Chapter 17: Watching Your System BAI617. Chapter Topics Working With Event Viewer Performance Monitor Resource Monitor.

Slides:



Advertisements
Similar presentations
Networking Essentials Lab 3 & 4 Review. If you have configured an event log retention setting to Do Not Overwrite Events (Clear Log Manually), what happens.
Advertisements

Guide to MCSE , Enhanced 1 Activity 14-1: Browsing Security Templates Objective: To become familiar with built-in security templates Start  Run.
Optimizing Windows Vista Performance Lesson 10. Skills Matrix Technology SkillObjective DomainObjective # Introducing ReadyBoostTroubleshoot performance.
Hands-On Microsoft Windows Server 2003 Administration Chapter 10 Monitoring and Troubleshooting Windows Server 2003.
70-290: MCSE Guide to Managing a Microsoft Windows Server 2003 Environment Chapter 14: Windows Server 2003 Security Features.
70-290: MCSE Guide to Managing a Microsoft Windows Server 2003 Environment Chapter 11: Monitoring Server Performance.
Chapter 11 - Monitoring Server Performance1 Ch. 11 – Monitoring Server Performance MIS 431 – created Spring 2006.
MCDST : Supporting Users and Troubleshooting a Microsoft Windows XP Operating System Chapter 10: Collect and Analyze Performance Data.
70-270, MCSE/MCSA Guide to Installing and Managing Microsoft Windows XP Professional and Windows Server 2003 Chapter Thirteen Performing Network.
11 MONITORING MICROSOFT WINDOWS SERVER 2003 Chapter 3.
Hands-On Microsoft Windows Server 2003 Administration Chapter 6 Managing Printers, Publishing, Auditing, and Desk Resources.
Maintaining and Updating Windows Server 2008
MCTS Guide to Microsoft Windows Server 2008 Network Infrastructure Configuration Chapter 11 Managing and Monitoring a Windows Server 2008 Network.
70-291: MCSE Guide to Managing a Microsoft Windows Server 2003 Network Chapter 14: Troubleshooting Windows Server 2003 Networks.
Check Disk. Disk Defragmenter Using Disk Defragmenter Effectively Run Disk Defragmenter when the computer will receive the least usage. Educate users.
Using the Windows Event Viewer and Task Scheduler Chapter 5.
Chapter 9 Overview  Reasons to monitor SQL Server  Performance Monitoring and Tuning  Tools for Monitoring SQL Server  Common Monitoring and Tuning.
Hands-On Microsoft Windows Server 2008 Chapter 11 Server and Network Monitoring.
CH 13 Server and Network Monitoring. Hands-On Microsoft Windows Server Objectives Understand the importance of server monitoring Monitor server.
Windows Server 2008 Chapter 11 Last Update
Event Viewer Was of getting to event viewer Go to –Start –Control Panel, –Administrative Tools –Event Viewer Go to –Start.
CONTENTS:-  What is Event Log Service ?  Types of event logs and their purpose.  How and when the Event Log is useful?  What is Event Viewer?  Briefing.
70-290: MCSE Guide to Managing a Microsoft Windows Server 2003 Environment, Enhanced Chapter 12: Managing and Implementing Backups and Disaster Recovery.
M ONITORING SERVER PERFORMANCE Unit objectives Use Task Manager to monitor server performance and resource usage Use Event Viewer to identify and troubleshoot.
Virtual Memory Tuning   You can improve a server’s performance by optimizing the way the paging file is used   You may want to size the paging file.
Network and Active Directory Performance Monitoring and Troubleshooting NETW4008 Lecture 8.
1 Chapter Overview Monitoring Server Performance Monitoring Shared Resources Microsoft Windows 2000 Auditing.
Monitoring and Troubleshooting Chapter 17. Review What role is required to share folders on Windows Server 2008 R2? What is the default permission listed.
Ch 11 Managing System Reliability and Availability 1.
1 Chapter Overview Planning an Audit Policy Implementing an Audit Policy Using Event Viewer.
®® Microsoft Windows 7 for Power Users Tutorial 8 Troubleshooting Windows 7.
