’; under rare conditions, expanding an Object would previously yield a ‘No Counters Found’ result;

  • Fix problem with expansion of selected Counters when Editing a Custom Collection Set; previously, it would not fully expand under some conditions, and the Collection Set could not be edited;

  • Fix problem in ‘Configure->Watches/Alerts’ when doing a ‘Duplicate’ of a CounterWatch; previously it would not expand to the Counter;

  • Fix problem in ‘Report->Schedule Periodic Report’ when doing a EventLogWatch->Query and selecting Users/Groups from Active Directory; in some instances, you could not ‘Schedule’ this resulting report entry;

  • Fix the ‘Description’ information displayed in the ‘User Security’ Report in ‘Run/Analyze & View’;

  • Add a new macro ‘&P’ for the Server/Device ‘Description’; previously ‘&O’ was added for the Server/Device ‘Notes’;

  • Fix ‘Configure->Watches/Alerts->SNMPTrapWatch’ so that the ‘Edit’ and ‘Delete’ button are enabled if no servers/devices are assigned to the Watch;

  • Add Catch/Fault logic to the data receive handler to prevent RPMCCS.EXE faults, termination, and subsequent auto-restarts;

 

Previous Version Notes:

Version 8.0.27

  • Enhancements to the Network Status Display ‘Alert Details’ View:
    - Now the View is a summary which displays one entry with a count of occurrences and date/time of first and last occurrence for duplicate alert details;
    - And also Log Network Status Display ‘Alert Details’ Acknowledgements to an audit log file called ‘MonitorITAcknowledge.log’ in the ‘.\MonitorIT\Bin’ folder; of RPMCCS.exe started by the  Sentry II Server service;

  • Enhancement to the ‘Registry Monitor’ feature; it now supports a wild-card specification of asterisk ‘*’ for the ‘Value Name’ so that all Values, under the ‘Registry Key’ specification, are monitored for additions, deletions, or changes; and Keys are monitored for additions or deletions; it does not nest any further then the immediate level for the specified ‘Registry Key’; enhancement is to the MonitorIT Agent and Server;

  • Enhancement to ‘Configure->Servers/Agents & Devices’ Edit when doing a server/workstation rename; now the Agent is notified, if connected, of the new name and the Agent will subsequently use the new name when reconnecting; previously, one had to manually change the Agent Registry setting ‘LoginName’;

  • Enhancement to EventLogWatch processing for the option ‘Not Rcvd In x Minutes’ when monitoring for the absence of the occurrence of events; now an EventLogWatch with this option will reset the ‘Not Received’ timer regardless of the ‘Precedence’ of this Watch, and then the processing continues to look for matches with other EventLogWatches; thereby providing the ability to monitor both for the absence of occurrence with one Watch and the occurrence with another Watch;

  • Fix ‘Utilities->Server/Device Maintenance’ so that no Maintenance Plans are displayed if all the included servers/devices are restricted from viewing by the user due to Group restrictions; and prevent creating new Maintenance Plans or deleting existing plans if the user rights are ‘View Only’ Analyst rights;

  • Fix ‘Alert Notification’ Report for EventLog data when using the ‘Query’ option and specifying multiple ‘Source’ or ‘User/Group’ parameters; previously only the 1st in the list of multiple ‘Source’ or ‘User’ would be displayed; also applies to, and fixes, ‘View Monitored Events’ in ‘EventLog View/Archive & Report’;

  • Delay Object Purging, and consequently Object cache refresh, until all Agents have been queried for current list of Objects after a MonitorIT restart; this enhances performance by eliminating repeated purging and Object Cache refreshes for every Agent;

  • Fix edit of the Custom Event Log definition so if all existing defined Custom Event Logs are deleted, the change is propagated; previously, if all were deleted, the change was not propagated;

  • Enhance the Auto-Restart Monitoring that the MonitorIT Server Service engages in so that database errors, usually due to problems communicating with the database, and other serious system errors, are reflected in this monitoring
    so that an Auto-Restart of MonitorIT is triggered by the Service when serious errors are detected;

  • Enhancement to the ‘Alert Notifications’ Report in ‘Schedule Periodic Reports’ and ‘Run/Analyze & View’ with a new option to select one or more servers to report on all the selected associated Watches; previously the only option was to select a server in each associated Watch;

  • Fix problem with ProcessWatch for Linux/Unix; previously after editing an existing ProcessWatch for Linux/Unix, subsequent email alerts would be blank;

  • Fix problem with ‘Eligible Watches’ where under rare occasions the WinServiceWatches would not be displayed due to corruption in the cache;

  • Change Agent Install handling so that the first logon tried uses the Domain selected in ‘Manage Agents->Logon’;

  • Enhance ‘Report->Run/Analyze & View->New’ so that it closes the pop-up and runs the selected report immediately;

