| DisplayName | ID | Target | Category | Enabled | Alert Generate |
| 终端服务活动会话 (2008) 的基准收集规则 | Microsoft.Windows.Server.2008.TerminalServicesRole.Service.TerminalServer.ActiveSessions.BaselineCollection | Microsoft.Windows.Server.2008.TerminalServicesRole.Service.TerminalServer | PerformanceCollection | True | False |
| 性能测量:终端服务活动会话 (2008) | Microsoft.Windows.Server.2008.TerminalServicesRole.Service.TerminalServer.ActiveSessions.PerformanceCollection | Microsoft.Windows.Server.2008.TerminalServicesRole.Service.TerminalServer | PerformanceCollection | True | False |
| 终端服务客户端提供的许可证无效 | Microsoft.Windows.Server.2008.TerminalServicesRole.Service.TerminalServer.EventCollection.1003 | Microsoft.Windows.Server.2008.TerminalServicesRole.Service.TerminalServer | EventCollection | False | True |
| 终端服务器无法颁发客户端许可证 | Microsoft.Windows.Server.2008.TerminalServicesRole.Service.TerminalServer.EventCollection.1004 | Microsoft.Windows.Server.2008.TerminalServicesRole.Service.TerminalServer | EventCollection | False | True |
| 终端服务器接收到大量没有完成的连接 | Microsoft.Windows.Server.2008.TerminalServicesRole.Service.TerminalServer.EventCollection.1006 | Microsoft.Windows.Server.2008.TerminalServicesRole.Service.TerminalServer | EventCollection | True | False |
| 终端服务器客户端已因其临时许可证到期而断开连接 | Microsoft.Windows.Server.2008.TerminalServicesRole.Service.TerminalServer.EventCollection.1011 | Microsoft.Windows.Server.2008.TerminalServicesRole.Service.TerminalServer | EventCollection | False | True |
| 远程会话超出了允许的最多登录失败尝试次数。 | Microsoft.Windows.Server.2008.TerminalServicesRole.Service.TerminalServer.EventCollection.1012 | Microsoft.Windows.Server.2008.TerminalServicesRole.Service.TerminalServer | EventCollection | True | False |
| 终端服务器客户端已因无法续订其许可证而断开连接 | Microsoft.Windows.Server.2008.TerminalServicesRole.Service.TerminalServer.EventCollection.1028 | Microsoft.Windows.Server.2008.TerminalServicesRole.Service.TerminalServer | EventCollection | False | True |
| 终端服务器侦听程序堆栈处于关闭状态 | Microsoft.Windows.Server.2008.TerminalServicesRole.Service.TerminalServer.EventCollection.1035 | Microsoft.Windows.Server.2008.TerminalServicesRole.Service.TerminalServer | EventCollection | True | True |
| 终端服务器会话创建失败 | Microsoft.Windows.Server.2008.TerminalServicesRole.Service.TerminalServer.EventCollection.1036 | Microsoft.Windows.Server.2008.TerminalServicesRole.Service.TerminalServer | EventCollection | True | True |
| 此终端服务器无法与许可证服务器通信 | Microsoft.Windows.Server.2008.TerminalServicesRole.Service.TerminalServer.EventCollection.1043 | Microsoft.Windows.Server.2008.TerminalServicesRole.Service.TerminalServer | EventCollection | True | True |
| 无法加载终端服务器配置文件路径 | Microsoft.Windows.Server.2008.TerminalServicesRole.Service.TerminalServer.EventCollection.1046 | Microsoft.Windows.Server.2008.TerminalServicesRole.Service.TerminalServer | EventCollection | False | True |
| 终端服务器侦听程序配置的身份验证和加密设置不一致 | Microsoft.Windows.Server.2008.TerminalServicesRole.Service.TerminalServer.EventCollection.1050 | Microsoft.Windows.Server.2008.TerminalServicesRole.Service.TerminalServer | EventCollection | True | True |
