diff --git a/docs/cwrmm/custom-fields/bsod-evaluation-days.md b/docs/cwrmm/custom-fields/bsod-evaluation-days.md new file mode 100644 index 000000000..4256909ba --- /dev/null +++ b/docs/cwrmm/custom-fields/bsod-evaluation-days.md @@ -0,0 +1,36 @@ +--- +id: '82703d2b-8e7d-4e69-b57b-493977056903' +slug: /82703d2b-8e7d-4e69-b57b-493977056903 +title: 'BSOD_Evaluation_Days' +title_meta: 'BSOD_Evaluation_Days' +keywords: ['BSOD', 'bluescreen', 'crashdump'] +description: 'Number of previous days to check for BSOD-related events in the Windows System event log.' +tags: ['bluescreen', 'alerting', 'application'] +draft: false +unlisted: false +last_update: + date: 2026-07-21 +--- + +## Summary +Number of previous days to check for BSOD-related events in the Windows System event log. Default is 7 days. + +## Details + +| Name | Level | Type | Help Text | Default | Editable | Description | +|----------------------|----------|-----|----------|------------------|----------|---------| +| BSOD_Evaluation_Days | Company | Text | Number of previous days to check for BSOD-related events in the Windows System event log. Default is 7 days. | - | Yes | Number of previous days to check for BSOD-related events in the Windows System event log. Default is 7 days. | + +## Dependencies + +- [Solution: BSOD Monitoring](/docs/fc85a090-94c2-4f91-8055-9c8e52d91ad1) + +## Completed Custom Field + +![Image1](../../../static/img/docs/82703d2b-8e7d-4e69-b57b-493977056903/image1.webp) + +## Changelog + +### 2026-07-21 + +- Initial version of the document \ No newline at end of file diff --git a/docs/cwrmm/custom-fields/bsod-monitoring-enable-endpoint.md b/docs/cwrmm/custom-fields/bsod-monitoring-enable-endpoint.md new file mode 100644 index 000000000..30c54e685 --- /dev/null +++ b/docs/cwrmm/custom-fields/bsod-monitoring-enable-endpoint.md @@ -0,0 +1,36 @@ +--- +id: '8af0cecf-10f6-4ee0-a068-0834df394708' +slug: /8af0cecf-10f6-4ee0-a068-0834df394708 +title: 'BSOD_Monitoring_Enable_Endpoint' +title_meta: 'BSOD_Monitoring_Enable_Endpoint' +keywords: ['BSOD', 'bluescreen', 'crashdump'] +description: 'Enables/disables CPU monitoring for servers at the Endpoint level.' +tags: ['bluescreen', 'alerting', 'application'] +draft: false +unlisted: false +last_update: + date: 2026-07-21 +--- + +## Summarys +Enables/disables CPU monitoring for servers at the Endpoint level. + +## Details + +| Name | Description | Level | Type | Option Type | Options | Help Text | Default Value | Editable | +|---|---|---|---|---|---|---|---|---| +| BSOD_Monitoring_Enable_Endpoint | Enables/disables CPU monitoring at the Endpoint level. | `Endpoint` | `Dropdown` | `string` | `Enable`, `Disable` | Select Enable to turn on monitoring, Disable to exclude. | | `Yes` | + +## Dependencies + +- [Solution: BSOD Monitoring](/docs/fc85a090-94c2-4f91-8055-9c8e52d91ad1) + +## Completed Custom Field + +![Image1](../../../static/img/docs/8af0cecf-10f6-4ee0-a068-0834df394708/image1.webp) + +## Changelog + +### 2026-07-21 + +- Initial version of the document diff --git a/docs/cwrmm/custom-fields/bsod-monitoring-enable-site.md b/docs/cwrmm/custom-fields/bsod-monitoring-enable-site.md new file mode 100644 index 000000000..fd16e4858 --- /dev/null +++ b/docs/cwrmm/custom-fields/bsod-monitoring-enable-site.md @@ -0,0 +1,36 @@ +--- +id: 'eb95e04e-3612-4da6-91d1-815ce2691292' +slug: /eb95e04e-3612-4da6-91d1-815ce2691292 +title: 'BSOD_Monitoring_Enable_Site' +title_meta: 'BSOD_Monitoring_Enable_Site' +keywords: ['BSOD', 'bluescreen', 'crashdump'] +description: 'Enables/Disables BSOD monitoring at the Site level.' +tags: ['bluescreen', 'alerting', 'application'] +draft: false +unlisted: false +last_update: + date: 2026-07-21 +--- + +## Summary +Enables/Disables BSOD monitoring at the Site level. + +## Details + +| Name | Description | Level | Type | Option Type | Options | Help Text | Default Value | Editable | +|---|---|---|---|---|---|---|---|---| +| BSOD_Monitoring_Enable_Site | Enables/Disables BSOD monitoring at the Site