Click to Rate and Give Feedback
TechNet
TechNet Library
TechNet Archive
MOM
MOM 2000
Opsguide
 Appendix A - Predefined Reports
Appendix A - Predefined Reports
Archived content. No warranty is made as to technical accuracy. Content may contain URLs that were valid when originally published, but now link to sites or pages that no longer exist.

Send feedback to the MOM Documentation Team (momdocs@microsoft.com).

MOM Reporting includes the following predefined sets of reports:

Active Directory reports

These reports cover operations, discovery, health monitoring and operational recovery, and replication monitoring.

Domain Controllers by Domain Summarizes information about the Microsoft® Active Directory domain controllers, sorted by domain. This report runs in a Microsoft Windows 2000 environment only. Reports do not reflect configuration changes until Active Directory is replicated. The length of the delay depends on the replication interval.

Domain Controllers by Site Summarizes information about the Active Directory domain controllers, sorted by site. This report runs in a Windows 2000 environment only. Reports do not reflect configuration changes until Active Directory is replicated. The length of the delay depends on the replication interval.

Operations Master Best Practices Summarizes the best practices of Active Directory Operations Masters. This report runs in a Windows 2000 environment only. Reports do not reflect configuration changes until Active Directory is replicated. The length of the delay depends on the replication interval.

Operations Masters by Computer Summarizes the Operations Masters and Global Catalogs for each domain, sorted by computer. This report runs in a Windows 2000 environment only. The five Operations Masters are: Domain Naming Master, Infrastructure Master, PDC Master, RID Master, and Schema Master. Reports do not reflect configuration changes until Active Directory is replicated. The length of the delay depends on the replication interval.

Operations Masters by Role Summarizes the Operations Masters and Global Catalogs for each domain, sorted by role. This report runs in a Windows 2000 environment only. The five Operations Masters are: Domain Naming Master, Infrastructure Master, PDC Master, RID Master, and Schema Master. Reports do not reflect configuration changes until Active Directory is replicated. The length of the delay depends on the replication interval.

Replication Topology by Domain Controller Summarizes the Active Directory replication topology sorted by domain controller. This report runs in a Windows 2000 environment only. Reports do not reflect configuration changes until Active Directory is replicated. The length of the delay depends on the replication interval.

Replication Topology by Site Summarizes the Active Directory replication topology sorted by site. This report runs in a Windows 2000 environment only. Reports do not reflect configuration changes until Active Directory is replicated. The length of the delay depends on the replication interval.

Active Directory Trust Web Summarizes the trust relationships of Active Directory domains. This report runs in a Windows 2000 environment only. Reports do not reflect configuration changes until Active Directory is replicated. The length of the delay depends on the replication interval.

Authentication Performance Displays a summary table of counters specific to Active Directory authentications, followed by a graph for each server that displays trending data for the counters in the summary table. The summary table shows the average for each counter over the reporting period.

Client Side Response Time Displays data collected by the Active Directory Client Side monitoring pack, including both the Lightweight Directory Access Protocol (LDAP) and Internet Control Message Protocol (ICMP) ping time and the Active Directory Service Interfaces (ADSI) bind time.

Active Directory Domain Controller Disk Space Summarizes log file size and other disk space information for the specified domain controller.

Active Directory Domain Controller Memory Capacity Planning by Day Graphs the memory capacity for each specified domain controller during the specified time period, sorted by day.

Active Directory Domain Controller Memory Capacity Planning by Peak Hours Graphs the memory capacity for each specified domain controller during the specified time period, sorted by peak hours.

Active Directory Domain Controller Processor Capacity Planning by Day Provides a graph of the processor capacity for each specified Active Directory domain controller during the specified time period, sorted by day.

Active Directory Domain Controller Processor Capacity Planning by Peak Hours Provides a graph of the processor capacity for each specified Active Directory domain controller during the specified time period, sorted by peak hours.

Active Directory General Health Displays a summary table of counters that indicate general Active Directory health, followed by a graph for each server that displays trending data for the counters in the summary table. The summary table shows the average for each counter over the reporting period.

Active Directory Global Catalog Search Time Graphs the time it takes to search the global catalog, based on the MCSActiveDirectory-Global Catalog Search Time performance counter.

Active Directory LDAP Performance Displays a summary table of counters specific to LDAP, followed by a graph for each server that displays trending data for the counters in the summary table. The summary table shows the average for each counter over the reporting period.

Active Directory LSASS Performance Displays a summary table of counters specific to Local Security Authentication Server (LSASS), followed by a graph for each server that displays the trending data for the counters in the summary table. The summary table shows the average for each counter over the reporting period. Note that the %Processor Time for the LSASS process is not normalized. To determine the actual % Processor Time for the LSASS process, you must divide by the number of processors in the machine.

Active Directory Operations Masters Connection Time Graphs the ping time and bind time to Operations Masters from a specified domain controller. The graph displays the following ActiveDirectory performance counters:

  • MCSActiveDirectory-MCSActiveDirectory - Domain Naming Last Bind (seconds)

  • MCSActiveDirectory-Op Master PDC Last Bind (Seconds)

  • MCSActiveDirectory-Op Master Schema Last Bind (Seconds)

  • MCSActiveDirectory-Op Master Infrastructure Last Ping (Seconds)

  • MCSActiveDirectory-Op Master RID Last Ping (Seconds)

  • MCSActiveDirectory-Op Master Infrastructure Last Bind (Seconds)

  • MCSActiveDirectory-Op Master RID Last Bind (Seconds)

  • MCSActiveDirectory-Op Master Domain Naming Last Ping (Seconds)

  • MCSActiveDirectory-Op Master PDC Last Ping (Seconds)

  • MCSActiveDirectory-Op Master Schema Last Ping (Seconds)

Active Directory Response Time Graphs the responsiveness of Active Directory from selected domain controllers. The graph displays the following ActiveDirectory performance counters:

  • MCSActiveDirectory-Active Directory Average Bind (Seconds)

  • MCSActiveDirectory-Active Directory Last Bind (Seconds)

Active Directory Reponse Time by Peak Hours Graphs the response times for each specified domain controller during the specified time period, displayed by peak hours and based on the MCSActiveDirectory - Active Directory Last Bind performance counter. The graph indicates the daily minimum, maximum, and average response times, based from 7:00 A.M. to 7:00 P.M.