| 终端服务器已配置为使用某个证书,但终端服务器在访问该证书时遇到问题 | Microsoft.Windows.Server.2008.TerminalServicesRole.Service.TerminalServer.EventCollection.1051.1055 | Microsoft.Windows.Server.2008.TerminalServicesRole.Service.TerminalServer | EventCollection | True | True |
| 终端服务器已配置为使用已过期或即将过期的证书 | Microsoft.Windows.Server.2008.TerminalServicesRole.Service.TerminalServer.EventCollection.1052.1065.1053 | Microsoft.Windows.Server.2008.TerminalServicesRole.Service.TerminalServer | EventCollection | True | True |
| 终端服务器已配置为使用某个证书,但该证书未包含服务器身份验证的“增强型密钥使用”属性 | Microsoft.Windows.Server.2008.TerminalServicesRole.Service.TerminalServer.EventCollection.1054 | Microsoft.Windows.Server.2008.TerminalServicesRole.Service.TerminalServer | EventCollection | True | True |
| 终端服务器无法创建或替换自签名证书 | Microsoft.Windows.Server.2008.TerminalServicesRole.Service.TerminalServer.EventCollection.1057.1058 | Microsoft.Windows.Server.2008.TerminalServicesRole.Service.TerminalServer | EventCollection | True | True |
| 终端服务器身份验证证书配置数据无效,且该服务已将其重置 | Microsoft.Windows.Server.2008.TerminalServicesRole.Service.TerminalServer.EventCollection.1059 | Microsoft.Windows.Server.2008.TerminalServicesRole.Service.TerminalServer | EventCollection | True | True |
| 因为指定的路径不存在或无法访问,未设置终端服务用户主目录 | Microsoft.Windows.Server.2008.TerminalServicesRole.Service.TerminalServer.EventCollection.1060 | Microsoft.Windows.Server.2008.TerminalServicesRole.Service.TerminalServer | EventCollection | False | True |
| 终端服务器无法从 AD 中检索用户授权信息 | Microsoft.Windows.Server.2008.TerminalServicesRole.Service.TerminalServer.EventCollection.1061 | Microsoft.Windows.Server.2008.TerminalServicesRole.Service.TerminalServer | EventCollection | False | True |
| 终端服务器已配置为使用基于模板的证书,但此证书上的使用者名称无效 | Microsoft.Windows.Server.2008.TerminalServicesRole.Service.TerminalServer.EventCollection.1062 | Microsoft.Windows.Server.2008.TerminalServicesRole.Service.TerminalServer | EventCollection | True | True |
| 终端服务器无法安装基于模板的新证书 | Microsoft.Windows.Server.2008.TerminalServicesRole.Service.TerminalServer.EventCollection.1064 | Microsoft.Windows.Server.2008.TerminalServicesRole.Service.TerminalServer | EventCollection | True | True |
| 终端服务器无法注册要用于服务器身份验证的“TERMSRV”服务主体名称 | Microsoft.Windows.Server.2008.TerminalServicesRole.Service.TerminalServer.EventCollection.1067 | Microsoft.Windows.Server.2008.TerminalServicesRole.Service.TerminalServer | EventCollection | True | True |
| 尚未配置 TS 授权模式 | Microsoft.Windows.Server.2008.TerminalServicesRole.Service.TerminalServer.EventCollection.1068 | Microsoft.Windows.Server.2008.TerminalServicesRole.Service.TerminalServer | EventCollection | True | True |
| TS 授权宽限期已到期,而终端服务器的授权模式尚未配置 | Microsoft.Windows.Server.2008.TerminalServicesRole.Service.TerminalServer.EventCollection.1069 | Microsoft.Windows.Server.2008.TerminalServicesRole.Service.TerminalServer | EventCollection | True | True |
| 终端服务器找不到许可证服务器或授权宽限期已到期或即将到期 | Microsoft.Windows.Server.2008.TerminalServicesRole.Service.TerminalServer.EventCollection.1129.1128.1130.1131.1132 | Microsoft.Windows.Server.2008.TerminalServicesRole.Service.TerminalServer | EventCollection | True | True |
