This guide demonstrates how to set up EventSentry to trigger an alert when a process runs longer than a specified duration. We will use PowerShell as the example for this configuration.
Screenshot 1 — Creating the Package
Screenshot 2 — Adding a performance object
Screenshot 3 — Configuring a performance object
Screenshot 4 — Assigning the package
Be sure to assign the package by right clicking on the package, clicking “Assign” and selecting the Computers or Groups to assign this package to. You can alternatively make the package Global (to apply to all hosts)
Screenshot 5 — Configuring the alert threshold
Explanation: We just created a package (Thread Intel) with a Performance / SNMP object, that will monitor all “powershell*” processes (the * is needed because multiple PowerShell instances will be named powershell#1 powershell#2 and so on). An alert will be generated in the event log if the process is running for more than 600 seconds (10 minutes).
Manage your cookie preferences below:
To learn more about our use of cookies, please see our
Privacy Policy.