{"id":492,"date":"2025-03-27T13:21:42","date_gmt":"2025-03-27T12:21:42","guid":{"rendered":"https:\/\/whoami.lausitz-event.info\/?p=492"},"modified":"2025-03-27T13:43:10","modified_gmt":"2025-03-27T12:43:10","slug":"nsclient-checks","status":"publish","type":"post","link":"https:\/\/whoami.lausitz-event.info\/?p=492","title":{"rendered":"NSClient.ini Konfiguration"},"content":{"rendered":"\n\n<p><a href=\"https:\/\/whoami.lausitz-event.info\/wp-content\/uploads\/2025\/03\/windows.zip\">Download Windows Plugins<\/a><\/p>\n\n\n\n\n\n<pre class=\"wp-block-code\"><code>&#91;\/modules]\nCheckDisk = 1\nCheckEventLog = 1\nCheckExternalScripts = 1\nCheckHelpers = 1\nCheckNSCP = 1\nCheckSystem = 1\nCheckTaskSched = 1\nNRPEServer = 1\nNSCAClient = 1\nNSClientServer = 1\n\n&#91;\/settings\/default]\nallowed hosts = X.X.X.X\n\n&#91;\/settings\/NRPE\/server]\nallow arguments = true\nallow nasty characters=1\nallowed ciphers = ALL\nssl options = no-sslv2,no-sslv3\nverify mode = none\ninsecure = false\n\n&#91;\/settings\/external scripts\/server]\nallow arguments = true\n\n&#91;\/settings\/external scripts]\nallow arguments = true\nallow nasty characters=1\n\n&#91;\/settings\/external scripts\/wrapped scripts]\ncheck_updates=check_windows_updates.ps1 $ARG1$\ncheck_ad_account=lotp_check_ad_accounts.ps1 $ARG1$ $ARG2$ $ARG3$ $ARG4$ $ARG5$\n\n&#91;\/settings\/external scripts\/scripts]\ndirectory_file_count = c:\\windows\\system32\\cscript.exe \/\/NoLogo \/\/T:30 C:\\Programme\\nsclient++\\scripts\\directory_file_count.wsf \"$ARG1$\" $ARG2$ $ARG3$\ncheck_users=scripts\\check_users.exe -n -w $ARG1$ -c $ARG2$\ncheck_win_perfmon=scripts\\check_win_perfmon.exe -f scripts\/$ARG1$\ncheck_time=cscript.exe \/T:30 \/NoLogo scripts\\check_time.vbs 131.188.3.221,131.188.3.222,131.188.3.223 20 240\ncheck_ad=cscript.exe \/\/NoLogo \/\/T:60 \"C:\\Program Files\\NSClient++\\scripts\\check_active_directory.vbs\"\n\n\n&#91;\/settings\/external scripts\/alias]\n\n; alias_cpu - Alias for alias_cpu. To configure this item add a section called: \/settings\/external scripts\/alias\/alias_cpu\nalias_cpu = checkCPU warn=$ARG1$ crit=$ARG2$ time=5m time=1m time=30s\nalias_disk = CheckDriveSize MaxWarn=$ARG1$ MaxCrit=$ARG2$ Drive=C: FilterType=FIXED\nalias_process = checkProcState ShowAll \"$ARG1$=started\"\nalias_service = checkServiceState ShowAll \"$ARG1$=started\"\nalias_up = checkUpTime MinWarn=1d MinWarn=1h\nalias_counter = CheckCounter \"Counter:$ARG1$=$ARG2$\" ShowAll MaxWarn=$ARG3$ MaxCrit=$ARG4$\nalias_event_log = CheckEventLog file=system MaxWarn=1 MaxCrit=2 \"filter=generated&gt;-24h AND severity='error' AND NOT (id='36887' OR id='36882' OR id ='36888')\" unique descriptions \"syntax=%severity%: %source%\"\n;alias_event_sys = CheckEventLog file=system MaxWarn=1 MaxCrit=1 \"filter=(generated gt -2h) AND (type IN ('1', '0'))\" truncate=800 unique descriptions \"syntax=%severity%: %generated%: %source%: %message% (%count%)\"\nalias_event_security = CheckEventLog file=security MaxWarn=2 MaxCrit=3 \"filter=generated&gt;-3d AND