DNS Server Memory Capacity Planning by Day Graphs the memory capacity for each specified Domain Name System (DNS) server during the specified time period, sorted by day. The graph indicates the minimum, maximum, and average daily usage based on the Memory/Pages Per Second performance counter.

DNS Server Memory Capacity Planning by Peak Hours Graphs the memory capacity for each specified DNS server during the specified time period, sorted by peak hours. The graph indicates the minimum, maximum, and average daily usage based on the Memory/Pages Per Second performance counter.

DNS Server Processor Capacity Planning by Day Graphs the processor capacity for each specified DNS server during the specified time period, sorted by peak hours. The graph indicates the minimum, maximum, and average daily usage based on the Processor/% Processor Time performance counter.

DNS Server Processor Capacity Planning by Peak Hours Graphs the processor capacity for each specified DNS server during the specified time period, sorted by day. The graph indicates the minimum, maximum, and average daily usage based on the Processor/% Processor Time performance counter.

AD Client Side Events Displays all events from the AD Client Side Monitoring pack.

AD Domain Changes Displays events that are relevant to changes in the domain.

AD Duplicate Accounts Indicates accounts that are identified as duplicates by Active Directory, usually due to a duplicate Service Principle Name (SPN).

AD Machine Account Authentication Failures Provides machine account authentication failure events.

AD Machine Account Authentication Failures by Repeat Count Provides machine account authentication failure events, ordered by repeat count.

AD SAM Account Changes Displays events that are relevant to Security Accounts Manager (SAM) account changes in the domain.

AD Services Availability Summarizes the percentage of time each Active Directory service was available during the specified period of time. If you do not specify a period of time, MOM Reporting calculates the percentage of time that each service was available since the first service availability event was received. The report includes the following services:

  • Kerberos Key Distribution Center

  • Security Accounts Manager

  • Net Logon

AD Time Service Displays events generated by the W32Time service during the specified period. Events are ordered by server and then by LastEventTime, so the most recent events are displayed at the top of each server section.

DNS Server Availability Summarizes the availability of DNS servers.

DNS Service Availability Summarizes the percentage of time the DNS Server service was available during the specified period of time. If you do not specify a period of time, MOM Reporting calculates the percentage of time each service was available since the first service availability event was received.

Active Directory Inbound Replication Bandwidth Usage Summarizes the total amount of inbound replication bandwidth used by replication by server to each partner. The graph displays the following performance counters for the directory replication agent (DRA):

  • DRA Inbound Bytes Total (Seconds)

  • DRA Inbound Bytes Compressed (Between Sites/Before Compression (Seconds)

  • DRA Inbound Bytes Not Compressed (Within Site) (Seconds)

  • DRA Inbound Bytes Compressed (Between Sites/After Compression) (Seconds)

Active Directory Outbound Replication Bandwidth Usage Summarizes the total amount of outbound replication bandwidth used by replication by server to each partner. The graph displays the following performance counters:

  • DRA Outbound Bytes Total (Seconds)

  • DRA Outbound Bytes Compressed (Between Sites/Before Compression (Seconds)

  • DRA Outbound Bytes Not Compressed (Within Site) (Seconds)

  • DRA Outbound Bytes Compressed (Between Sites/After Compression) (Seconds)

Active Directory Replication Collisions Summarizes replication collision events and provides information from the event. The report includes the following events from the directory service event log:

  • 1233—Object replaced by object with same version number but different timestamp

  • 1546—Conflict while replicating schema object

  • 1547—Conflict while replicating in schema object

Active Directory Replication Failures Summarizes information about replication failures using event log information. The report includes the following events from the directory service event log:

  • 1014—Replication topology update task terminated abnormally

  • 1075—DRA failed while assembling a replication update request message for another site

  • 1077—Replication error: Couldn't allocate memory

  • 1084—DRA couldn't update object

  • 1096—Directory replication agent (DRA) received a badly formatted update-replica message during intersite replication

  • 1098—DRA received invalid update-replica message

  • 1100—DRA received invalid update-replica message

  • 1222—Certificate for intersite replication rejected

  • 1223—Certificate for intersite replication was rejected

  • 1274—Directory service failed to replicate partition from remote server

  • 1308—Successive replication attempts failed

  • 1425—Directory service was unable to force a replication cycle with the RID FSMO computer

  • 1455—Directory service failed to find server to replicate off changes

  • 1457—Failed replication of local changes

  • 1531—DRA encountered failure receiving message during intersite replication

  • 1532—Failure sending message during intersite replication

AD Replication Monitoring Provides service level agreement (SLA) data for replication latency between specific domain controllers (depends on data collected from domain controllers in the Active Directory Replication Latency Data Collection computer group).

Internet Information Server (IIS) reports

These reports cover operation-related events and performance counters.

IIS Access Summary Provides a summary of the access events occurring on the specified IIS servers, including access events from the IIS log files.

IIS Events by Selected Client IP Address Provides a list of HTTP and FTP events generated from the specified IP addresses, including all events from the IIS log files.

IIS Events by Selected Client IP Address Summary Summarizes HTTP and FTP events generated from the specified IP addresses, including all events from the IIS log files.

IIS Disk Performance Analysis Provides a graph of several IIS disk performance counters for the specified server during the specified time period. Performance counter data is averaged by the hour. The graph displays the following disk performance counters:

  • NBT Connection / Bytes Total Per Second (IIS 4.0; Scale=KB)

  • PhysicalDisk / % Disk Time (Scale=1)

  • Processor / % Total Processor Time (Scale=1)

  • Counters [Processor-% Processor Time (Scale = 1)] and [PhysicalDisk-% Disk Time (Scale = 1)] are plotted on primary y-axis. Counter [NBT Connection-Bytes Total/sec (Scale = MB)] is plotted on secondary y-axis.

IIS Error Rate Performance Analysis Graphs several IIS error rate performance counters for the specified server during the specified time period, averaged by the hour. The graph displays the following performance counters:

  • Web Service / Not Found Errors Per Second (Scale=1)

  • Active Server Pages / Errors Per Second (Scale=1)

IIS FTP Service Connection Performance Analysis Provides a graph of several FTP service performance counters for the specified server during the specified time interval for all FTP service connection instances. Data for FTP service connection performance is sampled at 15-minute intervals and averaged by the hour. If FTP connections are short-lived, data about those connections may not be collected in this report.

