Atlas Knowledge Base
Dashboard
Sensor Types

Sensor Types


A sensor is one recurring check of one thing: a host reading, a network endpoint, a database value, a log file. Every sensor reports a status - up, warning, or down - plus one or more numeric readings called channels. Warning and down thresholds can be set on any channel, and each sensor has its own probe interval and alert timing.

Sensors run in one of two places. Agent sensors execute on the monitored host itself, collected by the local probe agent. Core sensors execute on the monitor's core servers, either directly or through a designated agent that acts as a probe for devices on its network.

Parameters listed as optional have a sensible default and can be omitted. File and directory paths are always absolute.

Network and endpoint checks


Type

What it checks

Parameters

ping

ICMP reachability and response time of a device. Each check sends a short burst of echoes rather than one, so the reading carries packet loss and latency spread as well as the mean round trip: responseMs (the mean of the echoes that answered), lossPercent, minMs, avgMs, maxMs and jitterMs. The sensor goes down only when every echo in the burst is lost; partial loss and choppy latency are threshold matters on their own channels, so a path that is degrading shows up before it fails. When nothing answers, lossPercent is still reported and the latency channels are left out rather than reported as zero. Devices without an agent are pinged from the core or from an agent on the same network, matching where the device is actually reachable from.

target - host, IP, or host:port. mode (optional) - icmp or tcp; when omitted the target shape decides: a target with a port is a TCP connect, a bare host or IP is ICMP. count (optional) - echoes per check, 5 by default, 1 to 10; 1 is a single-echo probe carrying the whole timeout.

http

An HTTP or HTTPS URL: the request succeeds, the response status is acceptable, and response time is recorded.

target - the URL. expectStatusClass (optional) - status class treated as up, 2xx by default. headers (optional) - request headers to send. expectBodyContains (optional) - text the response body must contain. expectJSON (optional) - a JSON field check on the response. insecure (optional) - skip TLS certificate verification.

tcp

A TCP connection to a host and port, with response time. Covers services that speak no HTTP - receivers, automation ports, listeners.

target - host:port.

ssl

A TLS certificate: validity and days remaining until expiry, so certificates warn before they lapse.

target - host:port. serverName (optional) - SNI name when it differs from the target host. warnDays (optional) - warning under this many days remaining, 30 by default. downDays (optional) - down under this many days, 7 by default.

dns

Name resolution: the record resolves and the answer is what it should be.

target - the name to resolve. dnsServer (optional) - resolver host:port, the system resolver by default. expected (optional) - an address the resolved set must contain.

snmp

One interface on a switch, router or firewall, over SNMP v2c or v3. It publishes rates rather than raw counters - inBps and outBps from the 64-bit octet columns, error and discard rates in each direction, and the raw operStatus - so a threshold means the same thing at every interval. The sensor itself is down only when the SNMP conversation fails or the named interface cannot be found; a saturated link, a port dropping frames and an interface that is administratively down are all channel thresholds. The interface is tracked by name, and the resolved index is re-checked on every poll, so a device that renumbers its ports across a reboot is re-resolved instead of reporting another port's traffic. A device restart is recognised from its own uptime and the sensor settles for one poll rather than publishing a false spike.

target - host, or host:port; 161 by default. interface - the interface name, matched against the device's interface-name column and then its description column. version (optional) - 2c by default, or 3. communityEnv - for v2c, the name of the environment variable holding the community string. For v3: secLevel, userEnv, authProto (sha or sha256) with authPassEnv, and privProto (aes or aes256) with privPassEnv, as the chosen security level requires. Credentials are named, never written: the value lives in the environment of the machine running the probe.

Host checks

Host checks run on the agent. CPU, memory, and clock sensors are created automatically for every agent host, and a disk sensor is created automatically for every discovered volume; the rest are configured per host.


Type

What it checks

Parameters

cpu

Processor load as a percentage.

None.

memory

Memory in use as a percentage.

None.

disk

Free space on one volume, as both a percentage and an absolute GB value. Thresholds can be set on either - absolute GB floors suit large volumes where a percentage misleads.

mount - the volume, set automatically for the auto-created per-volume sensors.

service

A named OS service is installed and running.

name - the service name.

process

A named process is present.

name - the process name. minCount (optional) - minimum number of instances that must be running, 1 by default.

iisapp

A named IIS application pool is started. IIS app pools are tracked separately from OS services.

appPool - the application pool name.

oslog

The OS event log, watched for matching entries.

source - the log or event source to watch. pattern (optional) - text the entry must match. minLevel (optional) - minimum severity level that counts.

clock

The host clock's drift from the monitor core, in seconds. A drifting clock corrupts timestamps long before anything else fails.