| 侦听程序侦听失败 | Microsoft.Windows.Server.2008.TerminalServicesRole.Service.TerminalServer.EventCollection.260 | Microsoft.Windows.Server.2008.TerminalServicesRole.Service.TerminalServer | EventCollection | True | True |
| TS 会话 Broker 服务器名称无效 | Microsoft.Windows.Server.2008.TerminalServicesRole.Service.TerminalServer.EventCollection.TSSessionBrokerClient1003 | Microsoft.Windows.Server.2008.TerminalServicesRole.Service.TerminalServer | Custom | True | True |
| 终端服务器负载平衡 Jet RPC 接口调用失败 | Microsoft.Windows.Server.2008.TerminalServicesRole.Service.TerminalServer.EventCollection.TSSessionBrokerClient1004 | Microsoft.Windows.Server.2008.TerminalServicesRole.Service.TerminalServer | EventCollection | True | True |
| 终端服务非活动会话 (Server 2008) 的基准收集规则 | Microsoft.Windows.Server.2008.TerminalServicesRole.Service.TerminalServer.InactiveSessions.BaselineCollection | Microsoft.Windows.Server.2008.TerminalServicesRole.Service.TerminalServer | PerformanceCollection | True | False |
| 性能测量:终端服务非活动会话 (2008) | Microsoft.Windows.Server.2008.TerminalServicesRole.Service.TerminalServer.InactiveSessions.PerformanceCollection | Microsoft.Windows.Server.2008.TerminalServicesRole.Service.TerminalServer | PerformanceCollection | True | False |
| 性能测量:终端服务会话总数 (2008) | Microsoft.Windows.Server.2008.TerminalServicesRole.Service.TerminalServer.TotalSessions.PerformanceCollection | Microsoft.Windows.Server.2008.TerminalServicesRole.Service.TerminalServer | PerformanceCollection | True | False |
| 重新启动 TS 网关服务器,并根据需要,删除并重新启动 TS 网关角色服务 | Microsoft.Windows.Server.2008.TerminalServicesRole.Service.TSGateway.EventCollection.1001 | Microsoft.Windows.Server.2008.TerminalServicesRole.Service.TSGateway | EventCollection | True | True |
| 获取、安装和配置满足 TS 网关服务器证书要求的证书 | Microsoft.Windows.Server.2008.TerminalServicesRole.Service.TSGateway.EventCollection.102 | Microsoft.Windows.Server.2008.TerminalServicesRole.Service.TSGateway | EventCollection | True | True |
| 确保已向 SSL 证书的私钥授予必需的权限 | Microsoft.Windows.Server.2008.TerminalServicesRole.Service.TSGateway.EventCollection.103 | Microsoft.Windows.Server.2008.TerminalServicesRole.Service.TSGateway | EventCollection | True | True |
| 检查设置是否与其他 TS 网关服务器上的本地安全组关联 | Microsoft.Windows.Server.2008.TerminalServicesRole.Service.TSGateway.EventCollection.2002 | Microsoft.Windows.Server.2008.TerminalServicesRole.Service.TSGateway | EventCollection | True | True |
| 确保已向 Core 注册表项授予必需的权限,如果需要,请删除并重新创建 TS CAP 和 TS RAP | Microsoft.Windows.Server.2008.TerminalServicesRole.Service.TSGateway.EventCollection.2004 | Microsoft.Windows.Server.2008.TerminalServicesRole.Service.TSGateway | EventCollection | True | True |
| 确保客户端满足 TS CAP 的要求 | Microsoft.Windows.Server.2008.TerminalServicesRole.Service.TSGateway.EventCollection.201 | Microsoft.Windows.Server.2008.TerminalServicesRole.Service.TSGateway | EventCollection | False | True |
| 同时连接到 TS 网关服务器的连接数已达到管理员配置的最大数量 | Microsoft.Windows.Server.2008.TerminalServicesRole.Service.TSGateway.EventCollection.203 | Microsoft.Windows.Server.2008.TerminalServicesRole.Service.TSGateway | EventCollection | True | True |