If you need to view data for short-lived FTP service connections, you must reduce the sampling interval for the performance counters in the following list.

To modify the sampling interval

  1. In the left pane of the MOM Administrator console, expand Rules, Processing Rule Groups, Microsoft Internet Information Services (IIS), IIS, and then Reporting Rules for IIS.

  2. Right-click Performance Processing Rules, and click Sample Performance Data.

  3. Select the applicable data provider, click Modify, and then reduce the sampling interval as needed. Repeat this procedure for each counter.

    Reducing the sampling interval affects performance, so you should consider your specific monitoring requirements and then evaluate this change.

    The report graph displays the following performance counters.

    • FTP Service / Current Anonymous Users (Scale=1)

    • FTP Service / Current Connections (Scale=1)

    • FTP Service / Current NonAnonymous Users (Scale=1)

IIS Memory Performance Analysis Provides a graph of several memory performance counters for the specified server during the specified time period. Memory performance counter data is averaged by the hour. The graph displays the following memory performance counters:

  • Memory / Available Bytes (Scale=MB)

  • Memory / Page Faults Per Second (Scale=1/10)

  • Memory / Page Reads Per Second (Scale=1)

  • Internet Information Services Global / Cache Hits % (IIS 5.0; Scale=1)

  • Internet Information Services Global / Cache Flushes (IIS 5.0; Scale=1)

  • Internet Information Services Global / File Cache Hits % (IIS 4.0; Scale=1/10)

  • Internet Information Services Global / File Cache Flushes (IIS 4.0; Scale=1/10)

  • Counters [Memory-Available Bytes (Scale = MB)], [Memory-Page Faults/sec (Scale = 1/10)], [Memory-Page Reads/sec (Scale = 1)], and [IIS Global-Cache Hits % (Scale = 1)] are plotted on primary y-axis. Counter [IIS Global-Cache Flushes (Scale = 1/10)] is plotted on secondary y-axis.

IIS Network Performance Analysis Provides a graph of several IIS network performance counters for the specified server during the specified time period. Network performance counter data is averaged by the hour. The graph displays the following network performance counters:

  • NBT Connection / Bytes Total Per Second (Scale=KB)

  • Web Service / Maximum Connections (Scale=1)

  • Web Service / Total Connection Attempts, all instances (Scale=1)

Counters NBT Connection-Bytes Total/sec and Web Service-Maximum Connections are plotted on the primary y-axis, and counter Web Service-Total Connection Attempts is plotted on the secondary y-axis.

This report helps you determine whether the network, disk or processor is acting as a bottleneck for your server. You should determine the bottleneck by determining which resource is near saturation.

If the NBT Connection-Bytes Total/sec is close to the bandwidth of your network adapter and the other two performance counters are moderate, the network connection might be a bottleneck.

If the % Disk time performance counter is at saturation and the other two counters are moderate, the disk might be a bottleneck for your server.

IIS NNTP Server Connection Performance Analysis Provides a graph of several performance counters for the specified server during the specified time period for all Network News Transfer Protocol (NNTP) server connection instances. Performance counter data is averaged by the hour. The graph displays the following NNTP server connection performance counters:

  • NNTP Service / Current Anonymous Users (Scale=1)

  • NNTP Service / Current Connections (Scale=1)

  • NNTP Service / Current NonAnonymous Users (Scale=1)

IIS Web Service Connection Performance Analysis Graphs several performance counters for the specified server during the specified time period, averaged by the hour. The graph displays the following Web Service connection performance counters:

  • Web Service / Current Anonymous Users, Instance _Total (Scale=1)

  • Web Service / Current Connections, Instance _Total (Scale=1)

  • Web Service / Current NonAnonymous Users, Instance _Total (Scale=1)

MOM reports

These reports summarize events, alerts, operations and licenses.

Alert Logging Latency Presents logging latency for alerts logged in the specified time period. Alert logging latency is the delay between the time an alert is raised by a computer and the time it is logged to the MOM database. The report lists average, maximum, and minimum for alert logging latencies per computer, starting with the highest average value.

Alert Resolution Times Provides the average delay in resolving alerts, categorized by alert severity and resolution state. The report lists average time alerts spend in different resolution states during the specified time period. Resolution delays are categorized by alert severity and resolution state. For each severity level, the total number of new and resolved alerts during the specified time period is also included in the report.

Alerts by Severity Provides a graph of alerts raised during the specified time period categorized by alert severity level.

Configuration Changes by Table Summarizes the changes made to processing rules or the configuration group, sorted by table. MOM logs these changes in the database. These reports are generated only when you have enabled Data Access Server (DAS) auditing. DAS auditing is CPU-intensive and stores a considerable amount of data in the database. By default, auditing is disabled. You can enable auditing in the Configuration Properties dialog box.

Configuration Changes by Time Summarizes the changes made to processing rules or the configuration group, sorted by time. MOM logs these changes in the database. These reports are generated only when you have enabled DAS auditing. DAS auditing is CPU-intensive and stores a considerable amount of data in the database. By default, auditing is disabled. You can enable auditing in the Configuration Properties dialog box.

Configuration Changes by User Summarizes the changes made to processing rules or the configuration group, sorted by user. MOM logs these changes in the database. These reports are only generated when you have enabled DAS auditing. DAS auditing is CPU-intensive and stores a considerable amount of data in the database. By default, auditing is disabled. You can enable auditing in the Configuration Properties dialog box.

Event Count by Agent by Day Provides a list of the events handled by MOM, sorted by agent and date. The report displays the most frequent alerts in each group, in descending order of frequency.

Event Logging Latency Presents logging latency for events logged in the specified time period. The report lists average, maximum and minimum for event logging latencies per computer, starting with the highest average value. For each severity level, the total number of new and resolved alerts during the specified time period is also included in the report.

Install and Uninstall Approvals Summarizes the pending agent installation and removal actions that were logged during a specified period of time. These reports are only generated when you have enabled DAS auditing. DAS auditing is CPU-intensive and stores a considerable amount of data in the database. By default, auditing is disabled. You can enable auditing in the Configuration Properties dialog box.

Most Common Alerts Lists the most common alerts, sorted by computer group, processing rule group, or alert count. The report displays the most frequent alerts in each group, in descending order of frequency.