  • Enhance Agent logon processing so that a successful logon counts as receiving a ‘keep-alive’;

  • SyslogWatch enhancement to the ‘Content’ parameter handling; previously it only supported a substring match of a single substring versus the content of the Syslog message; now it supports multiple comma-delimited or plus-delimited substrings, where the comma treats each substring as a Boolean OR, and the plus treats each substring as a Boolean AND; the delimiters cannot be mixed; also now case insensitive;

  • Fix Status Code text in ‘Alert Notifications Report->WinServiceWatches’ for the ‘Service Running’; previously the Status Code text was ‘Restart Failed’ when it should be ‘Running’;

  • CounterWatch tree performance enhancements in ‘Configure->Watches/Alerts’ and ‘Report->Create CounterWatch Report->Custom Collection Sets’;

  • Enhance performance of creating and editing WinServiceWatches in ‘Configure->Watches/Alerts’;

  • Add the ‘Server/Workstation’ information tool tip to the HDD Monitor, Memory Monitor, and Registry Monitor displays;

  • Cosmetic enhancement to ‘Configure->Watches/Alerts’ and ‘Reports->Create CounterWatch Reports’ to show the ‘Server/Device Selected’ box in white background;

  • In WOW64 fix problem with EventLog Archiving Size and Percent options for archiving, and uploading to Archive Centrally; updated Agent to handle WOW64 file redirection for the System32 folder/subfolders;

  • Change function used to look-up Counter info that is used to create the CounterWatch cache;

  • Fix problem with View Archived Event Logs; if no Custom Event Log defined, then the View would fail to find any archive records for any of the archived event logs;

  • Performance enhancements to the MonitorIT Server startup processing;

  • Enhancements to support AIX and SCO/Unixware in the new ‘Linux/Unix’ Agent.

Version 8.0.20

  • Enhancement to Event Log Watch so that it now supports the monitoring, alerting, reporting and archiving of user specified Custom Event Logs;  also support the new Microsoft Event Logs “Virtual Server’ and ‘Internet Explorer’;

  • Extend the time-out from 30 seconds to 1 minute that the ‘SentryIIService.exe’ uses when checking the process RPMCCS.exe before deciding that the process did not start; this may address an occasional issue where there would be multiple instances of RPMCCS.exe started by the  Sentry II Server service;

  • Enable a log message for a WinServicesWatch alert with sufficient information about the alert and to track what actions were taken;

  • Fix a DST issue that was affecting ‘Server/Device Maintenance’ and ‘Schedule Periodic Reports’;

  • Fix problem with deleting a Secondary Group in ‘Configure->Groups’; also fix problem with displaying deleted Groups in Group pop-ups;

  • Fix so that Vista workstations show in the various console displays as a Windows machine;

  • Enhance ‘CounterWatch Graphs’ to show 6 decimal places in tool tip summary of counter data;

  • Additional refinements to ‘SentryIIService.exe’ to prevent multiple instance of RPMCCS.exe when the ‘EnumProcessModules’ API call fails;

  • Fix ‘ServerWatch Display’ so that all entries are shown when 1st opened; previously some entries were initially filtered out if the there was a recent Maintenance mode, or an AGENT disk or memory threshold alert; 

  • Fix problem with the ‘View CounterWatch Graphs’ faulting sometimes when exiting;

  • Enhancement to ‘Configure->Groups’ with the addition of a ‘Verify Consistency’ function that provides for checking the consistency of Watches/Alerts and Reports assignment to the servers/devices that are members of one or more selected Groups; the consistency check results are displayed with any found discrepancies in a pop-up display with checkbox options to correct and apply selected discrepancies;

  • Enhance the Agent and put the WMI check for Hardware Configuration information into a separate thread in order to isolate it from the Agent processing that was responsible for sending and receiving the keep-alive check; there have been occurrences where the API calls to check WMI would not return thus disrupting the keep-alive checking and causing ‘keep-alive’ timeout errors;

  • Enhancement to the ‘Monitor->System Monitor’ display and add buttons to the ‘Log’ column that pops-up a display to manage Agent logging on the selected server;

  • Enhancements to support the initial release of the Linux/Unix Agent;

  • Fix ‘CounterWatch Graphs’ so it correctly handles counters that have a negative default Scale; previously the values for such counters were processed as a zero value;

  • Enhancement to ‘Schedule Periodic Reports’ with a new ‘Properties’ tab that has a new option to specify a global, default Alternate Report Output folder;

  • Enhancement to handle spaces in an ‘Optional Report Name’ spec in ‘Schedule Periodic Reports’; previously, the spaces in the name were not handled correctly;

  • Performance Enhancement to ‘WinServicesWatch’ so that when saving a Watch only the servers that actually had a change are notified; previously every server in the Watch was notified causing a lot of unnecessary overhead; particular significant when a Watch has a 100+ servers;