id='4625'\" unique descriptions \"syntax=%id%: %source%\"\n\n;\\\\DC\\Netzwerkschnittstelle(Intel&#91;R] PRO_1000 MT Network Connection)\\Gesamtanzahl Bytes\/s\n\n;alias_updates = check_updates -warning 0 -critical 0\n;alias_cpu_ex = checkCPU warn=$ARG1$ crit=$ARG2$ time=5m time=1m time=30s\n;alias_disk_loose = CheckDriveSize MinWarn=10% MinCrit=5% CheckAll FilterType=FIXED ignore-unreadable\nalias_file_age = checkFile2 filter=out \"file=$ARG1$\" filter-written=&gt;1d MaxWarn=1 MaxCrit=1 \"syntax=%filename% %write%\"\nalias_file_size = CheckFiles \"filter=size &gt; $ARG2$\" \"path=$ARG1$\" MaxWarn=1 MaxCrit=1 \"syntax=%filename% %size%\" max-dir-depth=10\nalias_mem = checkMem MaxWarn=$ARG1$ MaxCrit=$ARG2$ ShowAll=long type=physical type=virtual type=paged type=page\n;alias_process_count = checkProcState MaxWarnCount=$ARG2$ MaxCritCount=$ARG3$ \"$ARG1$=started\"\n;alias_process_hung = checkProcState MaxWarnCount=1 MaxCritCount=1 \"$ARG1$=hung\"\n;alias_process_stopped = checkProcState \"$ARG1$=stopped\"\n;alias_sched_all = CheckTaskSched \"filter=exit_code ne 0\" \"syntax=%title%: %exit_code%\" warn=&gt;0\n;alias_sched_long = CheckTaskSched \"filter=status = 'running' AND most_recent_run_time &lt; -$ARG1$\" \"syntax=%title% (%most_recent_run_time%)\" warn=&gt;0\n;alias_sched_task = CheckTaskSched \"filter=title eq '$ARG1$' AND exit_code ne 0\" \"syntax=%title% (%most_recent_run_time%)\" warn=&gt;0\n;alias_service = checkServiceState CheckAll\n;alias_service_ex = checkServiceState CheckAll \"exclude=Net Driver HPZ12\" \"exclude=Pml Driver HPZ12\" exclude=stisvc\n;alias_volumes = CheckDriveSize MinWarn=10% MinCrit=5% CheckAll=volumes FilterType=FIXED\n;alias_volumes_loose = CheckDriveSize MinWarn=10% MinCrit=5% CheckAll=volumes FilterType=FIXED ignore-unreadable \n\n;##############\n\nsys = CheckEventLog file=system MaxWarn=1 MaxCrit=1 \"filter=(generated gt -6000m) AND (severity NOT IN ('success', 'informational', 'warning'))\" truncate=800 unique descriptions \"syntax=%severity%: %type%: %generated%: %source%: %message% (%count%)\"\n; geht sys=CheckEventLog file=system MaxWarn=1 MaxCrit=1 \"filter=(generated gt -3d) AND (severity NOT IN ('success', 'informational', 'warning'))\" truncate=800 unique descriptions \"syntax=%severity%: %type%: %generated%: %source%: %message% (%count%)\"\n\nevent_app = CheckEventLog file=application MaxWarn=1 MaxCrit=1 \"filter=(generated gt -$ARG1$) AND (type IN ('1', '0')) AND (severity NOT IN ('success', 'informational', 'warning'))\" truncate=800 unique descriptions \"syntax=%source%: (%count%)\"\nevent_sys = CheckEventLog file=system MaxWarn=1 MaxCrit=1 \"filter=(generated gt -$ARG1$) AND (type IN ('1', '0')) AND (severity NOT IN ('success', 'informational', 'warning'))\" truncate=800 unique descriptions \"syntax=%source%: (%count%)\"\nevent_sev = CheckEventLog file=\"Symantec Enterprise Vault\" MaxWarn=1 MaxCrit=1 \"filter=(generated gt -$ARG1$) AND (type IN ('1', '0')) AND (severity NOT IN ('success', 'informational', 'warning'))\" truncate=800 unique