Skip to content
Release: Australia · Updated: 2026-03-12 · Official documentation · View source

Agent Client Collector Monitoring default checks and policies

Agent Client Collector Monitoring provides various default checks and policies.

Provided checks

The following tables list the default checks. You can edit these checks as needed. For more information about a specific check, see its Check Definitions page, as described in Checks and policies.

TypeNameDescription
Eventos.linux.check-processCounts the number of running processes.You can block event creation for this check when no process is detected. For details, see Block event creation for non-existent entities.
Eventos.linux.check-system-cpuChecks the CPU usage percentage.
Eventos.linux.check-system-cpu-loadChecks the CPU data load percentage against the configured thresholds.
Eventos.linux.check-system-disk-usageChecks the file system's mount points and metrics.
Eventos.linux.check-system-memory-percentageChecks the memory usage percentage.
Eventos.linux.check-system-memory-swapChecks the memory swap usage.
Eventos.linux.check-threads-countCounts the number of threads running on the system. Sends an alert if that number is greater than the Warning or Critical threshold values.
Metricos.linux.metrics-memory-vmstatCollects vmstat memory metrics.
Metricos.linux.metrics-process-statusCollects process status metrics provided to the metrics parameter.
Metricos.linux.metrics-system-cpuCollects CPU metrics, including cores.
Metricos.linux.metrics-system-cpu-loadUses uptime to collect CPU load metrics.
Metricos.linux.metrics-system-cpu-percentageCollects CPU usage percentage metrics, including average CPU utilization percentage.
Metricos.linux.metrics-system-diskCollects disk metrics.
Metricos.linux.metrics-system-disk-capacityCollects disk capacity metrics.
Metricos.linux.metrics-system-disk-usageCollects disk usage metrics, providing total, used, and available disk memory, as well as the disk's percentage of memory used.
Metricos.linux.metrics-system-memoryCollects memory metrics, providing data in KB.
Metricos.linux.metrics-system-memory-percentCollects memory percentage metrics.
Metricos.linux.metrics-system-uptimeCollects system uptime in seconds.
Metricos.linux.metrics-reboot-count-todayCollects the number of reboots performed today.
TypeNameDescription
Eventutil.check-logsEnables monitoring log files owned by a regular user.You can block event creation for this check when no process is detected. For details, see Block event creation for non-existent entities.
Eventutil.check-logs-sudoEnables monitoring log files owned by a root user.You can block event creation for this check when no process is detected. For details, see Block event creation for non-existent entities.
TypeNameDescription
Metricos.linux.metrics-network-interfaceRetrieves all network interface related metrics for Linux servers.
Metricos.linux.metrics-netstat.tcpRetrieves metrics on TCP socket states from netstat. Useful on high-traffic web or proxy servers with large numbers of short-lived TCP connections coming and going.
TypeNameDescription
Eventos.windows.check-logEnables monitoring log files on a Windows server.
TypeNameDescription
Eventos.windows.check-disk-nameTakes the storage drive name as input and verifies if the drive is present. Returns a CRITICAL\\WARNING\\OK value based on the parameter provided.
Eventos.windows.check-event-logMeasures the Windows event log against parameter thresholds and returns a CRITICAL\\WARNING\\OK event.
Eventos.windows.check-event-log-countMeasures the Windows event log against parameter thresholds and returns a CRITICAL\\WARNING\\OK event.Provides information on the number of events that have occurred within a specified duration for a single log file and a single ID. Also indicates the filters to be applied to retrieve events for a specific single-valued windows event level and provider name. Retrieving events from multiple log files is not supported. The number of events is provided, without details of each and every event.
Eventos.windows.check-event-log-detailsCollects and filters Windows event logs based on the `duration_hour`, `event_log_level` and `log_file` values. Retrieves and filters Windows event logs according to the provided parameters. It returns details about the events with CRITICAL, WARNING, or OK status, based on the specified severity level. Supported on Windows version 7 and higher.
Eventos.windows.check-env-variablesChecks the environmental variables using a regular expression and returns either a WARNING or OK value.If a new system variable is created after agent installation, you must restart the agent. This check can access only those user variables that are associated with the current user (used during agent installation).
Eventos.windows.check-file-hashcode-updateTakes the file's path and MD5 hashcode as an input and verifies whether file content has been modified. Returns a CRITICAL, WARNING, or OK value.Read permissions are required on the monitored file.
Eventos.windows.check-file-updateTakes the file's path and interval as an input and verifies whether file content has been modified. Returns a CRITICAL, WARNING, or OK value.Read permissions are required on the monitored file.
Eventos.windows.check-modulesVerifies whether the list of modules is present.
Eventos.windows.check-processor-queue-lengthChecks Processor Queue Length.
Eventos.windows.check-system-cpu-loadChecks the CPU load by using the `typeperf` command.
Eventos.windows.check-system-diskChecks disk usage under specific parameters.
Eventos.windows.check-system-memoryCollects RAM usage.
Eventos.windows.check-system-patchVerifies system patch installation. Returns either a WARNING or OK value.
Eventos.windows.check-system-processChecks the user's task list to find running processes.
Eventos.windows.check-user-accountTakes the list of user names as an input and verifies whether the user account is active. Returns a CRITICAL, WARNING, or OK value.
Eventos.windows.check-windows-directoryChecks if a directory exists.