Management Pack Licenses Required Summarizes the total number of Base and Application Management Pack Licenses required. The total number of Base and Application Management Pack licenses required is given at the end of the list of computers. The number of Base Management Pack licenses required is the total number of processors present in the computers that have the MOM agent installed. The number of Application Management Pack licenses required is the number of processors that require Application Management Pack and have the MOM agent installed.

Most Common Alerts by Alert Count Displays a list of the most common alerts, sorted by alert count, in descending order of frequency. Use this report to identify alerts that occur too frequently, or alerts for which automated responses may be appropriate.

Most Common Alerts by Computer Group Displays a list of the most common alerts, sorted by computer group, in descending order of frequency. Use this report to identify alerts that occur too frequently, or alerts for which automated responses may be appropriate.

Most Common Alerts by Processing Rule Group Displays a list of the most common alerts, sorted by processing rule group, in descending order of frequency. Use this report to identify alerts that occur too frequently, or alerts for which automated responses may be appropriate.

Most Common Events Lists the top 25 percent of the most common events, based on and sorted by the event count, with the event that occurred most often listed first.

Total Monitored Computers Lists all computers scanned in this configuration group, the type of computer, and whether an agent is installed.

Remote Access reports

These reports summarize Remote Access connection information.

Remote Access Connections by User Lists remote connections, including RAS connection events (20048—Windows 2000; 20050—Windows NT) from the system event log with the Remote Access source. The report is sorted by user account name, with the most recent event listed first.

Windows 2000 reports

These report cover processor, memory and disk performance; network activities, such as connections and spooled jobs; and availability and capacity planning.

Disk Queue Length by Day Graphs the disk queue length for each specified server during the specified time period, sorted by day. The graph indicates the minimum, maximum, and average daily usage based on the PhysicalDisk / Average Disk Queue Length performance counter. This report provides one graph for each specified server.

Disk Queue Length by Peak Hours Graphs the disk queue length for each specified server during the specified time period, sorted by peak hours. The graph indicates the minimum, maximum, and average daily usage based on the PhysicalDisk / Average Disk Queue Length performance counter. This report provides one graph for each specified server.

Disk Space Capacity Planning Graphs the disk space capacity for each specified server during the specified time period. The graph indicates the minimum, maximum, and average daily usage based on the LogicalDisk / % Free Space performance counter. This report provides one graph for each specified server.

Memory Capacity Planning by Day Graphs the minimum, maximum, and average daily usage of memory capacity, during the specified time period, and sorted by day. It is based on the Memory / Pages Per Second performance counter. This report provides one graph for each specified server.

Memory Capacity Planning by Peak Hours Graphs the minimum, maximum, and average daily usage of memory capacity, during the specified time period, and sorted by day. It is based on the Memory / Pages Per Second performance counter. This report provides one graph for each specified server.

Processor Capacity Planning by Day Graphs the processor capacity for each specified server during the specified time period, sorted by day. This report provides a graph of the processor capacity for each specified server during the specified time period. The graph indicates minimum, maximum, and average daily usage. For computers running Windows NT, the performance counter is System / % Total Processor Time. For computers running Windows 2000, the performance counter is Processor / Processor Time Instance_Total. This report provides one graph for each specified server.

Processor Capacity Planning by Peak Hours Graphs the processor capacity for each specified server during the specified time period, sorted by peak hours. This report provides a graph of the processor capacity for each specified server during the specified time period. The graph indicates minimum, maximum, and average daily usage. For computers running Windows NT, the performance counter is System / % Total Processor Time. For computers running Windows 2000, the performance counter is Processor / Processor Time Instance Total. This report provides one graph for each specified server.

Server Capacity Planning by Day Graphs the server capacity for each specified server during the specified time period, sorted by day. This report provides a graph of the server capacity for each specified server during the specified time period. The graph indicates the minimum, maximum, and average daily usage based on the Server + Redirector / Bytes Total Per Second performance counter. This report provides one graph for each specified server.

Server Capacity Planning by Peak Hours Graphs the server capacity for each specified server during the specified time period, sorted by peak hours. This report provides a graph of the server capacity for each specified server during the specified time period. The graph indicates the minimum, maximum, and average daily usage based on the Server + Redirector / Bytes Total Per Second performance counter. This report provides one graph for each specified server.

Application Log Summary Provides a summary count of the events from the application event log, sorted by the system that logged the event, and the event type and number.

Application Log Trend by Day Graphs the application log trend for each specified server during the specified time period.

Computer Availability by Computer Group Summarizes the percentage of time each computer was available during the specified period of time, sorted by computer group.

Computer Availability by Server Summarizes the percentage of time each computer was available during the specified period of time, sorted by server.

Logon Failure Events Lists logon failure events. The report includes the following events from the security event log:

  • 529—Unknown user name or bad password

  • 530—Account logon time restriction violation

  • 531—Account currently disabled

  • 532—The specified user account has expired

  • 533—User not allowed to log on at this computer

  • 534—The user has not been granted the requested logon type at this machine

  • 535—The password for the specified account has expired

  • 536—The NetLogon component is not active

  • 537—An unexpected error occurred during logon

  • 539—Account locked out

  • 548—Domain security ID inconsistent

Network Connections to Other Computers Lists network connections to other computers, sorted by user account name and logon event, with the most recent logon event listed first. The report includes the following events from the security event log with the Kerberos or NTLM Security Service Provider (NTLMSSP) logon process:

  • 540—Successful Logon

  • 540—Successful Logoff

PDC-BDC Full Synchronizations by Server Summarizes full synchronizations from the primary domain controller (PDC) to the backup domain controller (BDC) during the time specified, sorted by PDC name, and by the BDC name and date. The report includes the full synchronization events (5713) from the system event log with the NetLogon source.

PDC-BDC Partial Synchronizations by Server Summarizes partial synchronizations from the PDC to the BDC during the time specified, sorted by PDC name, and by the BDC name and date. The report includes the partial synchronization events (5715) from the system event log with the NetLogon source.

Security Log Summary Summarizes counts of the events from the security event log, sorted by the system that logged the event, and the event type and number.

Security Log Trend by Day Graphs the security log trend for each specified server during a specified time period, indicating the number of unfiltered events generated from the security event log.

Server Restarts by Day Summarizes server restarts for the servers, dates, and times specified, including the 512 - Windows NT is starting up events, from the security event log.

