SOLVED

Monitor Only "Automatic" Windows Services

%3CLINGO-SUB%20id%3D%22lingo-sub-1555504%22%20slang%3D%22en-US%22%3ERe%3A%20Monitor%20Only%20%22Automatic%22%20Windows%20Services%3C%2FLINGO-SUB%3E%3CLINGO-BODY%20id%3D%22lingo-body-1555504%22%20slang%3D%22en-US%22%3E%3CP%3EHi%3CA%20href%3D%22https%3A%2F%2Ftechcommunity.microsoft.com%2Ft5%2Fuser%2Fviewprofilepage%2Fuser-id%2F369698%22%20target%3D%22_blank%22%3E%40zarchi%3C%2FA%3E%20%2C%3C%2FP%3E%0A%3CP%3EThis%20is%20possible.%20Example%20query%3A%3C%2FP%3E%0A%3CPRE%20class%3D%22lia-code-sample%20language-sql%22%3E%3CCODE%3EConfigurationChange%0A%26nbsp%3B%7C%26nbsp%3Bwhere%26nbsp%3BConfigChangeType%26nbsp%3B%3D~%26nbsp%3B'WindowsServices'%26nbsp%3Band%26nbsp%3BChangeCategory%26nbsp%3B%3D~%26nbsp%3B'Modified'%26nbsp%3Band%26nbsp%3BSvcChangeType%26nbsp%3B%3D~%26nbsp%3B'State'%26nbsp%3Band%26nbsp%3BSvcState%26nbsp%3B%3D~%26nbsp%3B'Stopped'%20and%20SvcStartupType%20%3D~%20'Auto'%0A%26nbsp%3B%7C%26nbsp%3Bextend%26nbsp%3BAggregatedValue%26nbsp%3B%3D%26nbsp%3B1%26nbsp%3B%0A%20%7C%26nbsp%3Bsummarize%26nbsp%3Barg_max(TimeGenerated%2C%26nbsp%3B*)%26nbsp%3Bby%26nbsp%3B_ResourceId%2C%26nbsp%3BSvcDisplayName%2C%26nbsp%3Bbin(TimeGenerated%2C%26nbsp%3B5m)%26nbsp%3B%3C%2FCODE%3E%3C%2FPRE%3E%0A%3CP%3EYou%20can%20read%20more%20about%20the%20query%20I%20am%20using%20on%20%3CA%20href%3D%22https%3A%2F%2Fcloudadministrator.net%2F2019%2F10%2F07%2Fazure-monitor-alert-series-part-7%2F%22%20target%3D%22_self%22%20rel%3D%22nofollow%20noopener%20noreferrer%22%3Emy%20blog%20post%3C%2FA%3E.%20You%20need%20to%20set%20the%20alert%20on%20Metric%20measurement%2C%20greater%20than%2C%20threshold%20value%200%2C%20total%20breaches%20greater%20than%200.%20Period%205%20mins%2C%20frequency%205%20minutes.%20Aggregate%20on%3A%20select%20_ResourceId%20and%20SvcDisplayName.%20Usually%20Aggregate%20on%20is%20not%20available%20when%20you%20create%20alerts%20via%20portal%20so%20it%20is%20best%20to%20create%20it%20via%20ARM%20Template%20as%20I%20have%20shown%20in%20my%20blog%20post.%20My%20Advise%20is%20to%20always%20scope%20to%20specific%20services%20names%20as%20I%20have%20shown%20in%20my%20blog%20post%20and%20not%20to%20monitor%20all%20Automatic%20services.%20There%20are%20some%20automatic%20services%20that%20start%20and%20stop%20on%20certain%20periods%20which%20will%20generate%20a%20lot%20of%20false%20positives%20and%20noise.%3C%2FP%3E%3C%2FLINGO-BODY%3E%3CLINGO-SUB%20id%3D%22lingo-sub-1556255%22%20slang%3D%22en-US%22%3ERe%3A%20Monitor%20Only%20%22Automatic%22%20Windows%20Services%3C%2FLINGO-SUB%3E%3CLINGO-BODY%20id%3D%22lingo-body-1556255%22%20slang%3D%22en-US%22%3E%3CP%3E%3CA%20href%3D%22https%3A%2F%2Ftechcommunity.microsoft.com%2Ft5%2Fuser%2Fviewprofilepage%2Fuser-id%2F9172%22%20target%3D%22_blank%22%3E%40Stanislav%20Zhelyazkov%3C%2FA%3EThanks%20so%20much%20for%20the%20response.%20I%20was%20thinking%20to%20use%20%22Change%20Tracking%22%20and%20I%20found%20its%20limitation%20where%20all%20VMs%20need%20to%20the%20same%20subscription%20and%20region%20of%20the%20automation%20account.%20As%20we%20have%20many%20VMs%20across%20tenants%20and%20different%20subscriptions%2C%20we%20can't%20use%20it.%20Is%20it%20possible%20to%20use%20the%20Kusto%20query%3F%3C%2FP%3E%3CP%3E%26nbsp%3B%3C%2FP%3E%3C%2FLINGO-BODY%3E%3CLINGO-SUB%20id%3D%22lingo-sub-1556264%22%20slang%3D%22en-US%22%3ERe%3A%20Monitor%20Only%20%22Automatic%22%20Windows%20Services%3C%2FLINGO-SUB%3E%3CLINGO-BODY%20id%3D%22lingo-body-1556264%22%20slang%3D%22en-US%22%3E%3CP%3E%3CA%20href%3D%22https%3A%2F%2Ftechcommunity.microsoft.com%2Ft5%2Fuser%2Fviewprofilepage%2Fuser-id%2F369698%22%20target%3D%22_blank%22%3E%40zarchi%3C%2FA%3E%20There%20is%20no%20such%20limitation.%20If%20there%20is%20it%20must%20be%20in%20the%20portal%20only%20experience.%20To%20a%20single%20workspace%20and%20automation%20account%20with%20change%20tracking%20enabled%20you%20can%20onboard%20VMs%20from%20multiple%20subscriptions%20under%20the%20same%20tenant.