  • Performance enhancement to the ‘Cycle Multiple Displays’; previously if 100+ servers were displayed, particularly with the ‘Network Status Display’, it would take up to 10 seconds every cycle to fully display and use high CPU to do it;

  • Purge the ‘Session’ table as part of the daily ‘Auto-Purge’; previously this database table which logs Console logins was not being purged;

  • Date/Time fixes to correct few remaining issues with support for DD/MM/YY format;

  • Fix to recreate WinServices memory cache if fault occurs during ‘Eligible Watches’ lookup;

  • Fix performance in ‘Schedule Periodic Report’ when Editing a previously Queued report; previously when expanding the server tree view for reports with many Watches and many servers in each Watch, the tree expansion would take a long time;

  • Fix problem with EventLog Archive Viewer and also with the Alert Notifications->EventLogWatch->Query option when specifying an Event ID range as a filter; also fix the ‘Source’ parameter so that it accepts a wild-card in a Source name;

  • Enhance the ‘Alert Notifications’ Report for the EventLog Watch ‘Query’ with a new option ‘Notified Only’ to report only events that resulted in an alert notification action;

  • In ‘Configure->Watches/Alert’ now support multiple ‘Trap Target Address’ parameters in the ‘Action->Snmp Trap’ option;

  • Enhance the SNMP Trap OID exclude definition so it now works when optionally specified as a wild-card;

  • Enhance the ‘Incl All’ checkbox option to apply to a wild-card File Name specification and ‘Maximum Size’ so that if checked then the total size of all files matching the wild-card specification are compared versus the ‘Maximum Size’; otherwise if unchecked the size of each individual file  matching the wild-card specification is compared versus the ‘Maximum Size’; 

  • Enhance the ‘Memory Monitor’ and ‘HDD Monitor’ displays with a new option to ‘Show Faults Only’, that is, entries that are below the 20% threshold;

  • Enhance the ‘Description’ parameter in ‘EventLogWatch’ handling so that it now accepts a plus sign as a delimiter for multiple substrings, treated as a Boolean AND, that must be found in an event description; support for a comma delimiter treated as a Boolean OR for multiple substrings is still present;  substrings are NOT case sensitive;

  • Fix problem with CounterWatch Instance names which previously would fail monitoring if the spelling changed case; now it auto-corrects the case change in the name;

  • Fix ‘ProcessWatch’ so it will handle a process name with a tilde (~) character in the name;

  • Fix problem with sending a ServerWatch ‘Restore’ notification; previously, under conditions where successive failures occurred with different causes, a ‘Restore’ notification may not have been sent; HTTP was a problem but other ServerWatch checks could be affected as well;

  • Fix Syslog report in ‘Alert Notifications’ so that the Host/IP field in the report correctly  reflected the name of the originating Host;

  • New ‘FileWatch’ option called ‘Incl All’ and used with the ‘NOT Check’ option and wild-carded File Name; the ‘Incl All’ option says that all the matching files for the wild-carded name must match the ‘Not Check’ for the alert condition to exist; for example, all files matching the wild-card must ‘Not’ change, or must not exist (i.e. deleted) for the alert condition to exist; if any file changed , or if any file exists, the alert is not generated;

  • Fix problem in ‘Configure->Groups’ where Group server and Watch assignment data was being truncated if amount of data was greater than 1024 bytes; the symptom would be that a particular Group entry could not be edited or deleted;

  • Fix problem with WinServicesWatch where under some conditions, there would be duplicate monitoring specification records in the database table ‘NTServicesMonitor’ that would cause ‘Configure->Watches/Alerts’ to load very slowly;

  • Fix the Menu group buttons in the left pane so that they display without dithering when running in video modes of 256 colors;

  • New option to define Date format of DD/MM/YY versus the default MM/DD/YYYY; new button in upper-right of the Console display to change the date format for the local console only; format choice is persistent for the local console; selected Date format applies to any local console display as well as any Reports scheduled or edited;

  • New EventLogWatch options on the ‘Schedule’ tab to: (1) optionally include the Event Description in the ‘x Times in Y Seconds’ alert filter; and (2) optionally log to database only when the ‘x Times in Y Seconds’ criteria is met;

Version 8.0  

  • Total secure Agent and Console communications, using an encrypted and compressed message protocol over TCP connections, with the central Sentry II Server for all Agent and Console communications

  • Now, you can optionally configure remote, distributed SYSLOG and SNMP Trap & Query monitoring using one or more deployed Sentry II Agents running on a Windows machine as a service, and all transparently integrated with the central Sentry II Server and Sentry II's standard Watches, Displays, and Reports using Sentry II's Internet Explorer based console.

  • Groups enhanced:

  • New 'Secondary' Group concept where a server/device can belong to multiple 'Secondary' Groups; original Groups are now designated as 'Primary' Groups.