Service Availability by Computer Group Summarizes the percentage of time each service was available during the specified period of time, sorted by computer group. If you do not specify a period of time, MOM Reporting calculates the percentage of time each service was available since the first service availability event was received.

Service Availability by Server Summarizes the percentage of time each service was available during the specified period of time, sorted by server. If you do not specify a period of time, MOM Reporting calculates the percentage of time each service was available since the first service availability event was received.

Service Availability by Service Summarizes the percentage of time each service was available during the specified period of time, sorted by service. If you do not specify a period of time, MOM Reporting calculates the percentage of time each service was available since the first service availability event was received.

Spooled Jobs by Page Count Lists spooled print jobs, sorted by page count. The report includes the print job events from the system event log.

Spooled Jobs by Printer Lists spooled print jobs, sorted by printer. The report includes the print job events from the system event log.

Spooled Jobs by User Lists spooled print jobs, sorted by user. The report includes the print job events from the system event log.

System Clean Shutdown Events Lists the system clean shutdown events, including the 6006—The Event log service was stopped events, from the system event log.

System Dirty Shutdown Events Lists the system dirty shutdown events, including the 6008—The previous system shutdown was unexpected events, from the system event log.

System Log Summary Summarizes counts of the events from the system event log, sorted by the system that logged the event, and the event type and number.

System Log Trend by Day Graphs the system log trend for each specified server during the specified time period. The graph indicates the number of unfiltered events generated from the system event log.

System Shutdown Events Lists the system shutdown events, including 6006 —The Event log service was stopped and 6008 —The previous system shutdown was unexpected, from the system event log.

User Account Changes Lists all User Account Management events logged during the specified time period, grouped by the server where the event is generated and sorted by time. The report includes the following events from the security event log:

  • 624—User account created

  • 627—Change password attempt

  • 628—User account password set

  • 630—User account deleted

  • 642—User account changed, including user account enabled/disabled changes

CPU Performance Analysis Graphs several CPU performance counters for the specified server during the specified time period, averaged by the hour. The graph displays the following memory performance counters:

  • Processor / % Processor Time (Windows 2000; Scale=1)

  • Processor / % User Time (Windows 2000; Scale=1)

  • Processor / % Privileged Time (Windows 2000; Scale=1)

  • System / % Total Processor Time (Windows NT; Scale=1)

  • System / % Total User Time (Windows NT; Scale=1)

  • System / % Total Privileged Time (Windows NT; Scale=1)

  • System / Context Switches Per Second (Scale=1/1000)

  • System / Processor Queue Length (Scale=10/1)

Disk Performance Analysis Graphs several disk performance counters for the specified server during the specified time period, averaged by the hour. The graph displays the following disk performance counters:

  • PhysicalDisk / Average Disk Queue Length (Scale=100/1)

  • PhysicalDisk / Average Disk Seconds Per Transfer (Scale=1000/1)

  • PhysicalDisk / Disk Reads Per Second (Scale=1)

  • PhysicalDisk / Disk Writes Per Second (Scale=1)

  • PhysicalDisk / Disk Bytes Per Second (Scale=1/10000)

Memory Performance Analysis Graphs several memory performance counters for the specified server during the specified time period, averaged by the hour. The graph displays the following memory performance counters:

  • Memory / Available Bytes (Scale=MB)

  • Memory / Committed Bytes (Scale=MB)

  • Memory / Pages Per Second (Scale=1)

  • Memory / Page Reads Per Second (Scale=1)

  • Memory / Page Writes Per Second (Scale=1)

  • Process / Page File Bytes (Scale=MB)

  • Counters [Memory-Available Bytes (Scale = MB)],[Memory-Committed Bytes (Scale = MB)],and [Process-Page File Bytes-_Total (Scale = MB)] are plotted on primary y-axis and counters. [Memory-Pages/sec (Scale = 1)],[Memory-Page Reads/sec (Scale = 1)],and [Memory-Page Writes/sec (Scale = 1)] are plotted on secondary y-axis.

Server Performance Analysis Graphs several server performance counters for the specified server during the specified time period, averaged by the hour. The graph displays the following server performance counters:

  • Server / Bytes Total Per Second (Scale=KB)

  • Server / Files Open (Scale=1)

  • Server / Server Sessions (Scale=1)

Top CPU Utilization Lists servers with highest average CPU utilization during the specified time period, measured by counter Processor: %Processor Time. The list is ordered by average value for counter, starting with the highest value. The servers with the highest CPU utilization are listed in the report, based on the selection criteria. By default, the top five percent of the servers with the highest CPU-utilization are listed.

Top Disk Utilization Lists servers with the highest average disk utilization during the specified time period, measured by percent non-idle disk time calculated as (100 - PhysicalDisk: %Idle Time). The list is ordered by values in column Avg (100-%Idle Time), starting with the highest value. The servers with the highest disk utilization are listed in the report, based on the selection criteria. By default, the top five percent of the servers with the highest disk utilization are listed.

Top Memory Utilization Lists servers with the highest average memory utilization during the specified time period, measured by counter: Memory: Page Reads/sec. The list is ordered by average value for counter, starting with the highest value. The servers with the highest memory utilization are listed in the report, based on the selection criteria. By default, the top five percent of the servers with the highest memory utilization are listed.

Windows Terminal Server reports

These reports cover total sessions, memory and processor usage, and service availability.

Windows Terminal Server Memory Usage Graphs several Windows Terminal Server performance counters for the specified server during the specified time period. For Windows 2000, the performance object is Terminal Services Session. For Windows NT, the performance object is Session. The graph displays the following performance counters:

  • Total Bytes (Scale=.01)

  • Input Bytes (Scale=.01)

  • Output Bytes (Scale=.01)

  • Page File Bytes (Scale=.000001)

  • Pool Nonpaged Bytes (Scale=.00001)

  • Pool Paged Bytes (Scale=.00001)

Windows Terminal Server Processor Usage Graphs the processor capacity for each specified server running Windows Terminal Server during the specified time period. The graph indicates the minimum, maximum, and average daily usage based on the Process / % Processor Time performance counter. The instance is termsrv.

Windows Terminal Server Service Availability Summarizes the percentage of time the Terminal Services service was available during the specified period of time. If you do not specify a period of time, MOM Reporting calculates the percentage of time the service was available since the first service availability event was received.