%20If%20you%20want%20to%20onboard%20VMs%20in%20other%20tenants%20you%20have%20to%20onboard%20them%20like%20they%20are%20on-premises%20VMs.%20I%20would%20strongly%20suggest%20using%20automation%20account%20and%20workspace%20per%20tenant%20rather%20onboarding%20multiple%20tenants%20to%20the%20same%20workspace%20and%20automation%20account.%20Especially%20of%20the%20tenants%20are%20different%20customers.%3C%2FP%3E%3C%2FLINGO-BODY%3E%3CLINGO-SUB%20id%3D%22lingo-sub-1562251%22%20slang%3D%22en-US%22%3ERe%3A%20Monitor%20Only%20%22Automatic%22%20Windows%20Services%3C%2FLINGO-SUB%3E%3CLINGO-BODY%20id%3D%22lingo-body-1562251%22%20slang%3D%22en-US%22%3E%3CP%3E%3CA%20href%3D%22https%3A%2F%2Ftechcommunity.microsoft.com%2Ft5%2Fuser%2Fviewprofilepage%2Fuser-id%2F9172%22%20target%3D%22_blank%22%3E%40Stanislav%20Zhelyazkov%3C%2FA%3E%26nbsp%3BThanks%20for%20your%20suggestion.%20It%20is%20mentioned%20here%20in%20this%20article%20%22To%20use%20the%20Change%20Tracking%20and%20Inventory%20feature%2C%20you%20must%20locate%20all%20your%20VMs%20in%20the%20same%20subscription%20and%20region%20of%20the%20Automation%20account.%22%3C%2FP%3E%3CP%3E%3CA%20href%3D%22https%3A%2F%2Fdocs.microsoft.com%2Fen-us%2Fazure%2Fautomation%2Fchange-tracking%22%20target%3D%22_blank%22%20rel%3D%22noopener%20noreferrer%22%3Ehttps%3A%2F%2Fdocs.microsoft.com%2Fen-us%2Fazure%2Fautomation%2Fchange-tracking%3C%2FA%3E%3C%2FP%3E%3CP%3EAs%20long%20as%20it%20is%20working%20fine%20with%20multiple%20subscriptions%20and%20different%20locations%2C%20I%20am%20happy%20to%20enable%20this.%20%3A)%3C%2Fimg%3E%3C%2FP%3E%3C%2FLINGO-BODY%3E%3CLINGO-SUB%20id%3D%22lingo-sub-1562279%22%20slang%3D%22en-US%22%3ERe%3A%20Monitor%20Only%20%22Automatic%22%20Windows%20Services%3C%2FLINGO-SUB%3E%3CLINGO-BODY%20id%3D%22lingo-body-1562279%22%20slang%3D%22en-US%22%3E%3CP%3E%3CA%20href%3D%22https%3A%2F%2Ftechcommunity.microsoft.com%2Ft5%2Fuser%2Fviewprofilepage%2Fuser-id%2F369698%22%20target%3D%22_blank%22%3E%40zarchi%3C%2FA%3E%20As%20I%20have%20said%20it%20is%20not%20true.%20Here%20is%20official%20issue%20opened%20for%20the%20docs%3A%20%3CA%20href%3D%22https%3A%2F%2Fgithub.com%2FMicrosoftDocs%2Fazure-docs%2Fissues%2F60154%22%20target%3D%22_blank%22%20rel%3D%22noopener%20noreferrer%22%3Ehttps%3A%2F%2Fgithub.com%2FMicrosoftDocs%2Fazure-docs%2Fissues%2F60154%3C%2FA%3E%3C%2FP%3E%3C%2FLINGO-BODY%3E%3CLINGO-SUB%20id%3D%22lingo-sub-1569936%22%20slang%3D%22en-US%22%3ERe%3A%20Monitor%20Only%20%22Automatic%22%20Windows%20Services%3C%2FLINGO-SUB%3E%3CLINGO-BODY%20id%3D%22lingo-body-1569936%22%20slang%3D%22en-US%22%3E%3CP%3E%3CA%20href%3D%22https%3A%2F%2Ftechcommunity.microsoft.com%2Ft5%2Fuser%2Fviewprofilepage%2Fuser-id%2F9172%22%20target%3D%22_blank%22%3E%40Stanislav%20Zhelyazkov%3C%2FA%3E%26nbsp%3BThanks%20so%20much.%20I%20have%20enabled%20it%20and%20working%20fine%20%3A).%3C%2FP%3E%3C%2FLINGO-BODY%3E%3CLINGO-SUB%20id%3D%22lingo-sub-1537922%22%20slang%3D%22en-US%22%3EMonitor%20Only%20%22Automatic%22%20Windows%20Services%3C%2FLINGO-SUB%3E%3CLINGO-BODY%20id%3D%22lingo-body-1537922%22%20slang%3D%22en-US%22%3E%3CP%3EHi%20All%2C%3C%2FP%3E%0A%3CP%3E%26nbsp%3B%3C%2FP%3E%0A%3CP%3EIs%20there%20a%20way%20to%20monitor%20only%20Windows%20services%20which%20the%20startup%20type%20is%20%22Automatic%22%3F%3C%2FP%3E%0A%3CP%3EI%20found%20the%20following%20article%20to%20monitor%20Window%20services.%20but%20it%20is%20to%20monitor%20all%20Windows%20services%20regardless%20of%20startup%20type.%3C%2FP%3E%0A%3CP%3E%26nbsp%3B%3C%2FP%3E%0A%3CP%3E%3CA%20href%3D%22https%3A%2F%2Ftechcommunity.microsoft.com%2Ft5%2Fazure-monitor%2Fhow-to-monitor-windows-services%2Fm-p%2F768888%22%20target%3D%22_blank%22%3Ehttps%3A%2F%2Ftechcommunity.microsoft.com%2Ft5%2Fazure-monitor%2Fhow-to-monitor-windows-services%2Fm-p%2F768888%3C%2FA%3E%3C%2FP%3E%0A%3CP%3E%26nbsp%3B%3C%2FP%3E%0A%3CP%3E%26nbsp%3B%3C%2FP%3E%0A%3CP%3EThanks%20so%20much%3C%2FP%3E%3C%2FLINGO-BODY%3E%3CLINGO-LABS%20id%3D%22lingo-labs-1537922%22%20slang%3D%22en-US%22%3E%3CLINGO-LABEL%3EQuery%20Language%3C%2FLINGO-LABEL%3E%3C%2FLINGO-LABS%3E
Occasional Contributor

