Integrate Microsoft Windows Hyper V EventTracker v7.x Publication Date: Aug 9, 2014 EventTracker 8815 Centre Park Drive Columbia MD 21045 www.eventtracker.com
Abstract Hyper-V in Windows Server 2008 and Windows Server 2008 R2 enables you to create a virtualized server computing environment. This guide provides instructions to configure Microsoft Windows Hyper V to send the event logs to EventTracker Enterprise. Once events are configured to send to EventTracker Manager, alerts, dashboard and reports can be configured into EventTracker. Scope The configurations detailed in this guide are consistent with EventTracker Enterprise version 7.X and later, and Windows 2008 and later. Audience Microsoft Windows Hyper V users, who wish to forward event logs to EventTracker Manager and monitor events using Event Tracker Enterprise. The information contained in this document represents the current view of Prism Microsystems Inc. on the issues discussed as of the date of publication. Because Prism Microsystems must respond to changing market conditions, it should not be interpreted to be a commitment on the part of Prism Microsystems, and Prism Microsystems cannot guarantee the accuracy of any information presented after the date of publication. This document is for informational purposes only. Prism Microsystems MAKES NO WARRANTIES, EXPRESS OR IMPLIED, AS TO THE INFORMATION IN THIS DOCUMENT. Complying with all applicable copyright laws is the responsibility of the user. Without limiting the rights under copyright, this paper may be freely distributed without permission from Prism, as long as its content is unaltered, nothing is added to the content and credit to Prism is provided. Prism Microsystems may have patents, patent applications, trademarks, copyrights, or other intellectual property rights covering subject matter in this document. Except as expressly provided in any written license agreement from Prism Microsystems, the furnishing of this document does not give you any license to these patents, trademarks, copyrights, or other intellectual property. The example companies, organizations, products, people and events depicted herein are fictitious. No association with any real company, organization, product, person or event is intended or should be inferred. 2014 Prism Microsystems Corporation. All rights reserved. The names of actual companies and products mentioned herein may be the trademarks of their respective owners. 1
Table of Contents Abstract... 1 Scope... 1 Audience... 1 Microsoft Windows Hyper V... 3 Prerequisites... 3 Configure Microsoft Windows Hyper V to send event logs to EventTracker... 3 Import Hyper-V knowledge pack in EventTracker... 4 Import Category... 4 Import Alerts... 5 Verify Microsoft Windows Hyper V knowledge pack in EventTracker... 6 Verify categories... 6 Verify alerts... 6 EventTracker Knowledge Pack... 8 Categories... 8 Alerts... 10 2
Microsoft Windows Hyper V Hyper-V in Windows Server 2008 and Windows Server 2008 R2 enables you to create a virtualized server computing environment. You can use a virtualized computing environment to improve the efficiency of your computing resources by utilizing more of your hardware resources. This is possible because you use Hyper-V to create and manage virtual machines and their resources. Each virtual machine is a virtualized computer system that operates in an isolated execution environment. This allows you to run multiple operating systems simultaneously on one physical computer. Prerequisites EventTracker should be installed Microsoft Windows 2008 and later should be installed Microsoft Hyper V should be installed Configure Microsoft Windows Hyper V to send event logs to EventTracker Deploy EventTracker Agent on Hyper V machine. Once the events are triggered, logs will be sent to EventTracker automatically. 3
Import Hyper-V knowledge pack in EventTracker 1. Launch EventTracker Control Panel. 2. Double click ExportImport Utility, and then click the Import tab. Figure 1 Import Category/Alert as given below. Import Category 1. Click Category option, and then click the browse button. 4
2. Locate All HyperV group of categories.iscat file, and then click the Open button. 3. To import categories, click the Import button. EventTracker displays success message. Figure 2 4. Click OK, and then click the Close button. Import Alerts 1. Click Alert option, and then click the browse button. 2. Locate All HyperV group of alerts.isalt file, and then click the Open button. 3. To import alerts, click the Import button. EventTracker displays success message. Figure 3 4. Click the OK button, and then click the Close button. 5
Verify Microsoft Windows Hyper V knowledge pack in EventTracker Verify categories 1. Logon to EventTracker Enterprise. 2. Click the Admin menu, and then click Categories. 3. To view the imported categories, in the Category Tree, expand Microsoft Windows Hyper V group folder. Figure 4 Verify alerts 1. Logon to EventTracker Enterprise. 2. Click the Admin menu, and then click Alerts. 3. In the Search box, type Hyper V, and then click the Go button. Alert Management page will display all the imported alerts. 6
