Subscribe to Windows IT Pro

 

Get Newsletters

  • Get the Latest News
  • Product Updates
  • Helpful Tricks
  • Productivity Tips

Subscribe Now!

January 10, 2007 12:00 AM

EventSentry 2.72

Windows IT Pro
InstantDoc ID #94824
Rating: (1)

NETIKUS.NET’s EventSentry 2.72 is a network-monitoring tool that collects events on monitored computers, filters them according to customizable preferences, and forwards relevant items to the administrator. In addition to collecting event-log data from Windows servers and workstations, EventSentry agents can also monitor disk and processor performance, printing, logons, service state, and installed applications. A Windows event log stores all sorts of information useful to the administrator; it also contains many irrelevant items. EventSentry endeavors to deliver the useful items directly to the administrator at his or her desk. In times of trouble, this information can speed the diagnosis of problems.

An EventSentry agent runs as a service on monitored computers, sending collected data in real time to the management console. EventSentry can use MySQL, Microsoft SQL Server 2005, or SQL Server 2000 databases. Although I found the SQL Server option easier to configure, I appreciated having the choice. The installation and configuration of EventSentry was astoundingly easy. I completed the setup and did some preliminary filtering of unwanted information in just half an hour.

You manage EventSentry through agents, groups, and packages. From the EventSentry management console, I joined computers to groups by using the Active Directory (AD) linking feature. I was then able to deploy the agent automatically from the management console without physically visiting the monitored computers. The management console pushes alerting, health monitoring, and tracking packages to the agents. Depending on which packages are associated with a monitored computer, the computer’s agent performs tasks such as polling for disk space information or sending an email notification if a particular event occurs. EventSentry provides some preconfigured packages suitable for event tracking of common applications such as Microsoft Exchange Server and antivirus software. If critical services are halted, the administrator receives an email notification, page, or network message.

EventSentry also performs basic network monitoring, allowing the administrator to check node connectivity via Internet Control Message Protocol (ICMP) pings or custom TCP port pings. It is also capable of capturing syslog events from UNIX, Cisco, and other syslog-capable devices. With additional hardware available from NETIKUS.NET, EventSentry can monitor a server’s physical environment for temperature, humidity, and smoke.

EventSentry notified me by email of a problem in my test network. I opened up the EventSentry management application to read the alert: Microsoft ISA Server had attempted to take over master browser status of the domain. By following the link in the alert to EventSentry’s online knowledge base, MyEventLog.com, I determined that ISA Server wasn’t properly filtering incoming AD messages. I like this feature, but I wish the link to MyEventLog.com were in the email message so I wouldn’t have to open the EventSentry application.

The application documentation isn’t particularly strong. The EventSentry Quickstart Guide, available online, doesn’t include step-by-step installation and configuration instructions, which is what I expect from such a document. There are typos and grammatical errors on the Web page and within the Help file, which weakens my confidence in the information.

Although I found EventSentry to be a good product overall, I had a few problems with it. Some parts of the interface require more clicks than I thought should be necessary; it isn’t always clear whether a button is depressed or not, such as when I was configuring the date and time settings for when notifications should be sent; and the reporting Web page doesn’t auto refresh. These are minor issues to which a user could adapt.

However, I would not recommend EventSentry to large organizations because of a fundamental architectural problem: The management console can be run only locally and can run only a single instance at a time. As a result, multiple users can’t access the management console simultaneously. (By comparison, Microsoft Operations Manager—MOM—2005 has a complex architecture designed for delegation of responsibility to varying teams.) With EventSentry, a single computer is the focus of monitoring.

I was pleased with EventSentry’s easy setup and configuration and found the monitoring capabilities adequate for the needs of smaller and less complex organizations. Large IT organizations should give EventSentry a pass and go straight to MOM. However, smaller shops with the need to track some mission-critical services and computers will be pleased with EventSentry’s ease of use and effectiveness.

Summary
EventSentry 2.72

PROS: Simple to install
CONS: Poor documentation; only one management console instance can run at a time
RATING: 3 out of 5
PRICE: From one host for $69 to 150 hosts for $23.99 each; contact vendor for pricing for more than 150 hosts
RECOMMENDATION: Offers affordable and reliable monitoring to small organizations. Not suitable for large IT departments needing multiple-user capabilities.
CONTACT: NETIKUS.NET • 877-638-4587 • 312-624-7698• http://www.netikus.net

Related Content:

ARTICLE TOOLS

Comments
  • BRYAN
    5 years ago
    Aug 09, 2007

    I had high hopes for this product. I consider myself well adept at figuring things out. This product is EXTREMELY complicated, and one big can of worms. Hard to get it to do anything meaningful except constantly alert you about minor issues. DREADFUL documentation, if it could even be called that.

    It's a shame, because this looks like it could have potential, if you could ever figure it out.

You must log on before posting a comment.

Are you a new visitor? Register Here

advertisement

advertisement

White Papers

Get your Windows 7 deployment off to the right start by implementing PC lockdown. A locked-down environment is easier and cheaper to support since users are less likely to make unnecessary changes to the core system configuration - read more here!

Essential Guides

Is your iSCSI "lossy"? The reality is that most off-the-shelf Ethernet hardware deployed for iSCSI can lose packets, resulting in slow performance or application downtime. Learn how to assess your current iSCSI infrastructure and engineer an advanced iSCSI SAN infrastructure.

Web Seminars

What's the best way to keep your network safe from malware? In this web seminar, security expert Greg Shields suggests an alternative method to the traditional blacklisting approach that is common with anti-virus and anti-malware solutions.

eLearning Series

We bring the experts direct to you to share their real-world perspective and expertise. During each event, three sessions stream in real time, so you can learn, ask questions, and get solutions.
Upcoming event: Getting the Most with Exchange 2010 with Paul Robichaux

Subscribe to Windows IT Pro!

Windows is a trademark of the Microsoft group of companies. Windows IT Pro is used by Penton Media Inc. under license from owner.