Example - Using the Process Monitor to check for antivirus software
You can use the Process Monitor to verify that antivirus or anti-spyware software is a running on a device. If the monitor does not find the specified program running, an associated action will notify you of this potentially harmful vulnerability.
For this example, we will configure and assign a Process Monitor that checks to see if Norton AntiVirus™ is running on a device. We will also configure and assign an Email Action to notify you if the monitor fails.
To configure the Process Monitor:
- Go to the Active Monitor Library.
- From the web interface, click . The GO menu appears.
- If the WhatsUp section is not visible, click . The WhatsUp section of the GO menu appears.
- Select . The Active Monitor Library appears.
- or -
- From the main menu bar of the console, select . The Active Monitor Library appears.
- In the Active Monitor Library, click . The Select Active Monitor Type dialog appears.
- Select Process Monitor from the list, then click . The Add Process Monitor dialog appears.
- Enter a for the monitor, such as
Norton AntiVirus Monitor
. - Enter a for the monitor. This description is displayed next to the monitor name in the Active Monitor Library.
- Enter or browse () to the that the monitor will check. To monitor Norton AntiVirus software, enter
rtvscan.exe
. - Under the section of the dialog, select and . If the monitor does not find the
rtvscan.exe
process running on the device to which the monitor is assigned, the monitor is considered down.: Click to set the SNMP timeout and number of retries, and to decide if the monitor is used in Discovery.
- Click to save changes.
After configuring the Norton AntiVirus Monitor, you need to assign it to the device(s) that you want to check are running the monitor. In the next steps of this example, you will assign the monitor to a single device, and then, using the Action Builder, configure and assign an Email Action that will notify you when the monitor goes down.
: You can also assign the monitor to multiple devices at one time via Bulk Field Change. For more information, see Assigning a monitor to multiple devices.
To assign the Norton AntiVirus Monitor, and configure and assign an Email Action:
- Go to the properties for the device to which you want to assign the monitor.
- From either the Device View or Map View, right-click the device. The right-click menu appears.
- Select . The Device Properties dialog appears.
- Click . The Device Properties - Active Monitors dialog appears.
- Click . The Active Monitor Properties dialog appears.
- Select the , then click .
- Set the monitor's polling properties, then click .
- Select , then click . The Action Builder appears.
- Select , then click.
- Select the , then click .
- Under, select ; this option specifies that WhatsUp Gold will issue a state change after the monitor has been unable to find
rtvscan.exe
on the device for 20 minutes. Click. The New Email Action dialog appears.: On the console, ensure that the Mail Destination tab is selected.
- Enter a for the monitor, such as
Norton AntiVirus Email Notification
. - In , enter the IP address or Host (DNS) name of your email server (SMTP mail host).
- Enter the on which the SMTP Server is installed. The default SMTP port is 25.
- Optionally, change the from the default of 5 seconds.
- In , enter the email addresses to which you want send the notification. You can enter two addresses, separated by commas (with no spaces). The address should not contain brackets, spaces, quotation marks, or parentheses.
- Select if your SMTP server uses authentication. This enables the Username and Password options.
- Enter a and to be used with authentication.
- Select if your SMTP server requires data encryption over a TLS connection.
- Click to enter the notification content.
- In , enter the email address that will appear in the From field of the email that is sent from WhatsUp Gold.
- In , enter
%ActiveMonitor.Name has failed (%Device.HostName)
. This message indicates the monitor's name, its failed state, and the hostname of the device on which the monitor has failed. - In , enter
This %ActiveMonitor.Name has failed on %Device.Address.
Please restart the Norton AntiVirus software on this device.
----------------------------------------
This mail was sent on %System.Date at %System.Time
Ipswitch WhatsUp Gold
This message indicates that the Norton AntiVirus software has stopped on the specified device and that it should be restarted.
: Optionally, you can add a link to the or report for the device to which the monitor is assigned.
- Click to save changes.
- On the Active Monitor Properties dialog, click .