Eventos.windows.check-windows-pagefileCollects page file usage and compares it to the Warning and Critical thresholds.
Eventos.windows.check-windows-processChecks if a user input process is running.
Eventutil.check-windows-serviceChecks if a user-supplied service is running on Windows.Only the RUNNING status is treated as OK. Any other status generates either a WARNING or CRITICAL event, depending on your configuration. You can block event creation for this check when no process is detected. For details, see Block event creation for non-existent entities.
Metricos.windows.metrics-process-statusRetrieves the number of running instances, the percentage of CPU utilization, and the memory usage \(in kilobytes\) of the specified Windows process.
Metricos.windows.metrics-processor-queueCollects Processor Queue Length.
Metricos.windows.metrics-system-cpu-loadCollects the average CPU load per second.
Metricos.windows.metrics-system-disk-usageCollects disk usage metrics.
Metricos.windows.metrics-system-memory-percentCollects RAM usage per second, providing free physical, free virtual, total physical and total virtual memory percentage.
Metricos.windows.metrics-system-networkCollects network metrics.
Metricos.windows.metrics-system-uptimeCollects system uptime.
Metricutil.metrics-windows-perf-counters\(No description\)
TypeNameDescription
Eventapp.mid.check-activeChecks if the MID Server is active, based on the occurrence of LogStatusMonitor in the MID log.
Eventsapp.mid.check-logs-midChecks the MID logs for errors.
Metricapp.mid.metrics-statsCollects MID Server information from the log and returns metrics.
TypeNameDescription
Eventcheck-haproxyRetrieves the HAProxy load balancer details to determine whether it is running.
Metricmetrics-check-haproxyRetrieves the HAProxy load balancer metrics to determine whether it is running.
TypeNameDescription
Eventutil.check-http-responseTakes a URL or a combination of host/path/port/ssl, and checks for a 200 response that matches a pattern, if provided. Can use client certificates.
Eventutil.check-http-follow-redirectChecks that the URL doesn't exceed the maximum number of redirects.
Metricutil.metrics-http-curlRetrieves HTTP endpoint metrics using curl.
TypeNameDescription
Eventutil.check-http-response-codeRaises a critical event if the URL response code does not match the regex.
TypeCheckDescriptionCommand
Metricmetrics.windows.active-directoryCollects Active Directory metrics on the Windows host.Usage: winchecks metric-windows-active-dir -s hostname`winchecks metric-windows-active-dir {{if .labels.params_scheme}} -S {{.labels.params_scheme}} {{end}}`
TypeEvent/MetricDescriptionMinimum version
Metricapp.apache.metrics-apacheRetrieves Apache HTTP server metrics.2.4.x
TypeEvent/MetricDescriptionMinimum version
Eventkafka.check-zookeeper-statusRaises a critical event if the hosted Kafka Zookeeper is down.ZooKeeper 3.1.2
Eventkafka.check-topic-replicasRaises a critical event if any topic has partitions with unknown replicas.ZooKeeper 3.1.2
Eventkafka.check-topic-replication-factorRaises a critical event if replication factor of at least one topic is above or below provided replication factor parameter.ZooKeeper 3.1.2
Eventkafka.check-topic-leaderRaises a critical event if any topic has partitions with unknown leaders or unpreferred replica as leader.ZooKeeper 3.1.2
Eventskafka.check-topic-partitionsRaises a critical event if the number of partitions for a topic is less the min_partitions param.ZooKeeper 3.1.2
Eventkafka.check-broker-statusRaises a critical event if Kafka Broker on the host is down.Kafka 0.10.1.0
Metrickafka.metrics.brokerCollects Kafka Broker Metrics from the host.Kafka 0.10.1.0
Metrickafka.metrics.zookeeperCollects Zookeeper Metrics from the host.ZooKeeper 3.5.0-alpha
TypeEvent/MetricDescriptionCommand
Metricazure.metrics-k8s-serviceProvides pod, nodes, and cluster level metrics from all Azure Kubernetes services in metric form.Usage: metrics-azure-k8s-service.rb Command example: `metrics-azure-k8s-service.rb -S {{.labels.params_subscription_id}} -r westus2``metrics-azure-k8s-service.rb -r {{.labels.params_ci_region}} {{-s {{if.labels.params_subscription_id}} -S {{.labels.params_subscription_id}} {{end}}`
TypeEvent/MetricDescriptionCommand
Metricazure.metrics-vm-cpuProvides CPU-related metrics of each VM instance in the Azure region.Command example: `./metrics-azure-vm.rb -S {{.labels.params_subscription_id}} -T cpu``metrics-azure-vm.rb -r {{.labels.params_ci_region}} {{if .labels.params_subscription_id}} -S {{.labels.params_subscription_id}} {{end}} -T {{.labels.params_type}}`
Metricazure.metrics-vm-diskProvides disk-related metrics of each VM instance in the Azure region.Command example: `./metrics-azure-vm.rb -S {{.labels.params_subscription_id}} -T disk``metrics-azure-vm.rb -r {{.labels.params_ci_region}} {{if .labels.params_subscription_id}} -S {{.labels.params_subscription_id}} {{end}} -T {{.labels.params_type}}`
Metricazure.metrics-vm-memoryProvides memory-related metrics of each VM instance in the Azure region.Command example: `./metrics-azure-vm.rb -S {{.labels.params_subscription_id}} -T memory``metrics-azure-vm.rb -r {{.labels.params_ci_region}} {{if .labels.params_subscription_id}} -S {{.labels.params_subscription_id}} {{end}} -T {{.labels.params_type}}`
Metricazure.metrics-vm-networkProvides network-related metrics of each VM instance in the Azure region.Command example: `./metrics-azure-vm.rb -S {{.labels.params_subscription_id}} -T network``metrics-azure-vm.rb -r {{.labels.params_ci_region}} {{if .labels.params_subscription_id}} -S {{.labels.params_subscription_id}} {{end}} -T {{.labels.params_type}}`
Metricazure.metrics-vm-flowsProvides flows-related metrics of each VM instance in the Azure region.Command example: `./metrics-azure-vm.rb -S {{.labels.params_subscription_id}} -T flows``metrics-azure-vm.rb -r {{.labels.params_ci_region}} {{if .labels.params_subscription_id}} -S {{.labels.params_subscription_id}} {{end}} -T {{.labels.params_type}}`
TypeEvent/MetricDescription
Metricgcp.metrics.GCERetrieves metrics from GCP for Google Compute Engine.
