{
  "checks": [
    {
      "name": "DFSR Service",
      "auto_add": true,
      "check_mode": "agent",
      "check_type": "agent_service",
      "parameters": {
        "service": "DFSR"
      },
      "sort_order": 0,
      "value_type": "status",
      "description": "",
      "check_config": {
        "service": "DFSR"
      },
      "is_telemetry": false,
      "interpretation": null,
      "threshold_crit": null,
      "threshold_warn": null,
      "interval_seconds": 120,
      "threshold_direction": "upper",
      "confirmation_attempts": 1,
      "confirmation_interval_seconds": 10
    },
    {
      "name": "DFS Event 4612",
      "auto_add": true,
      "check_mode": "agent",
      "check_type": "agent_script",
      "parameters": {
        "script_id": "07c86fb5-6deb-5ef2-9c94-b70436779b02"
      },
      "sort_order": 1,
      "value_type": "gauge",
      "description": "",
      "check_config": {
        "script_id": "07c86fb5-6deb-5ef2-9c94-b70436779b02"
      },
      "is_telemetry": false,
      "interpretation": null,
      "threshold_crit": null,
      "threshold_warn": null,
      "interval_seconds": 600,
      "threshold_direction": "upper",
      "confirmation_attempts": 1,
      "confirmation_interval_seconds": 10
    },
    {
      "name": "DFS Event 2004",
      "auto_add": true,
      "check_mode": "agent",
      "check_type": "agent_script",
      "parameters": {
        "script_id": "0316d8dc-4f1e-551c-aaa2-42b2bc9840c5"
      },
      "sort_order": 2,
      "value_type": "gauge",
      "description": "",
      "check_config": {
        "script_id": "0316d8dc-4f1e-551c-aaa2-42b2bc9840c5"
      },
      "is_telemetry": false,
      "interpretation": null,
      "threshold_crit": null,
      "threshold_warn": null,
      "interval_seconds": 600,
      "threshold_direction": "upper",
      "confirmation_attempts": 1,
      "confirmation_interval_seconds": 10
    },
    {
      "name": "DFS Event 2104",
      "auto_add": true,
      "check_mode": "agent",
      "check_type": "agent_script",
      "parameters": {
        "script_id": "a3b90455-86db-56f5-adcf-5cb72d3b7194"
      },
      "sort_order": 3,
      "value_type": "gauge",
      "description": "",
      "check_config": {
        "script_id": "a3b90455-86db-56f5-adcf-5cb72d3b7194"
      },
      "is_telemetry": false,
      "interpretation": null,
      "threshold_crit": null,
      "threshold_warn": null,
      "interval_seconds": 600,
      "threshold_direction": "upper",
      "confirmation_attempts": 1,
      "confirmation_interval_seconds": 10
    },
    {
      "name": "DFS Event 4206",
      "auto_add": true,
      "check_mode": "agent",
      "check_type": "agent_script",
      "parameters": {
        "script_id": "179a70bd-a865-515e-b5a5-ed1f8f9e0055"
      },
      "sort_order": 4,
      "value_type": "gauge",
      "description": "",
      "check_config": {
        "script_id": "179a70bd-a865-515e-b5a5-ed1f8f9e0055"
      },
      "is_telemetry": false,
      "interpretation": null,
      "threshold_crit": null,
      "threshold_warn": null,
      "interval_seconds": 600,
      "threshold_direction": "upper",
      "confirmation_attempts": 1,
      "confirmation_interval_seconds": 10
    },
    {
      "name": "DFS Event 4212",
      "auto_add": true,
      "check_mode": "agent",
      "check_type": "agent_script",
      "parameters": {
        "script_id": "01395052-6235-5ccc-b763-f2698dc50f9d"
      },
      "sort_order": 5,
      "value_type": "gauge",
      "description": "",
      "check_config": {
        "script_id": "01395052-6235-5ccc-b763-f2698dc50f9d"
      },
      "is_telemetry": false,
      "interpretation": null,
      "threshold_crit": null,
      "threshold_warn": null,