Windows Terminal Server Total Sessions Graphs the Windows Terminal Server session performance counters for the specified server during the specified time period. Reports are based on the Terminal Services-Active Sessions and Terminal Services-Inactive Sessions performance counters for Windows 2000 servers. For Windows NT, counters used are System-Active Sessions and System-Inactive Sessions.

MOM Reporting also provides reports for SQL Server and Microsoft Exchange Server, which are included with the Application Management Pack:

SQL Server reports

These reports include connections usage, operation-related event reports, and performance reports.
SQL Server Backup Device Capacity Planning Provides a graph of the daily usage of the SQL Server backup device. The graph indicates the minimum, maximum, and average backup device capacity based on the Backup Device / Device Throughput Bytes Per Second performance counter. This report provides one graph for each specified server. This report is available only for SQL Server 7.0.

SQL Server User Connections by Day Graphs the daily SQL Server user connections for the specified server during the specified time period, displayed by day. The graph indicates the minimum, maximum, and average user connections capacity based on the SQL Server / General Statistics - User Connections performance counter for SQL Server 7.0, or the SQL Server / User Connections performance counter for SQL Server 6.5. This report provides one graph for each specified server.

SQL Server User Connections by Peak Hours Graphs the daily SQL Server user connections for the specified server during the specified time period, displayed by peak hours. The graph indicates the minimum, maximum, and average user connections capacity based on the SQL Server / General Statistics - User Connections performance counter for SQL Server 7.0, or the SQL Server / User Connections performance counter for SQL Server 6.5. This report provides one graph for each specified server.

SQL Server Critical Events Lists critical events (Event Type = 'Error') for source MSSQLServer, that have occurred on the specified server in the specified time period. This report is sorted by server, alphabetically, and then by event time.

SQL Server Critical Events Trend by Day Provides a daily graph of all critical events (Event Type = 'Error') for source MSSQLServer, that have occurred on the specified server in the specified time period.

SQL Server Distribution Replication Performance Analysis Provides a graph of several SQL Server distribution replication performance counters for the specified server during the specified time period. Performance counter data is averaged by the hour. The graph displays the following replication performance counters:

  • SQLServer:Replication Dist. / Dist:Delivered Commands Per Second (Scale=1/100)

  • SQLServer:Replication Dist. / Dist:Delivered Transactions Per Second (Scale=1/100)

  • SQLServer:Replication Dist. / Dist:Delivery Latency (Scale=1/100)

This report is available only for SQL Server 2000.

SQL Server Lock Performance Analysis Provides graphs of SQL Server lock performance counters for specified servers during the specified time period. Performance counter data is averaged by the hour. The graph displays the following lock performance counters:

  • SQLServer:Locks / Number of Deadlocks Per Second (Scale=1)

  • SQLServer:Locks / Lock Requests Per Second (Scale=1/100)

  • SQLServer:Locks / Lock Waits Per Second (Scale=1/10)

The graph displays the following instance for each server/performance counter combination:

  • Database

  • Extend

  • Key

  • Page

  • Rid

  • Table

This report is available only for SQL Server 2000.

SQL Server Log Performance Analysis Provides a graph of SQL Server 2000 transaction log performance counters for the specified server during the specified time period, where the database instance is not Total, master, msdb, model, Northwind, or pubs. Performance counter data is averaged by the hour. This report provides one graph for each database instance.

  • For a SQL Server 2000 database, the graph displays the following log performance counters:

  • SQLServer:Databases / Log Flushes Per Second (Scale=1/100)

  • SQLServer:Databases / Log Flush Wait Time (Scale=1/100)

  • SQLServer:Databases / Log Flush Waits Per Second (Scale=1/1000)

SQL Server Logreader Replication Performance Analysis Provides a graph of several SQL Server logreader replication performance counters for the specified server during the specified time period. Performance counter data is averaged by the hour. The graph displays the following logreader replication performance counters:

  • SQLServer:Replication Logreader / Logreader:Delivered Commands Per Second (Scale=1\100)

  • SQLServer:Replication Logreader / Logreader:Delivered Transactions Per Second (Scale=1\100)

  • SQLServer:Replication Logreader / Logreader:Delivery Latency (Scale=1\1000)

This report is available only for SQL Server 2000.

SQL Server Memory Performance Analysis Graphs several SQL Server memory performance counters for the specified server during the specified time period. Performance counter data is averaged by the hour. The graph displays the following memory performance counters:

  • Process:Page Faults Per Second (sqlservr) (Scale=1/10)

  • Process:Private Bytes (sqlservr) (Scale=MB)

  • SQLServer:Memory Manager / Total Server Memory (SQL Server 7.0; Scale=KB)

  • SQLServer:Buffer Manager / Buffer Cache Hit Ratio (SQL Server 7.0; Scale=1)

  • SQLServer:Buffer Manager / Free Buffers (SQL Server 7.0; Scale=1/10)

  • SQLServer:Buffer Manager / Lazy Writes Per Second (SQL Server 7.0; Scale=1/10)

  • SQLServer:Buffer Manager / Readahead Pages Per Second (SQL Server 7.0; Scale=1/10)

  • SQLServer / Cache Hit Ratio (SQL Server 6.5; Scale=1)

  • SQLServer:Cache / Number of Free Buffers (SQL Server 6.5; Scale=1/10)

  • SQLServer:I/O / Lazy Writes Per Second (SQL Server 6.5; Scale=1/10)

  • SQLServer:RA / Pages Fetched into Cache per Second (SQL Server 6.5; Scale=1/10)

SQL Server Merge Replication Performance Analysis Provides a graph of several SQL Server merge replication performance counters for the specified server during the specified time period. Performance counter data is averaged by the hour. The graph displays the following merge replication performance counters:

  • SQLServer:Replication Merge / Conflicts Per Second (Scale=1\100)

  • SQLServer:Replication Merge / Downloaded Changes Per Second (Scale=1\100)

  • SQLServer:Replication Merge / Uploaded Changes Per Second (Scale=1\100)

This report is available only for SQL Server 2000.