Metricglassfish.metric-server-requestsProvides http-request metrics for all applications deployed on the Glassfish server.
Metricglassfish.metric-server-resourcesProvides metrics of the resources deployed on the Glassfish server.
Metricglassfish.metric-transaction-serviceProvides metrics for all transactions on applications deployed on the Glassfish server.
Metricglassfish.metric-deployed-appsProvides metric output of the applications deployed on the Glassfish server.
Metricglassfish.metric-deployment-lifecycleProvides lifecycle metrics applications deployed on the Glassfish server.
TypeNameDescription
Metricglassfish.metric-jvm-levelRetrieves JVM metrics on the Glassfish server.
Metricglassfish.metric-server-requestsProvides http-request metrics for all applications deployed on the Glassfish server.
Metricglassfish.metric-server-resourcesProvides metrics of the resources deployed on the Glassfish server.
Metricglassfish.metric-transaction-serviceProvides metrics for all transactions on applications deployed on the Glassfish server.
Metricglassfish.metric-deployed-appsProvides metric output of the applications deployed on the Glassfish server.
Metricglassfish.metric-deployment-lifecycleProvides lifecycle metrics applications deployed on the Glassfish server.
TypeEvent/MetricDescriptionMinimum version
Metricapp.websphere.metrics-websphereReturns IBM WebSphere application server metrics.Ensure that the user running the agent has sufficient permissions to access the required files in the `IBM Websphere AS` installation directories.9
TypeEvent/MetricDescriptionMinimum version
Eventapp.iis.check-iis-aliveChecks if IIS is running.-
Eventapp.iis.check-iis-current-connectionsChecks the number of current connections to the IIS server and their status, depending on the input. By default, all sites are connected to the IIS server.-
Metricapp.iis.metrics-iisReturns IIS metrics.-
TypeEvent/MetricDescriptionMinimum version
Metricapp.jboss.metrics-jbossRetrieves JBoss/WildFly server metrics.Ensure that the user running the agent has sufficient permissions to access the required files in the`JBoss/WildFly` installation directories.16, 17
TypeEvent/MetricDescriptionCommand
Eventk8s.check-kube-apiserver-availableChecks if Kubernetes API server is up.`check-kube-apiserver-available.rb {{if .labels.params_api_server}} -s {{.labels.params_api_server}} {{end}}`
Eventk8s.check-kube-nodes-readyChecks whether Kubernetes nodes are in ready-to-use state.`check-kube-nodes-ready.rb {{if .labels.params_api_server}} -s {{.labels.params_api_server}} {{end}}`
Eventk8s.check-kube-pods-pendingMeasures the threshold by which pods are in the Pending state. Determine the threshold by setting the pending_timeout check parameter value (default = 300 seconds).`check-kube-pods-pending.rb {{if .labels.params_api_server}} -s {{.labels.params_api_server}} {{end}}`
Eventk8s.check-kube-pods-restartingChecks the pods that are restarting. Determine the threshold by setting the check parameter value \(default = 10\).`check-kube-pods-restarting.rb {{if .labels.params_api_server}} -s {{.labels.params_api_server}} {{end}} {{if .labels.params_restart}} -r {{.labels.params_restart}} {{end}}`
Eventk8s.check-kube-pods-runningChecks the pods that are in the running state. Configure the threshold in the not_ready_time check parameter, in seconds (default = 0).`check-kube-pods-running.rb {{if .labels.params_api_server}} -s {{.labels.params_api_server}} {{end}} {{if .labels.params_not_ready_time}} -time {{.labels.params_not_ready_time}} {{end}}`
Eventk8s.check-kube-pods-runtimeChecks whether pods are running longer than expected. Configure threshold in the check parameter \(in seconds\). You can configure both WARNING and CRITICAL thresholds.check-kube-pods-runtime.rb \{\{if .labels.params\_critical\}\} -c \{\{.labels.params\_critical\}\} \{\{end\}\} \{\{if .labels.params\_warning\}\} -w \{\{.labels.params\_warning\}\} \{\{end\}\} \{\{if .labels.params\_api\_server\}\} -s \{\{.labels.params\_api\_server\}\} \{\{end\}\}
Eventk8s.check-kube-service-availableChecks whether Kubernetes services are up and running. Add the list of services to be monitored in the services' check_param field as comma-separated values (without spaces).If you enter services that are not valid, the check fails.`check-kube-pods-runtime.rb {{if .labels.params_critical}} -c {{.labels.params_critical}} {{end}} {{if .labels.params_warning}} -w {{.labels.params_warning}} {{end}} {{if .labels.params_api_server}} -s {{.labels.params_api_server}} {{end}}`
Metrick8s.metrics-podsProvides a pod count from all of the exposed services.`metrics-pods.rb {{if .labels.params_api_server}} -s {{.labels.params__api_server }} {{end}}`
TypeEvent/MetricDescriptionMinimum version
Metricapp.msssql.metrics-mssqlRetrieves MSSQL database metrics.2016
Metricapp.metrics-mssql-queryGeneric MSSQL query class which accepts a query and dumps metrics.2016
TypeEvent/MetricDescriptionMinimum version
Eventapp.mysql.check-mysql-aliveChecks if the MySQL database is running.5.7, 8
Eventapp.mysql.check-mysql-threadsChecks the number of running threads on the MySQL database. Depending on the input, it determines the status: OK, Warning, or Critical.5.7, 8
Eventutil.check-mysql-queryChecks the length of a MySQL query result set.Ensure that you use the native\_password authentication method on the MySQL server when utilizing this check.5.7, 8
Metricapp.mysql.metrics-mysqlReturns MySQL database metrics.5.7, 8
Metricapp.mysql.metrics-mysql-processesReturns MySQL database process metrics.5.7, 8
Metricutil.metrics-mysql-queryCreates a formatted metric for the length of a MySQL query result set.5.7, 8
TypeEvent/MetricDescriptionMinimum version
Eventapp.mongodb.check-mongodb-aliveMonitors whether the MongoDB server is alive and creating alerts for the MongoDB server health status. 
Eventapp.mongodb.check-mongodb-metricsCreates alerts for any of the MongoDB metrics, based on the threshold limit. 
Metricapp.mongodb.metrics-mongodbReturns metrics of the MongoDB server and all databases. 
TypeEvent/MetricDescriptionMinimum version
Eventapp.oracle.check-oracle-alive