| 确保客户端满足网络策略服务器上配置的运行状况策略要求 | Microsoft.Windows.Server.2008.TerminalServicesRole.Service.TSGateway.EventCollection.204 | Microsoft.Windows.Server.2008.TerminalServicesRole.Service.TSGateway | EventCollection | False | True |
| 确保客户端满足 TS RAP 的要求 | Microsoft.Windows.Server.2008.TerminalServicesRole.Service.TSGateway.EventCollection.301 | Microsoft.Windows.Server.2008.TerminalServicesRole.Service.TSGateway | EventCollection | False | True |
| 确保远程桌面已启用且用户是 Remote Desktop Users 组的成员,并根据需要修复网络连接问题 | Microsoft.Windows.Server.2008.TerminalServicesRole.Service.TSGateway.EventCollection.304 | Microsoft.Windows.Server.2008.TerminalServicesRole.Service.TSGateway | EventCollection | True | True |
| 确保 TS 网关服务器支持客户端支持的身份验证方法 | Microsoft.Windows.Server.2008.TerminalServicesRole.Service.TSGateway.EventCollection.305 | Microsoft.Windows.Server.2008.TerminalServicesRole.Service.TSGateway | EventCollection | True | True |
| 将 TS 网关服务器配置为使用 SSL 的证书 | Microsoft.Windows.Server.2008.TerminalServicesRole.Service.TSGateway.EventCollection.306 | Microsoft.Windows.Server.2008.TerminalServicesRole.Service.TSGateway | EventCollection | True | True |
| 收集 TS 网关配置更改事件 | Microsoft.Windows.Server.2008.TerminalServicesRole.Service.TSGateway.EventCollection.504.506.510.512.514.516.520.521.522.540.541.542.560.561.562 | Microsoft.Windows.Server.2008.TerminalServicesRole.Service.TSGateway | EventCollection | True | False |
| 确保已向 LogEvents 注册表项授予必需的权限,且远程注册表服务已启动 | Microsoft.Windows.Server.2008.TerminalServicesRole.Service.TSGateway.EventCollection.505.507 | Microsoft.Windows.Server.2008.TerminalServicesRole.Service.TSGateway | EventCollection | True | True |
| 确保已向 Core 注册表项授予必需的权限 | Microsoft.Windows.Server.2008.TerminalServicesRole.Service.TSGateway.EventCollection.509.515.517 | Microsoft.Windows.Server.2008.TerminalServicesRole.Service.TSGateway | EventCollection | True | True |
| 确保已指定正确的中央 NPS 服务器 | Microsoft.Windows.Server.2008.TerminalServicesRole.Service.TSGateway.EventCollection.511.583.585 | Microsoft.Windows.Server.2008.TerminalServicesRole.Service.TSGateway | EventCollection | True | True |
| 查看事件日志中有关网络策略服务器的事件 | Microsoft.Windows.Server.2008.TerminalServicesRole.Service.TSGateway.EventCollection.513.584 | Microsoft.Windows.Server.2008.TerminalServicesRole.Service.TSGateway | EventCollection | True | True |
| 检查 TS 网关服务器是否已配置为使用满足 TS 网关要求的证书 | Microsoft.Windows.Server.2008.TerminalServicesRole.Service.TSGateway.EventCollection.518.519 | Microsoft.Windows.Server.2008.TerminalServicesRole.Service.TSGateway | EventCollection | True | True |
| 确保 TS CAP 配置正确 | Microsoft.Windows.Server.2008.TerminalServicesRole.Service.TSGateway.EventCollection.523.524.525 | Microsoft.Windows.Server.2008.TerminalServicesRole.Service.TSGateway | EventCollection | True | True |
| 确保 TS RAP 配置正确 | Microsoft.Windows.Server.2008.TerminalServicesRole.Service.TSGateway.EventCollection.543.544.545 | Microsoft.Windows.Server.2008.TerminalServicesRole.Service.TSGateway | EventCollection | True | True |