      "interval_seconds": 600,
      "threshold_direction": "upper",
      "confirmation_attempts": 1,
      "confirmation_interval_seconds": 10
    },
    {
      "name": "Agent Overview",
      "auto_add": true,
      "check_mode": "agent",
      "check_type": "agent_overview",
      "parameters": {},
      "sort_order": 5,
      "value_type": "info",
      "description": "Live-Telemetrie (CPU, RAM, Disks, Netzwerk, Top-Prozesse, Eventlog, Benutzer) für das Command Center Dashboard.",
      "check_config": {},
      "is_telemetry": true,
      "interpretation": null,
      "threshold_crit": null,
      "threshold_warn": null,
      "interval_seconds": 30,
      "threshold_direction": "upper",
      "confirmation_attempts": 1,
      "confirmation_interval_seconds": 10
    },
    {
      "name": "Agent Netzwerk-Status",
      "auto_add": true,
      "check_mode": "agent",
      "check_type": "agent_network_state",
      "parameters": {},
      "sort_order": 6,
      "value_type": "info",
      "description": "Interfaces, Listener, Verbindungen, Routing.",
      "check_config": {},
      "is_telemetry": true,
      "interpretation": null,
      "threshold_crit": null,
      "threshold_warn": null,
      "interval_seconds": 300,
      "threshold_direction": "upper",
      "confirmation_attempts": 1,
      "confirmation_interval_seconds": 10
    },
    {
      "name": "Agent Sicherheit",
      "auto_add": true,
      "check_mode": "agent",
      "check_type": "agent_security",
      "parameters": {},
      "sort_order": 7,
      "value_type": "info",
      "description": "Defender, Firewall, TPM, BitLocker, offene Ports, Zertifikate.",
      "check_config": {},
      "is_telemetry": true,
      "interpretation": null,
      "threshold_crit": null,
      "threshold_warn": null,
      "interval_seconds": 3600,
      "threshold_direction": "upper",
      "confirmation_attempts": 1,
      "confirmation_interval_seconds": 10
    },
    {
      "name": "Agent Lebenszyklus",
      "auto_add": true,
      "check_mode": "agent",
      "check_type": "agent_lifecycle",
      "parameters": {},
      "sort_order": 8,
      "value_type": "info",
      "description": "Aktivierung, Domain, Update-Historie, BSODs, Backup.",
      "check_config": {},
      "is_telemetry": true,
      "interpretation": null,
      "threshold_crit": null,
      "threshold_warn": null,
      "interval_seconds": 43200,
      "threshold_direction": "upper",
      "confirmation_attempts": 1,
      "confirmation_interval_seconds": 10
    },
    {
      "name": "Agent Inventar",
      "auto_add": true,
      "check_mode": "agent",
      "check_type": "agent_inventory",
      "parameters": {},
      "sort_order": 9,
      "value_type": "info",
      "description": "Installierte Programme, geplante Tasks, Autostart, Dienste.",
      "check_config": {},
      "is_telemetry": true,
      "interpretation": null,
      "threshold_crit": null,
      "threshold_warn": null,
      "interval_seconds": 21600,
      "threshold_direction": "upper",
      "confirmation_attempts": 1,
      "confirmation_interval_seconds": 10
    },
    {
      "name": "Agent Hardware",
      "auto_add": true,
      "check_mode": "agent",
      "check_type": "agent_hardware",
      "parameters": {},
      "sort_order": 10,
      "value_type": "info",
      "description": "CPU, Speicher, Mainboard, BIOS, Disks, GPUs, Akku.",
      "check_config": {},
      "is_telemetry": true,
      "interpretation": null,
      "threshold_crit": null,
      "threshold_warn": null,
      "interval_seconds": 86400,
      "threshold_direction": "upper",
      "confirmation_attempts": 1,
      "confirmation_interval_seconds": 10
    }
  ],
  "profile": {
    "icon": "server",