agent - the host whose clock is measured, set automatically for the auto-created sensors. staleAfterSeconds (optional) - how long without a fresh measurement before the sensor goes down.

hosthygiene

Patch and reboot posture of the host: uptimeDays, pendingReboot as 1 or 0, and daysSinceLastUpdate for the age of the newest installed operating-system update. It reports Up whenever collection works, so "up too long", "reboot queued" and "unpatched for N days" are threshold settings on those channels. A channel the platform cannot determine is left out rather than reported as zero, which would read as a false all-clear: a non-Windows host reports uptime alone, and a Windows host with no hotfix inventory omits the update age. On Windows the pending-reboot answer comes from the servicing, Windows Update and pending-file-rename signals together.

None.

diskhealth

Windows predictive disk failure. The sensor goes down when any physical disk predicts its own failure through SMART or reports a drive status other than OK, and the message names the model and serial, so the alert itself carries what a replacement needs. The count is published as failingDisks so the number is trendable outside an incident. A non-Windows host reports a clear down rather than a silent Up.

None.

perfcounter

One Windows performance counter, published as the single value channel. It is a reading rather than a verdict - Up whenever the counter answers, down only when it cannot be read - so "queue depth over 2" or "processor time over 90" is a threshold on that channel, and one sensor type covers every counter on the box. Counters are added by their English name, so the same configuration works on a localized Windows. Rate counters are collected twice a short interval apart, because a rate is the difference between two collections. A non-Windows host reports a clear down.

counter - the counter path in \Object(instance)\Counter form; wildcards and remote machine prefixes are rejected. sampleMillis (optional) - spacing of the two collections, 200 by default, 2000 at most.

Log and file checks


Type

What it checks

Parameters

logtail

A log file on the host, followed line by line. Ordered pattern rules classify new lines and matching lines raise the sensor's status; enrollment never replays history. A log whose file name changes with the date - the SBN services convention of a dated name plus numbered size-rollover segments - is followed by pattern instead of by a fixed path: the live file is the newest matching name, and a check that spans a rollover drains the file it was on to the end before walking the ones the log rolled into, so lines are never skipped across the roll. A pattern that matches no file at all is a down condition, not a quiet sensor.

path - the log file. pathPattern - an absolute file pattern instead of a fixed path, for date-stamped and rolled log names; exactly one of path and pathPattern is given. rules - an ordered list of entries, each a match pattern and the severity it raises; the first matching rule wins. startAt (optional) - where to begin on first read, the end of the file by default. maxBytesPerPoll and maxLineBytes (optional) - read caps per poll and per line.

filevalue

A numeric value written to a small file by a scheduled task on the host. A stale file is itself a down condition, so a silently dead task is caught even when the last written value looked healthy.

path - the drop file. staleAfterSeconds - file age beyond which the sensor goes down. label (optional) - display name for the value channel.

Database checks

Database sensors are covered in detail in Database Monitoring.


Type

What it checks

Parameters

dbproc

A read-only stored procedure in the dedicated health database, returning one or more value channels with normal thresholds. Space, log, blocking, connection, and queue checks all use this type, and per-database space sensors are created automatically from the server's own database list.

dialect - the database dialect. target - host:port of the database server. proc - the procedure to run. database (optional) - the database to run it in. args (optional) - named arguments passed to the procedure. loginEnv and passwordEnv - names of environment variables on the executing host that hold the monitor login; credentials never appear in the configuration itself. timeoutSeconds and dialTimeoutSeconds (optional) - query and connection timeouts.

dbmissing

A database that was expected but is absent from the server's database list. The sensor never probes; it exists to hold a down state until the database is back.

database - the missing database's name. server (optional) - the server it was expected on.

Scripted checks


Type

What it checks

Parameters

script

An operator-provided executable run by the monitor. The exit code sets the status and the output carries the value and message, in either the classic PRTG EXE text convention or a richer JSON form. A hung script is killed at its timeout and reported down.

command - absolute path to the executable; it runs directly, never through a shell. args (optional) - arguments. workDir (optional) - working directory. timeoutSeconds (optional) - kill-and-report-down timeout. envAllow (optional) - names of environment variables passed through; all others are stripped. outputMode (optional) - text for the PRTG EXE convention or json for the structured form.

Roll-ups


Type

What it checks

Parameters

composite

The combined state of a set of member sensors, presented as one sensor. A composite carries the worst state of its members, so one dashboard row can answer for a whole chain.

members - the member sensor names. aggregation (optional) - how member states combine, worst-of by default. upThreshold (optional) - minimum up members to stay up, all of them by default. downThreshold (optional) - how many down members force down, 1 by default.




Was this helpful?