Checks if the Oracle database is running.When using this check, add the OS user (servicenow) to the oinstall group to ensure that the user has execute permissions for the sqlplus tool.

Ensure that the CREATE SESSION database privilege is activated.

12c, 18c
Metricapp.oracle.metrics-oracle

Returns Oracle database metrics.When using this check, add the OS user (servicenow) to the oinstall group to ensure that the user has execute permissions for the sqlplus tool.

Ensure that the CREATE SESSION and SELECT database privileges are activated.

12c, 18c
Metricutil.metrics-oracle-query

Generic Oracle query class that accepts a query and dumps metrics.When using this check, add the OS user (servicenow) to the oinstall group to ensure that the user has execute permissions for the sqlplus tool.

Ensure that the CREATE SESSION and SELECT database privileges are activated.

12c, 18c
TypeEvent/MetricDescriptionMinimum version
Metricapp.weblogic.metrics-weblogicReturns Oracle WebLogic application server metrics.Ensure that the user running the agent has sufficient permissions to access the required files in the `WebLogic` installation directories.12cR2
TypeEvent/MetricDescriptionMinimum version
Metricapp.tomcat.metrics-tomcatReturns Apache Tomcat server metrics.8.5.27, 9.x
TypeNameDescription
Eventutil.check-snmpSNMP check that compares the metric value to the default. Requires input such as server, port, SNMP community, and limits.
Metricutil.metrics-snmpCollects metrics from an SNMP OID value.
Metricutil.metrics-snmp-bulk-snCollects metrics from an SNMP Table OID and returns the result as a table.
TypeEvent/MetricDescriptionCommand
Metric \(Windows\)os.windows.metrics-service-statusCollects Windows service status, providing metric of number of services running.Only the RUNNING status is treated as OK. Any other status generates either a WARNING or CRITICAL event, depending on your configuration.`winchecks metric-windows-service-status -S Wcmsvc --scheme hostname.proc`
TypeNameDescription
Metricapp.varnish.metrics-varnishCollects Varnish metrics from the host.
TypeNameDescription
Metricvsphere.metric-VirtualMachineRetrieves metrics for the vSphere Virtual Machine.
Metricvsphere.metric-DatastoreRetrieves metrics for the vSphere Datastore.
Metricvsphere.metric-DatacenterRetrieves metrics for the vSphere Datacenter.
Metricvsphere.metric-ESX_ServerRetrieves metrics for the vSphere ESX Server or HostSystem
TypeNameDescription
Metriczscaler-monitoring-checkVerifies whether the Zscaler app is running properly.
Metriczscaler-remediation-checkShuts down and restarts the Zscaler app, and creates an incident. Runs only when the zscaler-monitoring-check fails.
TypeEvent/MetricDescriptionCommand
Metricos.windows.metrics-system-cpuCollects CPU core metrics.winchecks metric-windows-cpu --scheme hostname.proc
Event/MetricDescriptionCommand
os.linux.check-disk-ioTimeWeightedMeasures the disk ioTimeWeighted value, returning a CRITICAL\WARNING\OK message, according to the thresholds specified in the parameters.check-disk-ioTimeWeighted.rb
os.linux.check-disk-sectorsWrittenMeasures the total number of sectors written successfully, returning a CRITICAL\WARNING\OK message, according to the thresholds specified in the parameters.check-disk-sectorsWritten.rb
os.linux.check-disk-sectorsReadMeasures the disk's total number of sectors read successfully, returning a CRITICAL\WARNING\OK message, according to the thresholds specified in the parameters.check-disk-sectorsRead.rb
os.linux.check-disk-readTimeMeasures the total number of milliseconds spent by all read-against thresholds, returning a CRITICAL\WARNING\OK message, according to the thresholds specified in the parameters.check-disk-readTime.rb
os.linux.check-disk-writesMeasures the total number of writes completed successfully, returning a CRITICAL\WARNING\OK message, according to the thresholds specified in the parameters.check-disk-writes.rb
os.linux.check-disk-readsMeasures the total number of reads completed successfully, returning a CRITICAL\WARNING\OK message, according to the thresholds specified in the parameters.check-disk-reads.rb
os.linux.check-disk-writesMergedMeasures the disk writesMerged value, returning a CRITICAL\WARNING\OK message, according to the thresholds specified in the parameters.check-disk-writesMerged.rb
os.linux.check-disk-readsMergedMeasures the disk readsMerged value, returning a CRITICAL\WARNING\OK message, according to the thresholds specified in the parameters.check-disk-readsMerged.rb
os.linux.check-disk-writeTimeMeasures the total number of milliseconds spent by all write operations, returning a CRITICAL\WARNING\OK message, according to the thresholds specified in the parameters.check-disk-writeTime.rb
os.linux.check-disk-ioInProgressMeasures the disk ioInProgress value, returning a CRITICAL\WARNING\OK message, according to the thresholds specified in the parameters.check-disk-ioInProgress.rb
os.linux.check-disk-iotimeMeasures the disk ioTime value, returning a CRITICAL\WARNING\OK message, according to the thresholds specified in the parameters.check-disk-ioTime.rb
Event/MetricDescriptionCommand
os.windows.check-disk-AvgSecWriteMeasures average disk writes per second, returning a CRITICAL\WARNING\OK message, according to the specified in the parameters.winchecks check-windows-AvgDisksec-write -w 1 -c 0
os.windows.check-disk-ReadBytes-secMeasures the disk ReadBytes value per second, returning a CRITICAL\WARNING\OK message, according to the thresholds specified in the parameters.winchecks check-windows-DiskReadBytes-sec -w 1 -c 0
os.windows.check-disk-WriteBytes-secMeasures the disk WriteBytes value per second, returning a CRITICAL\WARNING\OK message, according to the thresholds specified in the parameters.winchecks check-windows-DiskWriteBytes-sec -w 1 -c 0
os.windows.check-disk-AvgSecReadMeasures the average disk reads per second, returning a CRITICAL\WARNING\OK message, according to the thresholds specified in the parameters.winchecks check-windows-AvgDisksec-read -w 1 -c 0
Event/MetricDescriptionCommand
os.windows.metrics-system-diskCollects the following disk metrics:- AvgDiskSecPerRead - AvgDiskSecPerWrite - DiskReadBytesPerSec - DiskWriteBytesPerSec`winchecks metric-windows-disk`
TypeEvent/MetricDescriptionCommand
Event \(Linux\)os.linux.check-free-physical-memoryMeasures the free physical memory percentage of the Linux system, returning a CRITICAL\WARNING\OK event message, according to the thresholds specified in the parameters.`check-free-physical-memory -w 10 -c 5`
Event \(Linux\)os.linux.check-free-virtual-memoryMeasures the free virtual memory percentage of the Linux system, returning a CRITICAL\WARNING\OK event message, according to the thresholds specified in the parameters.`check-free-virtual-memory -w 10 -c 5`
Event \(Windows\)os.windows.check-free-physical-memoryMeasures the free physical memory percentage of the Windows system, returning a CRITICAL\WARNING\OK event message, according to the thresholds specified in the parameters.`winchecks check-windows-free-physfical-memory -w 10 -c 5`
Event \(Windows\)os.windows.check-free-virtual-memoryMeasures the free virtual memory percentage of the Windows system, returning a CRITICAL\WARNING\OK event message, according to the thresholds specified in the parameters.`winchecks check-windows-free-physical-memory -w 10 -c 5`
Metric \(Windows\)os.windows.metrics-system-memoryCollects the following memory metrics:- FreePhysicalMemory - TotalPhysicalMemory - FreeVirtualMemory - TotalVirtualMemorySize - AvailableMemory - TotalVisibleMemorySize`winchecks metric-windows-memory --scheme hostname.proc`
TypeEvent/MetricDescriptionCommand
Event (Linux)os.linux.check-process-cpuMeasures the Linux process CPU usage, returning a CRITICAL\WARNING\OK message, according to the thresholds specified in the parameters.check-process-cpu.rb -p acc -c 95 -w 85
Event (Linux)os.linux.check-process-memoryMeasures the Linux process memory usage, returning a CRITICAL\WARNING\OK message, according to the thresholds specified in the parameters.check-process-memory.rb -p acc -c 95 -w 85
Metric (Linux)os.linux.metrics-process-usageCollects the Linux process status, including the CPU and memory data used by the process.metrics-process-usage.rb -p acc -s hostname.proc
Event (Windows)os.windows.check-process-cpuMeasures the Windows process CPU usage, returning a CRITICAL\WARNING\OK message according to the thresholds specified in the parameters.winchecks check-windows-process-cpu-p acc -c 95 -w 85
Event (Windows)os.windows.check-process-memoryMeasures the Windows process memory usage, returning a CRITICAL\WARNING\OK message according to the thresholds specified in the parameters.winchecks check-windows-process-memory-p acc -c 95 -w 85
Metric (Windows)os.windows.metrics-process-usageCollects the Windows process status, including the CPU and memory data used by the process.winchecks metric-windows-process-status -n Svchost -s hostname.proc

