Skip to content

Service Monitor

Tiago Madeira edited this page Jan 29, 2025 · 17 revisions

Summary

ServiceMonitor.ps1 is a PowerShell script that monitors a specific Windows service and automatically restarts it if it stops. It uses WMI events for real-time monitoring and logs all actions to a file for auditing.

Disclaimer

Before running this script, you must replace all instances of <path> with the actual path where you saved the script. Failing to do so will result in errors. Open the script in a text editor like VS Code or PowerShell ISE.

Locate the $serviceName variable and change its value to the exact name of the Windows service you wish to monitor.

Run script via PowerShell

  • Open a PowerShell console (standard console, no administrator rights required).
  • Navigate to the folder containing the script
  • Call the script .\ServiceMonitor.ps1

Run script via Task Scheduler

1. Configure the Task:

  • Trigger: At system startup

Actions:

  • Action: Start a program
  • Program/script: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe
  • Arguments: -WindowStyle Hidden -ExecutionPolicy Bypass -File "C:\<Path>\ServiceMonitor.ps1" - This will suppress the console window.

Settings:

  • Check "Run whether user is logged on or not"
  • Check "Run with highest privileges"

2. Keep the Infinite Loop:

  • The while ($true) loop ensures the script stays running in the background. Task Scheduler will treat it as a long-running task.

Parameters

$serviceName: It specifies the name of the Windows service you want to monitor. You must change this to the correct name of your service.

$logPath: This defines the path to the log file where the script will record its actions (service restarts and errors).

$sourceIdentifier: This is used to manage the event subscription. It gives a name to the event registration so the script can later remove it if needed. It's set to "ServiceMonitor". You probably won't need to change this unless you're running multiple instances of this script for different services.

Clone this wiki locally