PI Nexus+ / Administration Guide
Host Monitoring
This chapter sets up agentless monitoring of the Windows servers in your PI landscape: CPU, memory, disks, PI services and PI roles. Users work with the results as described in Host Monitoring in the User Guide; all values and limits are in the Host Monitoring Reference.
Overview
This chapter sets up agentless monitoring of the Windows servers in your PI landscape: CPU, memory, disks, PI services and PI roles. Users work with the results as described in Host Monitoring in the User Guide; all values and limits are in the Host Monitoring Reference.
Before you start
You need:
- The Admin role in PI Nexus+.
- Network access from the scanner server to each host on TCP 5985 (or 5986 for HTTPS). See Ports in the Reference.
- A local administrator on each host, once, to grant the rights.
PI Nexus+ contacts no server until you add it. Host monitoring is included in every license edition.
Choose how to read each host
Use the first way wherever it is possible.

| Host | Read from | Section |
|---|---|---|
| Domain member the scanner service account can sign in to | WinRM, scanner service account, HTTP 5985 | Grant the rights on each host |
| Workgroup, DMZ or untrusted-domain host | WinRM, credential profile, HTTPS 5986 | Read a host with a credential profile |
| Host where no WinRM rights are granted, but PIPerfMon collects its counters | PI points | Read a host from PI points |
Grant the rights on each host
The rights script grants everything the scanner service account needs on one host, without administrator rights for the account.

- Open Admin > Hosts and choose Rights script. Note the account it names: the account the scanner service ran the last access test as. Before any test, use the PI Nexus+ service account.
- Choose Download script and copy
Grant-PINexusHostAccess.ps1to the host. - On the host, open Windows PowerShell 5.1 as a local administrator and run the commands shown, first with
-WhatIf. - Read the output. It lists what it changed; it changes only what is missing.
- In PI Nexus+, run Test access for the host (see Verify access).
Run the script again after installing or upgrading a PI component on the host. The rights and parameters are listed under Required Windows rights and Rights script parameters in the Reference.
Many hosts: Group Policy. In a GPO linked to the servers' OU, add the account to Remote Management Users and Performance Monitor Users, enable WinRM and open TCP 5985 from the scanner server. WMI and service rights have no Group Policy setting: run the rights script as a startup script or a scheduled task. Then run gpupdate /force and choose Test access. The policy paths are under Group Policy in the Reference.
SQL Server readings (optional). For database sizes, log use, backup age and blocking, grant the scanner service account's SQL Server login the rights in Required SQL Server rights. PI Nexus+ reads its own SQL Server and the PI Vision SQL Server automatically; add other instances in the host's Edit dialog under SQL Server instances.
Add a host
Adding a host starts its access test; polling starts once the test passes.

- Choose Add host, or Add next to a server under Suggested hosts. To add several suggestions, tick them and choose Add N selected.
- Enter the server's DNS name. Use the full name when two servers share a short name.
- Optionally enter a Display name and a Description, and choose the Site. Choose Add & test access.
- Wait for Access to show Ready. No access names the step that failed.
- Use the row menu for Test access, Edit, Pause monitoring and Delete.
Suggested hosts are the servers PI Nexus+ knows from its targets, the PI Vision SQL Server and the PI Interface and PI Adapter nodes. Any other Windows server gets the role Other.
Verify access
The access test shows which right or setting is missing on a host.

- Click the Ready or No access label in the Access column. Find the first step marked failed and read its remedy.
- Check the last line: it names the account and the scanner server the test ran as and from.
- Fix the cause (see Troubleshooting below) and choose Test again.
Optional steps that are not available do not stop monitoring. Within five minutes of Ready, the Monitoring board shows the host's CPU, memory and disks.
Read a host with a credential profile
Use a credential profile for a host the scanner service account cannot sign in to.