Hi All,

 

Is there a way to monitor only Windows services which the startup type is "Automatic"?

I found the following article to monitor Window services. but it is to monitor all Windows services regardless of startup type.

 

https://techcommunity.microsoft.com/t5/azure-monitor/how-to-monitor-windows-services/m-p/768888

 

 

Thanks so much

6 Replies
best response confirmed by Stanislav Zhelyazkov (MVP)
Solution

Hi@zarchi ,

This is possible. Example query:

ConfigurationChange
 | where ConfigChangeType =~ 'WindowsServices' and ChangeCategory =~ 'Modified' and SvcChangeType =~ 'State' and SvcState =~ 'Stopped' and SvcStartupType =~ 'Auto'
 | extend AggregatedValue = 1 
 | summarize arg_max(TimeGenerated, *) by _ResourceId, SvcDisplayName, bin(TimeGenerated, 5m) 

You can read more about the query I am using on my blog post. You need to set the alert on Metric measurement, greater than, threshold value 0, total breaches greater than 0. Period 5 mins, frequency 5 minutes. Aggregate on: select _ResourceId and SvcDisplayName. Usually Aggregate on is not available when you create alerts via portal so it is best to create it via ARM Template as I have shown in my blog post. My Advise is to always scope to specific services names as I have shown in my blog post and not to monitor all Automatic services. There are some automatic services that start and stop on certain periods which will generate a lot of false positives and noise.

@Stanislav ZhelyazkovThanks so much for the response. I was thinking to use "Change Tracking" and I found its limitation where all VMs need to the same subscription and region of the automation account. As we have many VMs across tenants and different subscriptions, we can't use it. Is it possible to use the Kusto query?

 

@zarchi There is no such limitation. If there is it must be in the portal only experience. To a single workspace and automation account with change tracking enabled you can onboard VMs from multiple subscriptions under the same tenant. If you want to onboard VMs in other tenants you have to onboard them like they are on-premises VMs. I would strongly suggest using automation account and workspace per tenant rather onboarding multiple tenants to the same workspace and automation account. Especially of the tenants are different customers.

@Stanislav Zhelyazkov Thanks for your suggestion. It is mentioned here in this article "To use the Change Tracking and Inventory feature, you must locate all your VMs in the same subscription and region of the Automation account."

https://docs.microsoft.com/en-us/azure/automation/change-tracking

As long as it is working fine with multiple subscriptions and different locations, I am happy to enable this. :)

@zarchi As I have said it is not true. Here is official issue opened for the docs: https://github.com/MicrosoftDocs/azure-docs/issues/60154

@Stanislav Zhelyazkov Thanks so much. I have enabled it and working fine :).