Supported Agent policies

This table lists the supported Agent Client Collector for Monitoring policies that the check definitions are associated with. The policies consist of the monitored CIs and the checks that run on them.

NameDescriptionChecks
Apache Events

Monitors operational Apache HTTP web servers.To enable monitoring if the process is alive, activate the relevant check:

  • For Linux: os.linux.check-process
  • For Windows: os.windows.check-windows-process

On the Credentials tab, specify Basic Auth Credentials.

- os.linux.check-process - os.windows.check-windows-process
Apache MetricsMonitors operational Apache HTTP web servers.On the Credentials tab, specify Basic Auth Credentials.app.apache.metrics-apache
Apache Kafka EventsMonitors the status of Kafka Broker, Kafka topics, partictions, replicas and Zookeeper. 
Apache Kafka MetricsMonitors and collects metrics from Kafka Broker and Kafka Zookeeper. 
Azure DB Metrics

Monitors Azure databases on an Azure datacenter.To enable the policy's checks:

  • Configure a proxy agent.
  • Add the following Azure service principal credentials:
  • Tenant ID
  • Client ID
  • Secret Key
  • Configure the Authentication Method as Client secret.
  • Add Azure credentials in the policy.
  • Provide the subscription_id value in each check instance.

The default monitored CI Type is cmdb_ci_azure_datacenter, but the binding occurs on the Cloud Database (cmdb_ci_cloud_database).

For details on configuring a policy, see Create an Agent Client Collector policy.

 
Azure k8s Service MetricsMonitors the Azure CI, cmdb_ci_azure_datacenter. Binds with the Kubernetes data cluster, cmdb_ci_kubernetes_cluster.azure.metrics-k8s-service For details, see Azure Health Monitoring default checks and policies.
Azure VM MetricsMonitors the Azure CI, cmdb_ci_azure_datacenter. Binds with the virtual machine instance, cmdb_ci_vm_instance.- azure.metrics-vm-cpu - azure.metrics-vm-disk - azure.metrics-vm-memory - azure.metrics-vm-network - azure.metrics-vm-flows For details, see Azure Health Monitoring default checks and policies.
Basic DiscoveryRuns basic ServiceNow Discovery on all agents, every 12 hours.This check extracts basic information about the host and its running processes. The host information is used to create the corresponding host in the CMDB, while the running processes create the classified application CIs. You need advanced OS privileges to use the Net stat command to discover ports. The command that you run depends on your OS, as follows: - Linux: `sudo -n netstat -antp` - Windows: `netstat -anop TCP`check-discovery-basic
Docker Container Metrics

Collects performance metrics for Docker containers.

Provide the credentials of users who are Docker user group members or have sudo rights. Provide these credentials on the Credentials tab of the policy form.

container.docker.metrics-docker
Docker Engine Metrics

Collects general metrics for the Docker engine. Provides the credentials of a user which is either a member of the Docker user group or has been assigned sudo rights on the Credentials tab.