SQL Server Overall Replication Performance Analysis Provides a graph of several SQL Server overall replication performance counters for the specified server during the specified time period. Performance counter data is averaged by the hour. The graph displays the following replication performance counters:

  • SQLServer:Databases / Replication Pending Xacts (SQL Server; Scale=1\100)

  • SQLServer:Databases / Replication Transaction Rate (SQL Server; Scale=1\100)

  • SQLServer Replication Published DB / Replicated Transactions Per Second

SQL Server Snapshot Replication Performance Analysis Provides a graph of several SQL Server snapshot replication counters for the specified server during the specified time period. Performance counter data is averaged by the hour. The graph displays the following snapshot replication performance counters:

  • SQLServer:Replication Snapshot / Snapshot:Delivered Commands Per Second (Scale=1\100)

  • SQLServer:Replication Snapshot / Snapshot:Delivered Transactions Per Second (Scale=1\100)

This report is available only for SQL Server 2000.

Exchange Server 2000 reports

These reports include server resource usage, mailbox and folder configuration information and sizes, common operation events, performance counters, and mail traffic patterns.

Database Sizes Lists database sizes for Exchange Server 2000 servers. Database size (in MB) is listed for each server, storage group, and database.

Disk Usage Provides disk usage information for Exchange Server 2000 servers, based on various disk performance counters. Daily averages for each counter are listed. Highest average in a half-hour period for each of the counters is also included, in addition to the time the highest average occurred.

Mailboxes Lists distribution of mailboxes across storage groups and databases for Exchange Server 2000 servers. The number of mailboxes and maximum limit for mailboxes is listed for each server, storage group, and database.

Server Availability Summarizes the percentage of server availability for Exchange Server 2000 servers during the specified time period. The percentage of availability and unavailability are listed in addition to the reasons for unavailability.

Server Configuration Provides Exchange Server 2000 server configuration information, including computer and operating systems configuration, local disks information, Windows Hotfix application history, Exchange Server 2000 server and storage group configuration.

IMAP4 Usage Summarizes the Internet Message Access Protocol 4 (IMAP4) usage rates, based on key performance counters. The report shows daily total and averages for designated IMAP4 performance counters for the specified time period. The highest average for each counter in a half-hour period and the time period for the highest average are also included.

Information Store Usage Summarizes internal Remote Procedure Call (RPC) operations against the Information Store by using key performance counters. The report lists daily totals and averages for the designated information store performance counters during the specified time period. The highest average for each counter in a half-hour period and the time period for the highest average are also included.

Mailbox Store Usage Summarizes rates of operations in the Mailbox Store based on key performance counters. The report shows daily totals and averages for designated Mailbox Store performance counters during the specified time period. The highest average for each counter in a half-hour period and the time period for the highest average are also included.

MTA Usage Summarizes rates of operations in the Message Transfer Agent (MTA) based on key performance counters. The report shows daily totals and averages for designated MTA performance counters during the specified time period. The highest average for each counter in a half-hour period and the time period for the highest average are also included.

POP3 Usage Summarizes rates of Post Office Protocol 3 (POP3) client usage and activity based on key performance counters. The report shows daily totals and averages for designated POP3 performance counters during the specified time period. The highest average for each counter in a half-hour period and the time period for the highest average are also included.

Public Store Usage Summarizes rates of operations in the Public Store based on key performance counters. The report shows daily totals and averages for designated public store performance counters during the specified time period. The highest average for each counter in a half-hour period and the time period for the highest average are also included.

SMTP Usage Summarizes rates of Simple Mail Transfer Protocol (SMTP) activity based on key performance counters, providing information about mail flow through your organization. The report shows daily totals and averages for designated SMTP performance counters for the specified time period. The highest average for each counter in a half-hour period and the time period for the highest average are also included.

Web Mail Usage Summarizes rates of Web Mail or Outlook Web Access (OWA) client usage and activity based on key performance counters. The report shows daily totals and averages for designated Web Mail performance counters during the specified time period. The highest average for each counter in a half-hour period and the time period for the highest average are also included.

Mail Delivered - Top 100 Recipient Mailboxes by Count Lists the top 100 mail recipients sorted by message count during a specified period of time, as reported in the Exchange message tracking logs.

Mail Delivered - Top 100 Recipient Mailboxes by Size Lists the top 100 mail recipients sorted by message size during a specified period of time, as reported in the Exchange message tracking logs.

Mail Delivered - Top 100 Sender Domains by Count Lists the top 100 sender domains sorted by message count during a specified period of time, as reported in the Exchange message tracking logs.

Mail Delivered - Top 100 Sender Domains by Size Lists the top 100 sender domains sorted by message size during a specified period of time, as reported in the Exchange message tracking logs.

SMTP OUT-Top 100 Recipient Domains by Count Lists the top 100 SMTP Out recipients sorted by message count during a specified period of time, as reported in the Exchange message tracking logs. SMTP Out recipients are identified by the domain of the Internet address to which e-mail is sent from Exchange.

SMTP OUT-Top 100 Recipient Domains by Size Lists the top 100 SMTP Out recipients sorted by message size during a specified period of time, as reported in the Exchange message tracking logs. SMTP Out recipients are identified by the domain of the Internet address to which e-mail is sent from Exchange.

SMTP OUT-Top 100 Senders by Count Lists the top 100 SMTP Out senders sorted by message count during a specified period of time, as reported in the Exchange message tracking logs. SMTP Out senders are Exchange mailboxes that have sent e-mail to an Internet address.

SMTP OUT-Top 100 Senders by Size Lists the top 100 SMTP Out senders sorted by message size during a specified period of time, as reported in the Exchange message tracking logs. SMTP Out senders are Exchange mailboxes that have sent e-mail to an Internet address.

Exchange Server 5.5 Reports

These reports include server resource usage, mailbox and folder configuration information and sizes, common operation events, performance counters, and mail traffic patterns.
Average Time for Delivery by Day Graphs the time for delivery for each specified server during the specified time period. The graph indicates the minimum, maximum, and average time for delivery based on the MSExchangeIS Public/Average Time for Delivery performance counter. This report provides one graph for each specified server.

Average Time for Local Delivery by Day Graphs the time for local delivery for each specified server during the specified time period. The graph indicates the minimum, maximum, and average time for local delivery based on the MSExchangeIS Public/Average Time for Local Delivery performance counter.