descriptions \"syntax=%source%: (%count%)\"\neventlog_error = CheckEventLog file=system file=application file=\"Symantec Enterprise Vault\" MaxWarn=1 MaxCrit=1 \"filter=(generated gt -$ARG1$) AND (type IN ('1', '0')) AND (severity NOT IN ('success', 'informational', 'warning'))\" truncate=800 unique descriptions \"syntax=%source%: (%count%)\"\nevent_sec = CheckEventLog file=security MaxWarn=1 MaxCrit=1 \"filter=(generated gt -6m) AND (type IN ('1', '0')) AND (severity NOT IN ('success', 'informational', 'warning'))\" truncate=800 unique descriptions \"syntax=%generated%: %severity%: %source%: (%count%)\"\n\nsys-info = CheckEventLog file=system MaxWarn=1 MaxCrit=1 \"filter=(generated gt -1d) AND (type IN ('error', 'critical'))\" truncate=800 unique descriptions \"syntax=%severity%: %generated%: %source%: %message% (%count%)\"\nsystem_error = CheckEventLog file=system MaxWarn=1 MaxCrit=1 \"filter=(generated gt -6m) AND (type IN ('1', '0')) AND (severity NOT IN ('success', 'informational', 'warning'))\" truncate=800 unique descriptions \"syntax=%generated%: %type%: %severity%: %source%: %message% (%count%)\"\n;CheckEventLog debug=true file=Anwendung MaxWarn=1 MaxCrit=1 \"filter=generated gt -1h AND type = 'info'\" truncate=800 unique descriptions \"syntax=%generated%: (%count%)\n\n;Test MMS:\nevt_app_err = CheckEventLog file=Anwendung MaxWarn=1 MaxCrit=1 \"filter=(generated gt -15m) AND (type IN ('1', '0')) AND (severity NOT IN ('success', 'informational', 'warning'))\" truncate=800 unique descriptions \"syntax=%severity%: %generated%: %source%: %message% (%count%)\"\nevt_sys_err = CheckEventLog file=System MaxWarn=1 MaxCrit=1 \"filter=(generated gt -15m) AND (type IN ('1', '0')) AND (severity NOT IN ('success', 'informational', 'warning'))\" truncate=800 unique descriptions \"syntax=%severity%: %generated%: %source%: %message% (%count%)\"\nevt_sec_err = CheckEventLog file=Sicherheit MaxWarn=1 MaxCrit=1 \"filter=(generated gt -15m) AND (type IN ('1', '0')) AND (severity NOT IN ('success', 'informational', 'warning'))\" truncate=800 unique descriptions \"syntax=%severity%: %generated%: %source%: %message% (%count%)\"\nevt_err=CheckEventLog file='$ARG1$' MaxWarn=1 MaxCrit=1 \"filter=(generated gt -15m) AND (type IN ('1', '0')) AND (severity NOT IN ('success', 'informational', 'warning'))\" truncate=800 unique descriptions \"syntax=%severity%: %generated%: %source%: %message% (%count%)\"\nevt=CheckEventLog file=application MaxWarn=1 MaxCrit=1 \"filter=(generated gt -15m) AND (type IN ('1', '0')) AND (severity NOT IN ('success', 'informational', 'warning'))\" truncate=800 unique descriptions \"syntax=%severity%: %generated%: %source%: %message% (%count%)\"\nevt_hw_err = CheckEventLog file=Hardware-Ereignisse MaxWarn=1 MaxCrit=1 \"filter=(generated gt -15m) AND (type IN ('1', '0')) AND (severity NOT IN ('success', 'informational', 'warning'))\" truncate=800 unique descriptions \"syntax=%severity%: %generated%: %source%: %message% (%count%)\"\nevt_OD_err = CheckEventLog \"file=Microsoft Office