To enable running checks through this policy, add the servicenow user to the Docker user group on the machine where the agent is running.

container.docker.metrics-docker-info
F5 SNMP Events

Example for using SNMP checks. Because the Agent doesn't run on SNMP devices, provide the following to complete this policy:

  • A Proxy Agent and credentials.
  • The host of the Proxy Agent. On the Credentials tab, specify the SNMP Community Credentials for connecting to the server.
util.check-snmp
F5 SNMP Metrics

Example for using SNMP metrics. Because the Agent doesn't run on SNMP devices, provide the following to complete this policy:

  • Proxy Agent and credentials.
  • The host of the Proxy Agent. On theCredentials tab, specify the SNMP Community Credentials for connecting to the server.
- util.metrics-snmp - util.metrics-snmp-bulk-sn
Glassfish MetricsRuns metric checks on the Glassfish server.Glassfish metrics are supported in ITOM Agent Client Collector version 2.3.0 - August 2022, available from the ServiceNow Store. 
HAProxy EventsRetrieves the HAProxy load balancer details to determine whether it is running.HAProxy events are supported in ITOM Agent Client Collector version 2.3.0 - August 2022, available from the ServiceNow Store. 
HAProxy MetricsRetrieves the HAProxy load balancer metrics to determine whether it is running.HAProxy metrics are supported in ITOM Agent Client Collector version 2.3.0 - August 2022, available from the ServiceNow Store. 
HTTP Entry Points EventsRuns the util.check-http-follow-redirect check on all HTTP entry points that belong to application business services. The policy filter chooses the services. The services define the entry points. - To enable this check, there is a new database view which combines the application services table with the entry points table. - You can filter the services and receive the entry points. - When you receive an alert, it is automatically bound to the entry points. This alert affects the impact calculation, because entry points are considered. - This policy requires a Proxy Agent.util.check-http-follow-redirect
HTTP Entry Points MetricsFor example, when the alert is bound to the entry point, the service map identifies an entry point problem. - The metric binds to the entry point CI. In previous releases, the metric was bound to the service and the entry point was the resource. - This policy requires a Proxy Agent.util.metrics-http-curl
IIS EventsMonitors operational IIS servers.- app.iis.check-iis-alive - app.iis.check-iis-current-connections
IIS MetricsMonitors operational IIS servers.app.iis.metrics-iis
JBoss/WildFly Application Server Events

Monitoring operational JBoss/WildFly application servers.To enable monitoring if the JBoss process is alive, activate os.linux.check-process.

The jboss_home parameter in the check instance is specified as the location where JBoss is installed.

os.linux.check-process
JBoss/WildFly Application Server MetricsMonitors operational JBoss/WildFly application servers.app.jboss.metrics-jboss
Kubernetes

Monitors health of Kubernetes infrastructure, such as clusters, nodes, pod status, API, and service availability.When running Kubernetes checks:

  • Proxy agent must be enabled.
  • Enter Kubernetes credentials, either a username/password combination or a bearer token (but not both).
  • To activate and publish the policy, configure the api_server value in the check parameter definitions of each check, as one of the following:

  • https://127.0.0.1:<portnumber>/api (If the API server and agent are running on the same server)

  • https://<api_server_url>/api (Whether the API server and agent are running on the same or different servers). To use the localhost as your api_server, run the following command: "kubectl proxy -port=8081 &"

  • Run Discovery to discover all Kubernetes CIs. For details, see Kubernetes discovery.

- k8s.check-kube-apiserver-available - k8s.check-kube-nodes-ready - k8s.check-kube-pods-pending - k8s.check-kube-pods-restarting - k8s.check-kube-pods-running - k8s.check-kube-pods-runtime - k8s.check-kube-service-available - k8s.metrics-pods
Linux log monitoringMonitors logs on operational Linux servers.- util.check-logs - util.check-logs-sudo
Linux OS EventsRuns Linux checks on operational Linux servers.- os.linux.check-process - os.linux.check-system-cpu - os.linux.check-system-cpu-load - os.linux.check-system-disk-usage - os.linux.check-system-memory-percentage - os.linux.check-system-memory-swap - os.linux.check-threads-count
Linux OS MetricsCollects Linux metrics on operational Linux servers.- os.linux.metrics-memory-vmstat - os.linux.metrics-process-status - os.linux.metrics-system-cpu - os.linux.metrics-system-cpu-load - os.linux.metrics-system-disk - os.linux.metrics-system-disk-capacity - os.linux.metrics-system-disk-usage - os.linux.metrics-system-memory - os.linux.metrics-system-memory-percentage - os.linux.metrics.reboot\_count\_today
MSSQL EventsMonitors the operational MSSQL server process. Runs os.windows.check-windows-process to monitor when the server process is alive.os.windows.check-windows-process
MSSQL MetricsMonitors operational MSSQL server process. Runs app.mssql.metrics-mssql to gather metrics.app.mssql.metrics-mssql
MySQL DB Events

Monitors operational MySQL instances.On the Credentials tab, specify Basic Auth Credentials for connecting to the database server.

Note: Utility checks, prefixed with util, have required parameters for which you must specify a value. These parameters have no default values.

- app.mysql.check-mysql-alive - app.mysql.check-mysql-threads - util.check-mysql-query
MySQL DB Metrics

Monitors operational MySQL instances.On the Credentials tab, specify Basic Auth Credentials for connecting to the database server.

Note: Utility checks, prefixed with util, have required parameters for which you must specify a value. These parameters have no default values.

- app.mysql.metrics-mysql - app.mysql.metrics-mysql-processes - util.metrics-mysql-query
Network ping metricsMonitors the ip address discovered in the ServiceNow instance. The cmdb\_ci\_hardware monitored CI type is bound to the relevant server:This policy requires a proxy agent.util.metrics-ping
Oracle DB Events

Monitors operational Oracle Database instances.On the Credentials tab, specify Basic Auth Credentials for connecting to the database server.

Note: Utility checks, prefixed with util, have required parameters for which you must specify a value. These parameters have no default values.

app.oracle.check-oracle-alive
Oracle DB Metrics

Monitors operational Oracle Database instances.On the Credentials tab, specify Basic Auth Credentials for connecting to the database server.

Note: Utility checks, prefixed with util, have required parameters for which you must specify a value. These parameters have no default values.