  • Watches and CounterWatch Reports can be assigned to the original 'Primary' Groups and the new 'Secondary' Groups; servers/devices assigned to Groups automatically pick up the Watches and CounterWatch Reports that are assigned to the Groups.

  • Designate 'Default' Secondary Groups so that any new Agents are automatically assigned to one or more 'Default' Secondary Groups and thus automatically pick up the Watches and CounterWatch Reports.

Active Directory Integration:

  • In 'Configure->Security' for the Sentry II console, you can pick from your list of Active Directory Groups or Users. If you specify a Group, then any member of that Group is authorized. In both Groups and Users, the authentication is done via Active Directory so you do not provide any passwords in 'Configure->Security'; the password you provide when you log on is authenticated through a call to Active Directory so the user can use the same UserName/Password as he uses for Windows.

  • In Event Log Watches, you can you can pick from your list of Active Directory Groups and Users for the 'User' parameter, and if you specify a Group, then any User in the Group would match on the event criteria. This makes it easier to define an Event Log Watch rule to monitor, for example, changes to the Administrators Group.

  • In the Event Log Archive Viewer as well as in the Event Log Reports->Query setup you will also be able to use the same pick list of your current Active Directory Groups and Users when defining filters for the Viewer or for the Reports making it easier to be selective on what you are filtering for reporting and viewing.

  • Monitor Hardware Configuration for changes and optionally alert when changes are detected

  • Monitor selected Registry Keys/Values for changes and optionally alert when changes are detected 

  • Monitor and optionally alert when server reboots/restarts are detected 

  • Significantly enhance ‘Alert Notification’ Report performance for EventLogWatch using the 'Query' and Syslog with 'Query'; in some scenarios the enhancement is as much as 50 to 1 and what previously took hours to complete now completes in minutes

  • Add a new 'Large Icon' option to the 'Network Status' dashboard display so that status icons are more easily viewed from a distance.

Version 7.0

  • Enhanced EventLog View/Archive & Report function with a flexible, interactive Viewer for Events in Archived Event Logs, in the Sentry II database, and/or in current Event Log files on selected servers/workstations; option to Save & Load Filters; option to Print, Email, or Export to CSV file the Event View results; option to set the "MaxFileSize" parameter for any or all Event Log files on any or all selected servers/workstations  

  • Archived Event Log files now saved compress in a GZIP format  

  • New Archive option to archive when an Event Log file exceeds a specified percentage full. 

  • New Import features in Configure Servers/Agents & Devices and Configure Groups to import and add from a comma-delimited list

  • New “Watch Templates” feature in Configure Watches/Alerts with predefined parameters for various Watch types

  • New “RegistryWatch Monitoring” feature to monitor and display select Registry values for all servers/workstations  

  • Change maximum “Status Interval” in Network Status Display to 120 hours (5 days)

  • New ‘self-monitoring’ auto-restart feature for the Sentry II Server component; it now sends a ‘keep-alive’ signal to the Sentry II Server service once per minute, and if not received within 15 minutes; the service terminates and restarts the Sentry II Server component 

  • Enhanced Agent / Server ‘keep-alive’ exchange and Agent check for Agent connectivity; Server now echoes back an Agent ‘keep-alive’ and Agent now checks for the response; attempts reconnection on failure to receive echoes; Server insures Agent successfully logged on before accepting ‘keep-alive’

  • Agent fixed to include an Event’s Description parameters even if the Event’s Message file cannot be found to resolve the description text

Version 6.0  

  • New Auto upload & archive Event Log EVT files to a central store based on one or more, totally flexible Archive Schedules

  • New 'CustomWatch' feature. Execute any Windows program, command, batch, or script executable, on a periodic schedule, at selected servers/workstations, and optionally alert if the Exit Code fails a comparison with a specified exit code.

  • New alert notification options; send an alert notification as an SNMP Trap or as a SYSLOG message

  • Enhanced Security with User logons restricted to viewing and working only with authorized server/device Groups, and Report and Chart ownership limiting who can view and use Reports and Charts

  • Monitor Select Windows Processes with 'ProcessWatch'; restart processes that should be running and terminate processes that should not be running;

  • Monitor CPU & Memory utilization thresholds on a per process basis

  • Track and Display Hardware Configuration details of your monitored Windows servers & workstations

  • Consolidated Network Status Display; and Memory and Logical Drive Monitoring Displays

 

Download FileAudit

Free Product Download

Download

Release Notes
 

Documentation
Reports
User Manual
Event IDs
Overview
Details
Features
Evaluating Automated Security Tools
Sarbanes-Oxley Compliance
Why you should monitor your event logs
 

White Paper

Event Log Management Cost Justification

Reviews

Customer Endorsements

© 2002-2007 Engagent