Diagnostics\" MaxWarn=1 MaxCrit=1 \"filter=(generated gt -15m) AND (type IN ('1', '0')) AND (severity NOT IN ('success', 'informational', 'warning'))\" truncate=800 unique descriptions \"syntax=%severity%: %generated%: %source%: %message% (%count%)\"\nevt_OS_err = CheckEventLog \"file=Microsoft Office Sessions\" MaxWarn=1 MaxCrit=1 \"filter=(generated gt -15m) AND (type IN ('1', '0')) AND (severity NOT IN ('success', 'informational', 'warning'))\" truncate=800 unique descriptions \"syntax=%severity%: %generated%: %source%: %message% (%count%)\"\n\nevt_source = CheckEventLog file=application MaxWarn=1 MaxCrit=1 \"filter=(generated gt -6m) AND \"filter=id = 1008\"\" truncate=800 unique descriptions \"syntax=%severity%: %generated%: %source%: %message% (%count%)\"\nevt_d = CheckEventLog file=Anwendung MaxWarn=1 MaxCrit=2 \"filter=(generated gt -1d) AND (id = '1003')\" truncate=800 unique descriptions \"syntax=%generated%: %source%: (%count%)\"\nevt = CheckEventLog file=application debug=true MaxWarn=1 MaxCrit=1 \"filter=(generated gt -50m) AND (source = 'SideBySide')\" truncate=800 unique descriptions \"syntax=%source%: (%count%)\"\nevt-a = CheckEventLog file=application debug=true MaxWarn=1 MaxCrit=1 \"filter=(generated gt -50m) AND (source = 'SideBySide')\" truncate=800 unique descriptions \"syntax=%source%: (%count%)\"\nevtid = CheckEventLog file=application debug=true MaxWarn=1 MaxCrit=1 \"filter=(generated gt -50m) AND (source = 'SideBySide') AND (id = 33)\" truncate=800 unique descriptions \"syntax=%source%: (%count%)\"\n\nevt-s = CheckEventLog file='$ARG1$' debug=true MaxWarn=1 MaxCrit=1 \"filter=(generated gt -$ARG3$m) AND (source = '$ARG2$')\" truncate=800 unique descriptions \"syntax=%source%: %message% (%count%)\"\nevt-id = CheckEventLog file='$ARG1$' debug=true MaxWarn=1 MaxCrit=1 \"filter=(generated gt -$ARG3$m) AND (id = $ARG2$)\" truncate=800 unique descriptions \"syntax=%source%: %message% (%count%)\"\nevt-s-id = CheckEventLog file='$ARG1$' debug=true MaxWarn=1 MaxCrit=1 \"filter=(generated gt -$ARG4$m) AND (source = '$ARG2$') AND (id = $ARG3$)\" truncate=800 unique descriptions \"syntax=%source%: %message% (%count%)\"\n\n;Performance \u00fcber CheckCounter\nperfcounter = CheckCounter \"$ARG1$\" ShowAll MaxWarn=$ARG2$ MaxCrit=$ARG3$\nproc2 = CheckCounter \"$ARG1$\" ShowAll MaxWarn=$ARG2$ MaxCrit=$ARG3$\nproc = CheckCounter \"Counter:proc=\\Prozessor(_Total)\\Prozessorzeit (%)\" ShowAll MaxWarn=5 MaxCrit=10\nproc0 = CheckCounter \"Counter:proc=\\Prozessor(0)\\Prozessorzeit (%)\" ShowAll MaxWarn=5 MaxCrit=10\nproc1 = CheckCounter \"Counter:proc=\\Prozessor(1)\\Prozessorzeit (%)\" ShowAll MaxWarn=5 MaxCrit=10\nmem=CheckCounter \"Counter:Speicher verfuegbare MB=\\Arbeitsspeicher\\Verf\u00fcgbare MB\" ShowAll MinWarn=20 MinCrit=10\nphys = CheckCounter \"Counter:phys=\\Physikalischer Datentr\u00e4ger(_Total)\\Zeit (%)\" ShowAll MaxWarn=5 MaxCrit=10\n\nmulti = CheckMultiple command=checkCPU warn=80 crit=90 time=5m time=1m time=30s command=CheckMeM MaxWarn=80% MaxCrit=90% command=CheckDriveSize