- app.oracle.metrics-oracle - util.metrics-oracle-query
Self-Healing EventsRuns a ping command to another host. Ensure that you run this check in proxy mode.util.check-ping
Tomcat Events

Monitors operational Apache Tomcat servers. To enable monitoring if the Tomcat process is alive, activate the relevant check:

  • For Linux: os.linux.check-process
  • For Windows: util.check-windows-service

If the Tomcat service is running under a different name, update the value of the check instance's service parameter to the correct value.

- os.linux.check-process - util.check-windows-service
Tomcat MetricsMonitors operational Apache Tomcat servers.If Tomcat Metrics are running on a port other than the default port (9000), update the value of the check instance's port parameter to the correct port value.app.tomcat.metrics-tomcat
Varnish MetricsMonitors and collects metrics from Varnish.Varnish metrics are supported in ITOM Agent Client Collector version 2.3.0 - August 2022, available from the ServiceNow Store. You must perform discovery using application fingerprints before running Varnish checks. For details, see Enable running of Varnish checks. 
vSphere MetricsMonitors and collects metrics from vSphere.vSphere metrics are supported in ITOM Agent Client Collector version 2.3.0 - August 2022, available from the ServiceNow Store. This policy requires a proxy agent. 
WebLogic Application Server EventsMonitors operational Oracle WebLogic application servers. This policy monitors if the WebLogic process running on Linux is alive.On the Credentials tab, specify Basic Auth Credentials for connecting to the application server.os.linux.check-process
WebLogic Application Server Metrics

Monitors operational Oracle WebLogic application servers.On the Credentials tab, specify Basic Auth Credentials for connecting to the application server.

Ensure that the user running the agent has sufficient permissions to access the required files in the WebLogic installation directories.