Figure 5 4. To activate the imported alerts, select the respective checkbox in the Active column. EventTracker displays message box. Figure 6 5. Click OK, and then click the Activate Now button. 7
EventTracker Knowledge Pack Categories Hyper V Configuration failed: This category based report provides information related to Microsoft Windows Hyper-V configuration failed. Hyper V Hypervisor launch aborted: This category based report provides information related to Hypervisor launch aborted in a virtual network. Hyper V Hypervisor launch failed: This category based report provides information related to Hypervisor launch failed. Hyper V Hypervisor traces corrupted: This category based report provides information related to Hypervisor traces are corrupted. Hyper V Image management service: This category based report provides information related to Hyper-V Image management Service. Hyper V Insufficient system resources: This category based report provides information related to virtual machine start failed because of insufficient system resources. Hyper V Network adaptor failed: This category based report provides information related to network adapters failed to power up in a virtual network. Hyper V Network adaptor started: This category based report provides information related to virtual network adapters power up in a virtual network. Hyper V Network conflict: This category based report provides information related to virtual network conflicts with another adapter. Hyper V Network resource error: This category based report provides information related to error performed in a network resource of a virtual network. Hyper V New partition created: This category based report provides information related to new partition created. Hyper V Partition creation failed: This category based report provides information related to new partition failed to create. Hyper V Partition deleted: This category based report provides information related to new partition deleted. 8
Hyper V Server shutdown: This category based report provides information related to Hyper-V physical machine is shutting down. Hyper V Virtual disk compacted: This category based report provides information related to virtual hard disk compacted. Hyper V Virtual disk convert failed: This category based report provides information related to disk conversion failed. Hyper V Virtual disk converted: This category based report provides information related to virtual hard disk is converted from fixed to dynamic or dynamic to fixed. Hyper V Virtual disk create failed: This category based report provides information related to virtual hard disk creation failed. Hyper V Virtual disk created: This category based report provides information related to new virtual hard disk created. Hyper V Virtual disk expanded: This category based report provides information related to virtual hard disk expanded. Hyper V Virtual machine creation failed: This category based report provides information related to virtual machine creation failed. Hyper V Virtual machine import failed: This category based report provides information related to virtual machine import failed. Hyper V Virtual machine initialize failed: This category based report provides information related to virtual machine failed to initialize. Hyper V Virtual machine restore failed: This category based report provides information related to virtual machine restore failed. Hyper V Virtual machine start failed: This category based report provides information related to virtual machine failed to start. Hyper V Virtual machine started: This category based report provides information related to virtual machine started successfully. Hyper V Virtual switch created: This category based report provides information related to virtual switch created in a virtual network. Hyper V Virtual switch deleted: This category based report provides information related to virtual switch is deleted in a virtual network. 9
Hyper V Virtual switch setup started: This category based report provides information related to switch setup started in a virtual network. Hyper V VM configuration error: This category based report provides information related to virtual machine configuration files are missing or corrupt. Hyper V VM export failed: This category based report provides information related to exporting virtual machine is failed. Hyper V VM management service: This category based report provides information related to virtual machine management service started or stopped. Hyper V VM snapshot created: This category based report provides information related to virtual machine snapshot created successfully. Hyper V Worker process failed: This category based report provides information related to failed to start worker process. Alerts Hyper V Hypervisor traces corrupted: This alerts is generated when Hypervisor traces are corrupted. Hyper V Partition creation failed: This alert is generated when new partition failed to create. Hyper V Virtual machine initialize failed: This alert is generated when virtual machine failed to initialize. Hyper V Virtual switch deleted: This alert is generated when virtual switch is deleted in a virtual network. Hyper V VM configuration error: Alerts is generated when virtual machine configuration files are missing or corrupt. 10