| 确保安全组和 TS 网关管理的组配置正确 | Microsoft.Windows.Server.2008.TerminalServicesRole.Service.TSGateway.EventCollection.563.564.565 | Microsoft.Windows.Server.2008.TerminalServicesRole.Service.TSGateway | EventCollection | True | True |
| 确保已向 RPC 注册表项授予必需的权限 | Microsoft.Windows.Server.2008.TerminalServicesRole.Service.TSGateway.EventCollection.622.623 | Microsoft.Windows.Server.2008.TerminalServicesRole.Service.TSGateway | EventCollection | True | True |
| 手动启用“终端服务网关服务器场”例外 | Microsoft.Windows.Server.2008.TerminalServicesRole.Service.TSGateway.EventCollection.627 | Microsoft.Windows.Server.2008.TerminalServicesRole.Service.TSGateway | EventCollection | True | True |
| 性能测量:TS 网关连接请求授权时间 (2008) | Microsoft.Windows.Server.2008.TerminalServicesRole.Service.TSGateway.PerformanceCollection.Connectionrequestauthorizationtime | Microsoft.Windows.Server.2008.TerminalServicesRole.Service.TSGateway | PerformanceCollection | True | False |
| 性能测量:TS 网关当前连接 (2008) | Microsoft.Windows.Server.2008.TerminalServicesRole.Service.TSGateway.PerformanceCollection.Currentconnections | Microsoft.Windows.Server.2008.TerminalServicesRole.Service.TSGateway | PerformanceCollection | True | False |
| 性能测量:TS 网关失败的连接授权 (2008) | Microsoft.Windows.Server.2008.TerminalServicesRole.Service.TSGateway.PerformanceCollection.FailedConnectionAuthorization | Microsoft.Windows.Server.2008.TerminalServicesRole.Service.TSGateway | PerformanceCollection | True | False |
| 性能测量:TS 网关失败的资源授权 (2008) | Microsoft.Windows.Server.2008.TerminalServicesRole.Service.TSGateway.PerformanceCollection.FailedResourceAuthoization | Microsoft.Windows.Server.2008.TerminalServicesRole.Service.TSGateway | PerformanceCollection | True | False |
| 在终端服务许可证服务器上创建“Terminal Server Computers”本地组或向该组添加终端服务器 | Microsoft.Windows.Server.2008.TerminalServicesRole.Service.TSLicensing.71.4140.4141 | Microsoft.Windows.Server.2008.TerminalServicesRole.Service.TSLicensing | EventCollection | True | True |
| 删除并重新安装 TS 授权角色服务 | Microsoft.Windows.Server.2008.TerminalServicesRole.Service.TSLicensing.EventCollection.12.38 | Microsoft.Windows.Server.2008.TerminalServicesRole.Service.TSLicensing | EventCollection | True | True |
| 终端服务许可证服务器无法检测到本地安装的终端服务客户端访问许可证 (TS CAL),或无法与其他终端服务许可证服务器进行通信 | Microsoft.Windows.Server.2008.TerminalServicesRole.Service.TSLicensing.EventCollection.14 | Microsoft.Windows.Server.2008.TerminalServicesRole.Service.TSLicensing | EventCollection | True | True |
| 购买 TS CAL 并将其安装到许可证服务器上 | Microsoft.Windows.Server.2008.TerminalServicesRole.Service.TSLicensing.EventCollection.20.22 | Microsoft.Windows.Server.2008.TerminalServicesRole.Service.TSLicensing | EventCollection | True | True |
| 终端服务许可证服务器的某种类型的永久终端服务客户端访问许可证没有任何剩余 | Microsoft.Windows.Server.2008.TerminalServicesRole.Service.TSLicensing.EventCollection.21 | Microsoft.Windows.Server.2008.TerminalServicesRole.Service.TSLicensing | EventCollection | True | True |
| 使用电话方法将 TS CAL 重新安装到许可证服务器上 | Microsoft.Windows.Server.2008.TerminalServicesRole.Service.TSLicensing.EventCollection.26 | Microsoft.Windows.Server.2008.TerminalServicesRole.Service.TSLicensing | EventCollection | True | True |
