Techzone
© GHIT ApS
DomainScan - Server monitoring
 
   
DomainScan Service description
Tech doc #1

Revision v3.1

Last Update
Jan 7 2009

Published
June 14 2004

Affected versions
DomainScan Server Monitoring 7
DomainScan Pro 2.7+
DomainScan Standard 6.5+




Scan cycle up
DomainScan Pro monitors the network in cycles, as shown in the picture below:


Initially DomainScan Pro Service Control will be started automatically when Windows is started. Once started DomainScan Pro Service Control will immediately start DomainScan Pro Engine which is the service that monitors the network.

DomainScan Pro Service Control up
DomainScan Pro Service Control is always running, and can be described as a watchdog service that monitors that DomainScan Pro Engine is running properly

DomainScan Pro Service Control is also responsible for waking DomainScan Pro Engine when the idle period (Idle time) has completed.

DomainScan Pro Service Control does not need a specified account to run, as it does not perform any network related activities.

DomainScan Pro Engine up
DomainScan Pro Engine is only active during the actual scan (Scan time), and is the component that monitors the network, gathers audit data etc.

During a scan, these 3 steps will be performed:

Preprocessing

Backup, if configured.

The Monitor time is set. This is the fixed time stamp that is used during the entire scan, which means that anything that happens during the scan will have the same time marker.

The database is mounted, and tested for integrity. DomainScan Pro will not continue, unless the database integrity is intact.

Commit pending changes (pending changes are not saved to the database before the final database update in the post-process)

Scanning

This step is highly parallelized, and consists of two sub steps that are performed simultaneously, namely gather devices to scan and monitor devices.

Individual device processing is also done in this step.


Post processing

Events are evaluated, and Responses are triggered, if needed.

Statistics are updated

Event files are updated

The database are updated, and DomainScan client can now update


Once completed, DomainScan Pro Engine will shut down and the Idle time will begin, which is controlled by DomainScan Service Control.

DomainScan Pro Engine needs to run with privileges that allow interaction with the network. For ease of use, it is recommended that DomainScan Pro Engine runs with administrative privileges due to the fact that this works regardless of Windows version.
However, one may successfully try to lower credentials – however it’s not supported by GH Software.


Watchdog log up
It is possible to enable logging for the DomainScan Pro Service Control service. Follow these steps to enable the log:

Warning:This step includes modifying the Windows Registry directly, and it is recommended that the registry is backed up before changes are made. Changes are at your own risk

1: Open the Windows Registry Editor (regedit.exe), and open the following key:

DomainScan Pro
 HKEY_LOCAL_MACHINE\SOFTWARE\GH Software\DomainScan Pro\Service

DomainScan Standard
 HKEY_LOCAL_MACHINE\SOFTWARE\GH Software\DomainScan Standard\Service

2: Create a new String with the name Engine_Log. In this entry, enter a file name where DomainScan Pro Service Control is to write output data.

DomainScan Pro Service Control will start writing information at the beginning of the next scan cycle.

To remove the log, delete the Engine_Log entry.

  2003 - 2010 GHIT ApS (Formerly GH Software). Contact