MinWarn=10% MinCrit=5% CheckAll FilterType=FIXED\nmulti1 = CheckMultiple command=CheckCounter \"Counter:proc=\\Prozessor(_Total)\\Prozessorzeit (%)\" ShowAll MaxWarn=95 MaxCrit=98 command=CheckCounter \"Counter:proc0=\\Prozessor(0)\\Prozessorzeit (%)\" ShowAll MaxWarn=85 MaxCrit=95 command=CheckCounter \"Counter:proc1=\\Prozessor(1)\\Prozessorzeit (%)\" ShowAll MaxWarn=85 MaxCrit=95\n\n;Drivesize absolut\ndisk_absolute_free = CheckDriveSize ShowAll MinWarnFree=$ARG1$ MinCritFree=$ARG2$ Drive=$ARG3$\ndisk_absolute_Used = CheckDriveSize ShowAll MaxWarnUsed=$ARG1$ MaxCritUsed=$ARG2$ Drive=$ARG3$\ndisk_absolute = CheckDriveSize $ARG1$ $ARG2$ $ARG3$ $ARG4$\n\n;TaskSched\nTaskSched1 = CheckTaskSched +filter-exit-code==0 ShowAll MaxWarn=0 MaxCrit=0  \n\n; '\\Processor(_Total)\\% User Time'=0;20;10; '\\Processor(0)\\% User Time'=0;20;10; '\\Processor(1)\\% User\nCounterMax = CheckCounter \"Counter:$ARG1$=$ARG2$\" ShowAll MaxWarn=$ARG3$ MaxCrit=$ARG4$\nCounterMin = CheckCounter \"Counter:$ARG1$=$ARG2$\" ShowAll MinWarn=$ARG3$ MinCrit=$ARG4$\n\n; Verzeichnisgroesse:\ndir-a = CheckFileSize ShowAll MaxWarn=1024M MaxCrit=4096M File:DIR-A=c:\\WINDOWS\\*.*\n\n;Dateiattribute\npagefile = CheckFileSize ShowAll MinWarn=800M  MinCrit=512M File:Page=c:\\pagefile.sys\nfileage = CheckFiles path=C:\\TMP pattern=*.* \"filter=creation &gt; -1d and line_count &lt; 100\" \"syntax=%filename%: %size% %line_count% %creation% %access%\" MaxWarn=1 MaxCrit=1\nfa-nsc = CheckFiles path=C:\\Programme\\NSClient++ pattern=nsclient.ini \"filter=access &lt; 1d\" \"syntax=%filename%: %size% %line_count% %creation% %access% %write%\" MaxWarn=1 MaxCrit=1\n\n;##################################\n\n\ndefault = \n<\/code><\/pre>\n\n\n","protected":false},"excerpt":{"rendered":"<p>Download Windows Plugins<\/p>","protected":false},"author":2,"featured_media":0,"comment_status":"closed","ping_status":"closed","sticky":false,"template":"","format":"standard","meta":{"site-sidebar-layout":"default","site-content-layout":"","ast-site-content-layout":"default","site-content-style":"default","site-sidebar-style":"default","ast-global-header-display":"","ast-banner-title-visibility":"","ast-main-header-display":"","ast-hfb-above-header-display":"","ast-hfb-below-header-display":"","ast-hfb-mobile-header-display":"","site-post-title":"","ast-breadcrumbs-content":"","ast-featured-img":"","footer-sml-layout":"","ast-disable-related-posts":"","theme-transparent-header-meta":"default","adv-header-id-meta":"","stick-header-meta":"","header-above-stick-meta":"","header-main-stick-meta":"","header-below-stick-meta":"","astra-migrate-meta-layouts":"set","ast-page-background-enabled":"default","ast-page-background-meta":{"desktop":{"background-color":"var(--ast-global-color-4)","background-image":"","background-repeat":"repeat","background-position":"center center","background-size":"auto","background-attachment":"scroll","background-type":"","background-media":"","overlay-type":"","overlay-color":"","overlay-opacity":"","overlay-gradient":""},"tablet":{"background-color":"","background-image":"","background-repeat":"repeat","background-position":"center