How Do I....Setup monitoring of windows 2008/2011 SBS backups?

How Do I....Setup monitoring of windows 2008/2011 SBS backups?

Hi Everyone,

First time caller here :)

I am reviewing OPSview core and am having an issue monitoring backups of sbs servers 2008/2011. I have successfully got the sbs2003 server backups monitored using the following:

check_nrpe -H $HOSTADDRESS$ -p %NRPE_PORT% -t 30 -c nsc_checkeventlog -a 'file=application MaxWarn=1 MaxCrit=1 filter=new filter+generated=<1d filter=id=5634 descriptions truncate=75 unique'

The above means that we get an alert if event ID 5634 shows in the event viewer logs.

The issue I am facing is that the location of the eventlog for backups of sbs2008/2011 are located in a subfolder within event viewer. They are in the following location within event viewer:

Application and Servers Logs/Microsoft/Windows/Backup/Operational

How can I get the checkeventlog to look within this to check the backup log status so that I can configure a similar alert?


Hi Deborah,

Hi Deborah,

Probably a bit too late now for a reply! - But I believe OpsView is just looking for a file name.

Therfore, take a look at the file name of the event log, and try adding that on the command.

You may have to move the log file's default location to the root folder

(i.e. Application is usually here: %SystemRoot%\System32\Winevt\Logs\Application.evtx  so move the SBS backup log to %SystemRoot%\System32\Winevt\Logs\)