ConfigurationChange
| where ConfigChangeType == "WindowsServices"
and SvcState == "Stopped"
and (
Computer has "NET-SQL2.networkhg.org.uk"
or Computer has "NET-SQL3.networkhg.org.uk"
or Computer has "NET-GISSQL1.networkhg.org.uk"
or Computer has "NET-CALSQL.networkhg.org.uk"
)
and (
SvcDisplayName == "SQL Full-text Filter Daemon Launcher (TEST)"
or SvcDisplayName == "SQL Full-text Filter Daemon Launcher (MSSQLSERVER)"
or SvcDisplayName == "SQL Full-text Filter Daemon Launcher (SQLEXPRESS)"
or SvcDisplayName == " SQL Server (MSSQLSERVER)"
or SvcDisplayName == "SQL Server (Test) "
or SvcDisplayName == "SQL Server Agent (MSSQLSERVER)"
or SvcDisplayName == "SQL Server Agent (Test)"
or SvcDisplayName == "SQL Server Browser"
or SvcDisplayName == "SQL Server Integration Services 10.0"
or SvcDisplayName == "SQL Full-text Filter Daemon Launcher (FIDO)"
or SvcDisplayName == "SQL Full-text Filter Daemon Launcher (SUN)"
or SvcDisplayName == "SQL Server (FIDO)"
or SvcDisplayName == "SQL Server (SUN)"
or SvcDisplayName == "SQL Server Agent (FIDO)"
or SvcDisplayName == "SQL Server VSS Writer"
or SvcDisplayName == " SQL Server Integration Services 11.0"
or SvcDisplayName == "SQL Server Reporting Services (MSSQLSERVER)"
or SvcDisplayName == "SQL Server Reporting Services (SQLEXPRESS)"
or SvcDisplayName == "SQL Server Analysis Services (MSSQLSERVER)"
)
要问的问题,如果其中一个服务在上述任何服务器中停止,我会收到有关该服务器的电子邮件还是将列出所有服务器
编写查询只是您问题的一半。需要创建基于此查询的警报才能获取电子邮件。
电子邮件将是查询的结果,在这种情况下,查询将是已停止的服务器/服务的所有组合。
谢谢,我已经得到了这个问题的答案,我创建了另一个与此类似的查询,并且我创建了一个警报,如果任何服务在服务器组合中停止,我会通过电子邮件对组进行操作。
见解 前 10 个结果 计算机 NH-P2PAPP01.networkhg.org.uk
ConfigChangeType WindowsServices 更改类别已修改 源计算机ID d901f954-1d9a-43b5-a0b9-afd0cf688923 SvcChangeType State SvcDisplayName Integra SPC FINPROD SvcName SPCFINPROD SvcState 已停止 SvcPreviousState Run SvcStartupType Auto SvcAccount LocalSystem SvcPath F:\Integra\intspc\FINPROD\bin..\bin\spc_64.exe//RS//SPCFINPROD 源系统操作管理器 MG 00000000-0000-0000-0000-000000000001 管理组名称 AOI-4d3a9999-1d9a-4086-8d0c-1a31ac03c9d8 租户 ID 4d3a9999-1d9a-4086-8d0c-1a31ac03c9d8 生成时间 2020-06-14T01:00:20 VMUUID 116e3f42-eb84-de2e-00c5-c56ed4f4b80f 最后快照年龄 60 类型配置更改