center","background-size":"auto","background-attachment":"scroll","background-type":"","background-media":"","overlay-type":"","overlay-color":"","overlay-opacity":"","overlay-gradient":""},"mobile":{"background-color":"","background-image":"","background-repeat":"repeat","background-position":"center center","background-size":"auto","background-attachment":"scroll","background-type":"","background-media":"","overlay-type":"","overlay-color":"","overlay-opacity":"","overlay-gradient":""}},"ast-content-background-meta":{"desktop":{"background-color":"var(--ast-global-color-5)","background-image":"","background-repeat":"repeat","background-position":"center center","background-size":"auto","background-attachment":"scroll","background-type":"","background-media":"","overlay-type":"","overlay-color":"","overlay-opacity":"","overlay-gradient":""},"tablet":{"background-color":"var(--ast-global-color-5)","background-image":"","background-repeat":"repeat","background-position":"center center","background-size":"auto","background-attachment":"scroll","background-type":"","background-media":"","overlay-type":"","overlay-color":"","overlay-opacity":"","overlay-gradient":""},"mobile":{"background-color":"var(--ast-global-color-5)","background-image":"","background-repeat":"repeat","background-position":"center center","background-size":"auto","background-attachment":"scroll","background-type":"","background-media":"","overlay-type":"","overlay-color":"","overlay-opacity":"","overlay-gradient":""}},"footnotes":""},"categories":[9,3],"tags":[],"class_list":["post-492","post","type-post","status-publish","format-standard","hentry","category-icinga","category-it"],"_links":{"self":[{"href":"https:\/\/whoami.lausitz-event.info\/index.php?rest_route=\/wp\/v2\/posts\/492","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/whoami.lausitz-event.info\/index.php?rest_route=\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/whoami.lausitz-event.info\/index.php?rest_route=\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/whoami.lausitz-event.info\/index.php?rest_route=\/wp\/v2\/users\/2"}],"replies":[{"embeddable":true,"href":"https:\/\/whoami.lausitz-event.info\/index.php?rest_route=%2Fwp%2Fv2%2Fcomments&post=492"}],"version-history":[{"count":6,"href":"https:\/\/whoami.lausitz-event.info\/index.php?rest_route=\/wp\/v2\/posts\/492\/revisions"}],"predecessor-version":[{"id":501,"href":"https:\/\/whoami.lausitz-event.info\/index.php?rest_route=\/wp\/v2\/posts\/492\/revisions\/501"}],"wp:attachment":[{"href":"https:\/\/whoami.lausitz-event.info\/index.php?rest_route=%2Fwp%2Fv2%2Fmedia&parent=492"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/whoami.lausitz-event.info\/index.php?rest_route=%2Fwp%2Fv2%2Fcategories&post=492"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/whoami.lausitz-event.info\/index.php?rest_route=%2Fwp%2Fv2%2Ftags&post=492"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}