| 密钥包或证书链验证失败 | Microsoft.Windows.Server.2008.TerminalServicesRole.Service.TSLicensing.EventCollection.56.57.58 | Microsoft.Windows.Server.2008.TerminalServicesRole.Service.TSLicensing | EventCollection | True | True |
| 此终端服务许可证服务器太忙或无法通知其他终端服务许可证服务器 | Microsoft.Windows.Server.2008.TerminalServicesRole.Service.TSLicensing.EventCollection.7.15 | Microsoft.Windows.Server.2008.TerminalServicesRole.Service.TSLicensing | EventCollection | True | True |
| 终端服务许可证服务器无法与其他终端服务许可证服务器进行通信 | Microsoft.Windows.Server.2008.TerminalServicesRole.Service.TSLicensing.EventCollection.8.45 | Microsoft.Windows.Server.2008.TerminalServicesRole.Service.TSLicensing | EventCollection | True | True |
| 无法吊销已颁发的终端服务客户端访问许可证 (TS CAL) | Microsoft.Windows.Server.2008.TerminalServicesRole.Service.TSLicensing.EventCollection.81 | Microsoft.Windows.Server.2008.TerminalServicesRole.Service.TSLicensing | EventCollection | True | True |
| TS 会话 Broker 无法删除所有日志文件 | Microsoft.Windows.Server.2008.TerminalServicesRole.Service.TSSessionBroker.EventCollection.1000 | Microsoft.Windows.Server.2008.TerminalServicesRole.Service.TSSessionBroker | EventCollection | True | True |
| TS 会话 Broker 服务未能设置从注册表检索的工作目录 | Microsoft.Windows.Server.2008.TerminalServicesRole.Service.TSSessionBroker.EventCollection.1007 | Microsoft.Windows.Server.2008.TerminalServicesRole.Service.TSSessionBroker | EventCollection | True | True |
| TS 会话 Broker 服务已拒绝来自未经授权的计算机的远程过程调用 (RPC) | Microsoft.Windows.Server.2008.TerminalServicesRole.Service.TSSessionBroker.EventCollection.1016 | Microsoft.Windows.Server.2008.TerminalServicesRole.Service.TSSessionBroker | EventCollection | True | True |
| 收集有关 TS 服务器加入和脱离服务器场的事件 | Microsoft.Windows.Server.2008.TerminalServicesRole.Service.TSSessionBroker.EventCollection.1017.1018 | Microsoft.Windows.Server.2008.TerminalServicesRole.Service.TSSessionBroker | EventCollection | True | False |
| 组是空的 | Microsoft.Windows.Server.2008.TerminalServicesRole.Service.TSSessionBroker.EventCollection.1020 | Microsoft.Windows.Server.2008.TerminalServicesRole.Service.TSSessionBroker | EventCollection | True | True |
| 组不存在 | Microsoft.Windows.Server.2008.TerminalServicesRole.Service.TSSessionBroker.EventCollection.1021 | Microsoft.Windows.Server.2008.TerminalServicesRole.Service.TSSessionBroker | EventCollection | True | True |
| TS 会话 Broker 服务器场处于不一致状态 | Microsoft.Windows.Server.2008.TerminalServicesRole.Service.TSSessionBroker.EventCollection.1023 | Microsoft.Windows.Server.2008.TerminalServicesRole.Service.TSSessionBroker | EventCollection | True | True |
| 没有为 TS Web 访问指定任何终端服务器。 | Microsoft.Windows.Server.2008.TerminalServicesRole.Service.TSWebAccess.EventCollection.6 | Microsoft.Windows.Server.2008.TerminalServicesRole.Service.TSWebAccess | EventCollection | True | True |
| TS Web 访问无法访问终端服务器 | Microsoft.Windows.Server.2008.TerminalServicesRole.Service.TSWebAccess.EventCollection.8 | Microsoft.Windows.Server.2008.TerminalServicesRole.Service.TSWebAccess | EventCollection | True | True |