app.weblogic.metrics-weblogic
WebSphere Application Server EventsMonitors operational IBM WebSphere servers. This policy monitors if the WebSphere process running on Linux is alive. On the Credentials tab, specify Basic Auth Credentials for connecting to the application server.os.linux.check-process
WebSphere Application Server MetricsMonitors operational IBM WebSphere servers. On the Credentials tab, specify Basic Auth Credentials for connecting to the application server.app.websphere.metrics-websphere
Windows Log MonitoringMonitors logs on operational Windows servers.os.windows.check-log You can block event creation for this check when no process is detected. For details, see Block event creation for non-existent entities.
Windows OS EventsRuns Windows checks on operational Windows servers.- os.windows.check-processor-queue-length - os.windows.check-system-cpu-load - os.windows.check-system-disk - os.windows.check-system-memory - os.windows.check-system-process - os.windows.check-windows-directory - os.windows.check-windows-directory - os.windows.check-windows-directory - os.windows.check-windows-pagefile - os.windows.check-windows-process
Windows OS Events - ExtendedRuns Windows checks to monitor directories and files on Windows servers.- check-directory-file-count - check-directory-integrity - check-file-age - check-file-response-time - check-file-size - check-file-space - os.windows.check-directory-space
Windows OS MetricsCollects Windows metrics on operational Windows servers.- os.windows.metrics-processor-queue-len - os.windows.metrics-system-cpu-load - os.windows.metrics-system-disk-usage - os.windows.metrics-system-memory-percent - os.windows.metrics-system-network - os.windows.metrics-system-uptime
Zscaler Monitoring PolicyExecutes Zscaler monitoring on all of a machine's CIs.- zscaler-monitoring-check - zscaler-remediation-check
  • Active Directory metrics
    The following table lists the metrics that are gathered as output from Active Directory checks. Entries indicated as Featured metrics are high-visibility metrics that are displayed in the Operator Workspace Metric tab after an alert is generated. These metrics provide the operator with additional information to help them further explore the specified issue.
  • Apache Kafka default checks and policies
    Agent Client Collector provides the following policies for Apache Kafka health monitoring. Policies come with the checks specified in the indicated table. Policies and checks are available for both Windows and Linux.
  • Apache Kafka metrics
    The following table lists the metrics that are gathered as output from Kafka checks. Entries indicated as Featured metrics are high-visibility metrics that are displayed in the Operator Workspace Metric tab after an alert is generated. These metrics provide the operator with additional information to help them further explore the specified issue.
  • AWS Health Monitoring default checks and policies
    Agent Client Collector provides the following default checks and policies for AWS monitoring.
  • AWS metrics
    The following tables list and describe the metrics that are gathered as output from the specified AWS checks. Entries indicated as Featured metrics are high-visibility metrics that are displayed in the Operator Workspace Metric tab after an alert is generated. These metrics provide the operator with additional information to help them further explore the specified issue.
  • Azure Health Monitoring default checks and policies
    Agent Client Collector provides the following default checks and policies for Azure health monitoring.
  • Azure metrics
    The following tables list and describe the metrics that are gathered as output from Azure checks. Entries indicated as Featured metrics are high-visibility metrics that are displayed in the Operator Workspace Metric tab after an alert is generated. These metrics provide the operator with additional information to help them further explore the specified issue.
  • Azure cloud metrics
    Azure cloud metrics are gathered from Azure virtual machines (VMs) and Azure storage account policies. Collecting the cloud metrics enables you to monitor the performance of your Azure resources.
  • Cassandra default checks and policies
    Agent Client Collector provides the following policies for Cassandra health monitoring. Policies come with the checks specified in the indicated table. Policies and checks are available for Linux only.
  • Cassandra metrics
    The following table lists the metrics that are gathered as output from Cassandra checks. Entries indicated as Featured metrics are high-visibility metrics that are displayed in the Operator Workspace Metric tab after an alert is generated. These metrics provide the operator with additional information to help them further explore the specified issue.
  • Directory Scan monitoring default checks and policies
    The Agent Client Collector provides the following default checks and policies for Directory Scan monitoring.
  • Google Cloud Platform (GCP) metrics
    The following table lists and describes the metrics that are gathered by the acc_grp_metrics_list.json configuration data file. The file is uploaded to a check definition or check instance, and the metrics in the file are monitored by the check for its agent.
  • Glassfish default checks and policies
    Agent Client Collector provides the following default checks and policies for Glassfish monitoring.
  • GlassFish metrics
    The following table lists the metrics that are gathered as output from GlassFish checks. Entries indicated as Featured metrics are high-visibility metrics that are displayed in the Operator Workspace Metric tab after an alert is generated. These metrics provide the operator with additional information to help them further explore the specified issue.
  • HAProxy default checks and policies
    Agent Client Collector provides the following default checks and policies for HAProxy monitoring.
  • HAProxy metrics
    The following table lists the metrics that are gathered as output from HAProxy checks. Entries indicated as Featured metrics are high-visibility metrics that are displayed in the Operator Workspace Metric tab after an alert is generated. These metrics provide the operator with additional information to help them further explore the specified issue.
  • HTTP default checks and policies
    Agent Client Collector provides the following policies for HTTP health monitoring. Policies come with the checks specified in the tables below.
  • HTTP entry point metrics
    The following table lists the metrics that are gathered as output from HTTP entry point checks. Entries indicated as Featured metrics are high-visibility metrics that are displayed in the Operator Workspace Metric tab after an alert is generated. These metrics provide the operator with additional information to help them further explore the specified issue.
  • HTTP response code check
    Agent Client Collector provides the following additional check for HTTP response code. This check is not associated with any policy.
  • Internet Information Services (IIS) metrics
    The following table lists the metrics that are gathered as output from IIS checks. Entries indicated as Featured metrics are high-visibility metrics that are displayed in the Operator Workspace Metric tab after an alert is generated. These metrics provide the operator with additional information to help them further explore the specified issue.
  • Linux default checks and policies
    Agent Client Collector provides the following default checks and policies for Linux Metrics monitoring.
  • Linux metrics
    The following table lists the metrics that are gathered as output from Linux checks. Entries indicated as Featured metrics are high-visibility metrics that are displayed in the Operator Workspace Metric tab after an alert is generated. These metrics provide the operator with additional information to help them further explore the specified issue.
  • MongoDB default checks and policies
    Agent Client Collector provides the following policies for MongoDB health monitoring. Policies come with the checks specified in the indicated table. Policies and checks are available for both Windows and Linux.
  • MongoDB metrics
    The following table lists the metrics that are gathered as output from MongoDB checks. Entries indicated as Featured metrics are high-visibility metrics that are displayed in the Operator Workspace Metric tab after an alert is generated. These metrics provide the operator with additional information to help them further explore the specified issue.
  • MS Exchange default checks and policies
    Agent Client Collector provides the following default checks and policies for MS Exchange monitoring.
  • MSSQL default checks and policies
    The Agent Client Collector provides the following default checks and policies for MSSQL Metrics monitoring.
  • MySQL default checks and policies
    The Agent Client Collector provides the following default checks and policies for MySQL Metrics monitoring.
  • Network ping default checks and policies
    Agent Client Collector provides the following default checks and policies for Network ping monitoring. Policies and checks are available for both Windows and Linux.
  • Network ping metrics
    The following table lists the metrics that are gathered as output from Network ping checks. Entries indicated as Featured metrics are high-visibility metrics that are displayed in the Operator Workspace Metric tab after an alert is generated. These metrics provide the operator with additional information to help them further explore the specified issue.
  • Network host availability check
    Agent Client Collector provides the following default check for network ping monitoring. The check is available for both Windows and Linux.
  • Nginx default checks and policies
    Agent Client Collector provides the following policies for Nginx health monitoring. Policies come with the checks specified in the indicated table. Policies and checks are available for both Windows and Linux.
  • Nginx metrics
    The following table lists the metrics that are gathered as output from Nginx checks. Entries indicated as Featured metrics are high-visibility metrics that are displayed in the Operator Workspace Metric tab after an alert is generated. These metrics provide the operator with additional information to help them further explore the specified issue.
  • PostgreSQL default checks and policies
    Agent Client Collector provides the following default checks and policies for PostgreSQL health monitoring.
  • PostgreSQL metrics
    The following tables list and describe the metrics that are gathered as output from the specified PostgreSQL checks. Entries indicated as Featured metrics are high-visibility metrics that are displayed in the Operator Workspace Metric tab after an alert is generated. These metrics provide the operator with additional information to help them further explore the specified issue.
  • RabbitMQ default checks and policies
    Agent Client Collector provides the following default checks and policies for RabbitMQ health monitoring. You must perform RabbitMQ discovery before executing the checks. RabbitMQ checks are available only in a Windows environment.
  • RabbitMQ metrics
    The following table lists the metrics that are gathered as output from RabbitMQ checks. Entries indicated as Featured metrics are high-visibility metrics that are displayed in the Operator Workspace Metric tab after an alert is generated. These metrics provide the operator with additional information to help them further explore the specified issue.
  • URL Monitoring default checks and policies
    Agent Client Collector provides policies for URL Monitoring. Polices come with embedded checks.
  • Varnish default checks and policies
    Agent Client Collector provides the following default checks and policies for Varnish monitoring.
  • Varnish metrics
    The following table lists the metrics that are gathered as output from Varnish checks. Entries indicated as Featured metrics are high-visibility metrics that are displayed in the Operator Workspace Metric tab after an alert is generated. These metrics provide the operator with additional information to help them further explore the specified issue.
  • vSphere default checks and policies
    Agent Client Collector provides the following default checks and policies for vSphere monitoring.
  • vSphere metrics
    The following table lists the metrics that are gathered as output from vSphere checks. Entries indicated as Featured metrics are high-visibility metrics that are displayed in the Operator Workspace Metric tab after an alert is generated. These metrics provide the operator with additional information to help them further explore the specified issue.
  • Windows default checks and policies
    Agent Client Collector provides the following default checks and policies for Windows health monitoring.
  • Windows metrics
    The following table lists the metrics that are gathered as output from Windows checks. Entries indicated as Featured metrics are high-visibility metrics that are displayed in the Operator Workspace Metric tab after an alert is generated. These metrics provide the operator with additional information to help them further explore the specified issue.
  • Windows log monitoring default checks and policies
    Agent Client Collector provides the following policy for Windows log monitoring.
  • Linux log monitoring default checks and policies
    Agent Client Collector provides the following policy for Linux log monitoring.

Parent Topic:Agent Client Collector Monitoring reference