September 18, 2002 Introduction to Windows 2000 Server Components Ryan Larson David Greer.
CN1176 Computer Support Kemtis Kunanuraksapong MSIS with Distinction MCT, MCTS, MCDST, MCP, A+
CH 6 Configuring Server Hardware and power options.
A+ Guide to Software Managing, Maintaining and Troubleshooting THIRD EDITION Chapter 6 Managing and Troubleshooting Windows 2000.
Managing and Monitoring Windows 7 Performance Lesson 8.
Module 7: Fundamentals of Administering Windows Server 2008.
70-290: MCSE Guide to Managing a Microsoft Windows Server 2003 Environment, Enhanced Chapter 11: Monitoring Server Performance.
Module 10: Monitoring ISA Server Overview Monitoring Overview Configuring Alerts Configuring Session Monitoring Configuring Logging Configuring.
DIT314 ~ Client Operating System & Administration CHAPTER 5 MANAGING USER ACCOUNTS AND GROUPS Prepared By : Suraya Alias.
Windows Vista Inside Out Chapter 22 - Monitoring System Activities with Event Viewer Last modified am.
Monitoring Windows Server 2012
Learningcomputer.com SQL Server 2008 – Profiling and Monitoring Tools.
11 DISASTER RECOVERY Chapter 13. Chapter 13: DISASTER RECOVERY2 OVERVIEW  Back up server data using the Backup utility and the Ntbackup command  Restore.
Updating Windows Vista Lesson 10. Skills Matrix Technology SkillObjective Domain SkillDomain # Understanding UpdatesApply security patches and updates.
Module 14 Monitoring and Optimizing SharePoint Performance.
Maintaining and Updating Windows Server Monitoring Windows Server It is important to monitor your Server system to make sure it is running smoothly.
70-290: MCSE Guide to Managing a Microsoft Windows Server 2003 Environment, Enhanced Chapter 11: Monitoring Server Performance.
Chapter 10 System Monitoring Issues Performance Benchmarks NT Server Services Users and Server Access Information Task Manager for Applications Ram and.
Chapter 10 Chapter 10: Managing the Distributed File System, Disk Quotas, and Software Installation.
Troubleshooting Security Issues Lesson 6. Skills Matrix Technology SkillObjective Domain SkillDomain # Monitoring and Troubleshooting with Event Viewer.
Using Event Viewer Event Levels Creating Custom Views Windows Logs Monitoring Performance.
Vinay Paul. CONTENTS:- What is Event Log Service ? Types of event logs and their purpose. How and when the Event Log is useful? What is Event Viewer?
CH 13 Server and Network Monitoring. Hands-On Microsoft Windows Server Objectives Understand the importance of server monitoring Monitor server.
Windows monitoring Unit objectives: Monitor the operating system Monitor system performance Backup and restore operating system files and data.
Module 13: Monitoring Resources and Performance. Overview Using Task Manager to Monitor System Performance Using Performance and Maintenance Tools to.
Optimizing Windows Vista Performance Lesson 10. Skills Matrix Technology SkillObjective DomainObjective # Introducing ReadyBoostTroubleshoot performance.
Understand Audit Policies LESSON Security Fundamentals.
1 Chapter Overview Monitoring Access to Shared Folders Creating and Sharing Local and Remote Folders Monitoring Network Users Using Offline Folders and.
Monitoring Servers Lesson 11. Skills Matrix Technology SkillObjective DomainObjective # Using the Reliability and Performance Console Monitor servers.
ITMT 1371 – Window 7 Configuration 1 ITMT Windows 7 Configuration Chapter 8 – Managing and Monitoring Windows 7 Performance.
Maintaining and Updating Windows Server 2008 Lesson 8.
Web Server Administration Chapter 11 Monitoring and Analyzing the Web Environment.
SQL Database Management
Monitoring Windows Server 2012
Chapter Objectives In this chapter, you will learn:
Hands-On Microsoft Windows Server 2008
MONITORING MICROSOFT WINDOWS SERVER 2003
Bethesda Cybersecurity Club
MAINTAINING SERVER AVAILIBILITY
Presentation transcript:

Chapter 17: Watching Your System BAI617

Chapter Topics Working With Event Viewer Performance Monitor Resource Monitor

Monitoring Your System with Event Viewer The best time to know about a problem is before it happens Event Viewer in Windows Server 2008 R2 is one of the primary tools used to watch your system

Performance & Event Logs Logging is your eyes and ears when you are not present to monitor systems yourself Baselines help determine the “norm” From the baseline you can determine performance improvement or degradation. Without logging there is no proving that any tweaks you make are making a difference

Managing Event Logs Event logs will tell you the following crucial information about system events Date / Time Source of Event (Subcomponent) Event ID Specifics of error Possible causes Sometime they are completely unhelpful, but most times they are a great starting point.

Windows 2008 Event Logs Windows 2008 brings some new organization to the Computer Management window and many new categories for event logging

Getting to what you need There can be hundreds of events to sift through to try to find the one you are looking for. There are useful search and filter tools built into the Event Viewer console

Viewing an Event

Understanding Event Levels Information events: – These entries are used to indicate a change has occurred or to describe the successful completion of an operation. The icon used to represent Information events is an in a circle. Warning events: – Indicate events that may lead to a problem in the future. The event isn’t necessarily significant. Sometimes you can trace back from critical or error events to identify a preceding warning. The icon used to represent Warning events is a black exclamation point in a yellow triangle. Error events: – Indicate a problem occurred external to the application or component that might impact the functionality of the application or component. The icon used to represent error events is a white exclamation point in a red circle Critical events: – Critical event is one that an application or component cannot automatically recover from. Critical events are the most serious. The icon used to represent Critical events is a white x in a red circle.

Understanding Windows Logs Application – The Application log is used to log events from applications. The application developer can choose to log events in this log or create an additional application log specifically for the application. As an example, SQL Server will log applications into this log. Security – The Security log will show all audited events. Audited events include logons, files, and other object usage, as well as any other auditing events the administrator has enabled. Audited events can be specified to include both success and failure events. Windows Server 2008 R2 does enable auditing of specific events by default, so these logs will have events even if the administrator hasn’t modified auditing. System – The System log records events related to the operating system. It includes information related to system drivers and system services.

Archiving Logs Many organizations have policies in place that require log files to be archived. Once archived, the original file is saved and can be viewed later, and new events won’t overwrite archived events Certain logs are going to need to be saved for future reference – Security and Auditing logs are an example. Other logs can be cleared after review.

Monitoring Multiple Machines Creating Custom Views in MMC Manage your server farm. Advanced topic: With SQL you can collect events to a database and configure subscribers.

Performance Monitor Performance Monitor has been around in the Windows operating systems for several versions, but it enjoys some significant improvements today This is one of the tools used to create a network and server performance baseline Performance Monitor measures specific counters from every part of the server – hardware, OS, application, networking, etc

Performance Monitor Performance Monitor uses objects and counters. Objects – Performance Monitor objects are specific resources that can be measured. Some commonly measured objects are Processor, Memory, Network Interface, and Physical Disk. Counters – Counters are the individual metrics within an object. For example, the Processor object includes counters such as the % Processor Time, % User Time, and Interrupts/Sec counters.

Resource Monitor The Resource Monitor is constantly running and capturing counters on the core four resources of your system. – You can access it by right-clicking Monitoring Tools and selecting Resource Monitor. – You can also access via Task Manager. Select the Performance tab, and click the Resource Monitor button

Resource Monitor One of the primary benefits of the Resource Monitor is the ability to filter the results according to specific processes or services. For example, if you want to identify the load a specific application is placing on your system, you can select only that application’s processes.

Resource Monitor

Overview Tab – Gives you a one screen view of the main 4 subsystems

Resource Monitor Memory Tab

Resource Monitor Disk Tab

Review Working With Event Viewer Performance Monitor Resource Monitor

Questions?

Lab Environment