On the host, grant the profile's account the rights from Grant the rights on each host, create a WinRM HTTPS listener with a certificate for the host's name (winrm quickconfig -transport:https), and allow TCP 5986 from the scanner server.
In PI Nexus+, create the profile first:

- Open Admin > Hosts > Credentials and choose Add profile.
- Enter a Name and the Account (
DOMAIN\user,HOST\useroruser@domain). - Enter the account's Password and choose Save.
Then choose Edit in the host's row menu:
- Set Read from to WinRM.
- Set Account to the profile.
- Set Transport to HTTPS 5986 and save. The access test runs again.
With a profile over HTTPS, a host can also be added by its IP address. For a self-signed certificate, use Skip CA check or Skip name check, on a trusted network only. Availability checks and SQL Server reads still use the scanner service account.
Note: On a split installation, install the shared secret certificate on both servers before you save a profile (see Protect the client secret with a certificate in OpenID Connect). Otherwise the scanner server cannot decrypt the password.
Read a host from PI points
Use PI points for a host whose IT grants no WinRM rights, where the PIPerfMon interface already collects its Windows counters.

- In the host's Edit dialog, set Read from to PI points, choose the PI Data Archive that holds the points, and save.
- Check the PI points list: it shows the point found for each metric and disk with its last value.
- Correct a point by typing another name, or use Add disk or Find points.
A PI points host gives CPU, memory and disks only. The counter paths are listed under PI points read for a PI points host in the Reference.
Add availability checks
Availability checks test from the scanner server that a service on the host answers. Checks for PI Data Archive, AF Server and PI Vision targets are created automatically.

- In the host's row menu, choose Availability checks.
- Under Check, choose HTTP address (for example
https://pi01/piwebapi) or TCP port (for example1433). - For an address on another server that needs Windows sign-in, tick Send Windows credentials.
- Choose Add check.
Adjust limits, disks and watched services
Defaults suit most estates; change them only for a known need.
- All hosts: Admin > Hosts > Limits. CPU, disk latency, network, PI Buffer size and SQL blocking alerts are off until you switch them on.
- One host or disk: in Edit, clear Use defaults under Disk, CPU or Disk latency (Memory alerts exist per host only), or set a volume to GB free or Ignore this volume. On a PI Data Archive, tick PI archive volume on the archive disk.
- Services and processes: use Also watch and Never watch. Set a service you do not use to Manual or Disabled on the host instead of suppressing its issue.
All defaults and ranges are in Default limits in the Reference.
Plan maintenance windows
A maintenance window stops host emails during planned work.

- Open Admin > Hosts > Maintenance and choose Add window.
- Under Applies to, choose All hosts, The hosts of one site or One host.
- Under Repeats, choose Once or Every week. Set Starts, Duration hours and Duration minutes, add an optional Note, and choose Save.
Issues are still raised during a window. Those still open when it ends are emailed then. Weekly windows follow the scanner server's time zone.
Send host monitoring emails
Host issues have their own email type, so an IT team can receive host outages without the content-health emails.

- Open Admin > Notifications > Delivery Rules > Host monitoring, tick Enable and choose the emails and the Minimum severity.
- Optionally set a Reminder and an Escalation for errors nobody has acknowledged.
- Under Recipients, tick Host monitoring for the recipients who should receive them, and Host monitoring escalations for the escalation recipients.
With the rule on, PI Nexus+ also emails the Host monitoring recipients when the Scanner service stops reporting for ten minutes. Settings and defaults: Notifications in the Reference.
Troubleshooting
Find the first failed step in the host's Access details. Every step's causes and fixes are under Access problems in the Reference.
| Step or symptom | Cause | Fix |
|---|---|---|
| WinRM port failed | WinRM is off, or a firewall blocks TCP 5985 or 5986 | Run winrm quickconfig (HTTPS: create the HTTPS listener) and open the port from the scanner server |
| WinRM sign-in failed: access denied, WMI access failed, or CPU counters failed | A right is missing | Run the rights script, then test again |
| WinRM sign-in failed: IP address | An IP address with the scanner service account or over HTTP | Add the host by DNS name, or use a credential profile over HTTPS |
| The rights script stops with "is a domain controller" | A domain controller has no local groups | Grant the rights through domain policy (see Many hosts: Group Policy) |
| Host shows Stale on the board | The Scanner service has stopped | Start the PI Nexus+ Scanner service |
| Disk issue on a large disk that is fine | Percent limits do not suit a large disk | Set GB free limits for that disk |
Reference: Host Monitoring Reference