IMC Queue Lengths Graphs the interactions between Exchange and Internet Mail Connector (IMC) for the specified server during the specified time period. Performance counter data is averaged by the hour. The graph displays the following performance counters:

  • MSExchangeIMC / Queued MTS-IN (Scale=1)

  • MSExchangeIMC / Queued MTS-OUT (Scale=1)

  • MSExchangeIMC / Queued Outbound (Scale=1)

  • MSExchangeIMC / Queued Inbound (Scale=1)

Internet Mail by Day Graphs Internet mail usage for each specified server during the specified time period. The graph indicates the number of inbound and outbound SMTP events. These numbers are based on the following events from the application log:

  • 2000—A new TCP/IP SMTP connection has been received from host

  • 2003—A new TCP/IP SMTP connection has been made to the host

Internet News by Day Provides a graph of inbound newsgroup messages for each specified server during the specified time period. The graph indicates the number of inbound SMTP events. These numbers are based on the following events from the application log:

  • 11606—News article was pulled to this server and successfully posted to the following newsgroups

  • 11609—News article was pulled to this server and successfully posted to the following newsgroups

Pending Replication Synchronizations by Day Graphs the pending replication synchronizations for each specified server during the specified time period. The graph indicates the minimum, maximum, and average pending replication synchronizations based on the MSExchangeDS/Pending Replication Synchronizations performance counter.

Remaining Replication Updates by Day Graphs the remaining replication updates for each specified server during the specified time period. The graph indicates the minimum, maximum, and average remaining replication updates based on the MSExchangeDS/Remaining Replication Updates performance counter.

Top 100 Exchange Recipients by Message Count Lists the top 100 Exchange recipients during a specified period of time, as reported in the Exchange Message Transfer Agent (MTA) log, sorted by message count. Exchange recipients are mailboxes on this server receiving non-SMTP e-mails.

Top 100 Exchange Recipients by Size Lists the top 100 Exchange recipients during a specified period of time, as reported in the MTA log, sorted by size. Exchange recipients are mailboxes on this server receiving non-SMTP e-mails.

Top 100 Exchange Senders by Message Count Lists the top 100 Exchange senders during a specified period of time, as reported in the MTA log, sorted by message count. Exchange senders are mailboxes on this Exchange server that have sent non-SMTP e-mail.

Top 100 Exchange Senders by Size Lists the top 100 Exchange senders during a specified period of time, as reported in the MTA log, sorted by size. Exchange senders are mailboxes on this Exchange server that have sent non-SMTP e-mail.

Top 100 SMTP In Recipients by Message Count Lists the top 100 SMTP In recipients during a specified period of time, as reported in the MTA log, sorted by message count. SMTP In recipients are Exchange mailboxes that receive SMTP e-mail from the Internet.

Top 100 SMTP In Recipients by Size Lists the top 100 SMTP In recipients during a specified period of time, as reported in the MTA log, sorted by size. SMTP In recipients are Exchange mailboxes that receive SMTP e-mail from the Internet.

Top 100 SMTP In Senders by Message Count Lists the top 100 SMTP In senders during a specified period of time, as reported in the MTA log, sorted by message count. SMTP In senders are Internet domains from which Exchange users receive SMTP e-mail.

Top 100 SMTP In Senders by Size Lists the top 100 SMTP In senders during a specified period of time, as reported in the MTA log, sorted size. SMTP In senders are Internet domains from which Exchange users receive SMTP e-mail.

Top 100 SMTP Out Recipients by Message Count Lists the top 100 SMTP Out recipients during a specified period of time, as reported in the MTA log, sorted by message count. SMTP Out recipients are identified by the domain of the Internet address to which e-mail is sent from Exchange.

Top 100 SMTP Out Recipients by Size Lists the top 100 SMTP Out recipients during a specified period of time, as reported in the MTA log, sorted by size. SMTP Out recipients are identified by the domain of the Internet address to which e-mail is sent from Exchange.

Top 100 SMTP Out Senders by Message Count Lists the top 100 SMTP Out senders during a specified period of time, as reported in the MTA log, sorted by message count. SMTP Out senders are Exchange mailboxes that have sent e-mail to an Internet address.

Top 100 SMTP Out Senders by Size Lists the top 100 SMTP Out senders during a specified period of time, as reported in the MTA log, sorted by size. SMTP Out senders are Exchange mailboxes that have sent e-mail to an Internet address.

Active Client Logons by Day Provides a graph of the active client logons for each specified server during the specified time period. The graph indicates the minimum, maximum, and average active client logons based on the MSExchangeIS Public/Active Client Logons performance counter. This report provides one graph for each specified server.

Client Logons by Day Graphs the client logons for each specified server during the specified time period. The graph indicates the minimum, maximum, and average active client logons based on the MSExchangeIS Public/Client Logons performance counter. This report provides one graph for each specified server.

Message Recipients Delivered per Minute by Day Provides a graph of the message recipients delivered per minute for each specified server during the specified time period. The graph indicates the minimum, maximum, and average number of message recipients delivered per minute based on the MSExchangeIS Public/Message Recipients Delivered/min performance counter. This report provides one graph for each specified server.

Messages Sent per Minute by Day Graphs the message recipients delivered per minute for each specified server during the specified time period. The graph indicates the minimum, maximum, and average number of message recipients delivered per minute based on the MSExchangeIS Public/Message Recipients Delivered/min performance counter. This report provides one graph for each specified server.

MTA Messages per Second by Day Graphs the MTA messages per second for each specified server during the specified time period. The graph indicates the minimum, maximum, and average number of MTA messages per second based on the MSExchangeMTA/Messages/Sec performance counter. This report provides one graph for each specified server.

MTA Work Queue Length by Day Graphs of the MTA work queue length for each specified server during the specified time period. The graph indicates the minimum, maximum, and average MTA work queue length based on the MSExchangeMTA/Work Queue Length performance counter. This report provides one graph for each specified server.

Highest Growth Mailboxes Summarizes the Exchange mailboxes with the most growth during the specified period of time. Two days of data must be available for the report to display growth statistics.

Highest Growth Public Folders Summarizes the Exchange public folders with the most growth during the specified period of time. Two days of data must be available for the report to display growth statistics.

Top 100 Mailboxes by Message Count Lists the top 100 mailboxes during a specified period of time, sorted by message count.

Top 100 Mailboxes by Size Lists the top 100 mailboxes during a specified period of time, sorted by size.

Top 100 Public Folders by Message Count Lists the top 100 public folders during a specified period of time, sorted by message count.

Top 100 Public Folders by Size Lists the top 100 public folders during a specified period of time, sorted by size.

© 2009 Microsoft Corporation. All rights reserved. Terms of Use | Trademarks | Privacy Statement
Page view tracker