    "name": "Windows - DFS Replication",
    "tags": [
      "windows",
      "agent",
      "dfs"
    ],
    "vendor": "microsoft",
    "category": "server",
    "os_family": "windows",
    "description": "DFS Replication monitoring: Service, replication events. Auf Basis-Template + dieses anwenden.",
    "ip_required": false,
    "port_layout": null,
    "visual_type": null,
    "snmp_enabled": false,
    "agent_capable": true,
    "requires_snmp": false,
    "description_md": "DFS Replication monitoring: Service, replication events. Auf Basis-Template + dieses anwenden.",
    "requires_agent": true,
    "sysoid_patterns": null,
    "sysdescr_patterns": null,
    "requires_collector": false
  },
  "scripts": [
    {
      "name": "DFS Event 4612",
      "script_id": "07c86fb5-6deb-5ef2-9c94-b70436779b02",
      "is_builtin": true,
      "description": "DFS replication warning event check",
      "interpreter": "powershell",
      "script_body": "$c = @(Get-WinEvent -FilterHashtable @{LogName='DFS Replication';ID=4612;StartTime=(Get-Date).AddHours(-24)} -EA SilentlyContinue).Count\nif ($c -gt 0) { Write-Output \"WARNING - $c DFS replication warning (Event 4612) | count=$c\"; exit 1 }\nWrite-Output \"OK - No DFS replication warning (Event 4612) | count=0\"; exit 0",
      "expected_output": "nagios"
    },
    {
      "name": "DFS Event 2004",
      "script_id": "0316d8dc-4f1e-551c-aaa2-42b2bc9840c5",
      "is_builtin": true,
      "description": "DFS journal wrap event check",
      "interpreter": "powershell",
      "script_body": "$c = @(Get-WinEvent -FilterHashtable @{LogName='DFS Replication';ID=2004;StartTime=(Get-Date).AddHours(-24)} -EA SilentlyContinue).Count\nif ($c -gt 0) { Write-Output \"CRITICAL - $c DFS journal wrap (Event 2004) | count=$c\"; exit 2 }\nWrite-Output \"OK - No DFS journal wrap (Event 2004) | count=0\"; exit 0",
      "expected_output": "nagios"
    },
    {
      "name": "DFS Event 2104",
      "script_id": "a3b90455-86db-56f5-adcf-5cb72d3b7194",
      "is_builtin": true,
      "description": "DFS replication stopped event check",
      "interpreter": "powershell",
      "script_body": "$c = @(Get-WinEvent -FilterHashtable @{LogName='DFS Replication';ID=2104;StartTime=(Get-Date).AddHours(-24)} -EA SilentlyContinue).Count\nif ($c -gt 0) { Write-Output \"CRITICAL - $c DFS replication stopped (Event 2104) | count=$c\"; exit 2 }\nWrite-Output \"OK - No DFS replication stopped (Event 2104) | count=0\"; exit 0",
      "expected_output": "nagios"
    },
    {
      "name": "DFS Event 4206",
      "script_id": "179a70bd-a865-515e-b5a5-ed1f8f9e0055",
      "is_builtin": true,
      "description": "DFS space problem event check",
      "interpreter": "powershell",
      "script_body": "$c = @(Get-WinEvent -FilterHashtable @{LogName='DFS Replication';ID=4206;StartTime=(Get-Date).AddHours(-24)} -EA SilentlyContinue).Count\nif ($c -gt 0) { Write-Output \"CRITICAL - $c DFS space problem (Event 4206) | count=$c\"; exit 2 }\nWrite-Output \"OK - No DFS space problem (Event 4206) | count=0\"; exit 0",
      "expected_output": "nagios"
    },
    {
      "name": "DFS Event 4212",
      "script_id": "01395052-6235-5ccc-b763-f2698dc50f9d",
      "is_builtin": true,
      "description": "DFS staging area full event check",
      "interpreter": "powershell",
      "script_body": "$c = @(Get-WinEvent -FilterHashtable @{LogName='DFS Replication';ID=4212;StartTime=(Get-Date).AddHours(-24)} -EA SilentlyContinue).Count\nif ($c -gt 0) { Write-Output \"CRITICAL - $c DFS staging area full (Event 4212) | count=$c\"; exit 2 }\nWrite-Output \"OK - No DFS staging area full (Event 4212) | count=0\"; exit 0",
      "expected_output": "nagios"
    }
  ],
  "schema_version": 1
}