level. | `Site` | `Dropdown` | `string` | `Enable`, `Disable` | Enables/Disables BSOD monitoring at the Site level. | | `Yes` | + +## Dependencies + +- [Solution: BSOD Monitoring](/docs/fc85a090-94c2-4f91-8055-9c8e52d91ad1) + +## Completed Custom Field + +![Image1](../../../static/img/docs/eb95e04e-3612-4da6-91d1-815ce2691292/image1.webp) + +## Changelog + +### 2026-07-21 + +- Initial version of the document diff --git a/docs/cwrmm/custom-fields/bsod-monitoring-enable.md b/docs/cwrmm/custom-fields/bsod-monitoring-enable.md new file mode 100644 index 000000000..7a288d4c2 --- /dev/null +++ b/docs/cwrmm/custom-fields/bsod-monitoring-enable.md @@ -0,0 +1,37 @@ +--- +id: '99388b13-3ba3-4cca-990e-d295e30922f1' +slug: /99388b13-3ba3-4cca-990e-d295e30922f1 +title: 'BSOD_Monitoring_Enable' +title_meta: 'BSOD_Monitoring_Enable' +keywords: ['BSOD', 'bluescreen', 'crashdump'] +description: 'Enables/Disables BSOD monitoring at the Company level.' +tags: ['bluescreen', 'alerting', 'application'] +draft: false +unlisted: false +last_update: + date: 2026-07-21 +--- + +## Summary + +Enables/Disables BSOD monitoring at the Company level. + +## Details + +| Name | Description | Level | Type | Option Type | Options | Help Text | Default Value | Editable | +|---|---|---|---|---|---|---|---|---| +| BSOD_Monitoring_Enable | Enables/Disables BSOD monitoring at the Company level. | `Company` | `Dropdown` | `string` | `Enable`, `Disable` | Select Enable to turn on monitoring, Disable to exclude. | `Disable` | `Yes` | + +## Dependencies + +- [Solution: BSOD Monitoring](/docs/fc85a090-94c2-4f91-8055-9c8e52d91ad1) + +## Completed Custom Field + +![Image1](../../../static/img/docs/99388b13-3ba3-4cca-990e-d295e30922f1/image1.webp) + +## Changelog + +### 2026-07-21 + +- Initial version of the document \ No newline at end of file diff --git a/docs/cwrmm/custom-fields/bsod-threshold.md b/docs/cwrmm/custom-fields/bsod-threshold.md new file mode 100644 index 000000000..cdc3e553b --- /dev/null +++ b/docs/cwrmm/custom-fields/bsod-threshold.md @@ -0,0 +1,38 @@ +--- +id: '94877b6f-56ed-4e42-a33c-55ef441e10bf' +slug: /94877b6f-56ed-4e42-a33c-55ef441e10bf +title: 'BSOD_Threshold' +title_meta: 'BSOD_Threshold' +keywords: ['BSOD', 'bluescreen', 'crashdump'] +description: 'Maximum allowed BSOD-related events before triggering an alert.' +tags: ['bluescreen', 'alerting', 'application'] +draft: false +unlisted: false +last_update: + date: 2026-07-21 +--- + +## Summary + +Maximum allowed BSOD-related events before triggering an alert. Default Value is '3'. + +## Details + +| Name | Level | Type | Help Text | Default | Editable | Description | +|----------------------|----------|-----|----------|------------------|----------|---------| +| BSOD_Threshold | Company | Text | Maximum allowed BSOD-related events before triggering an alert. Default Value is '3'. | - | Yes | Maximum allowed BSOD-related events before triggering an alert. Default Value is '3'. | + +## Dependencies + +- [Solution: BSOD Monitoring](/docs/fc85a090-94c2-4f91-8055-9c8e52d91ad1) + +## Completed Custom Field + +![Image1](../../../static/img/docs/94877b6f-56ed-4e42-a33c-55ef441e10bf/image1.webp) + + +## Changelog + +### 2026-07-21 + +- Initial version of the document \ No newline at end of file diff --git a/docs/cwrmm/groups/bsod-monitoring.md b/docs/cwrmm/groups/bsod-monitoring.md new file mode 100644 index 000000000..718010fcf --- /dev/null +++ b/docs/cwrmm/groups/bsod-monitoring.md @@ -0,0 +1,73 @@ +--- +id: '607ed709-2b00-4f6c-a1aa-6d234d0a5c0e' +slug: /607ed709-2b00-4f6c-a1aa-6d234d0a5c0e +title: 'BSOD Monitoring' +title_meta: 'BSOD Monitoring' +keywords: ['BSOD', 'bluescreen', 'crashdump'] +description: 'Contains endpoints with BSOD monitoring enabled based on the configured custom fields.' +tags: ['bluescreen', 'alerting', 'application'] +draft: false +unlisted: false +last_update: + date: 2026-07-21 +--- + +## Summary + +Contains endpoints with BSOD monitoring enabled based on the configured custom fields. Devices in this group are monitored for Blue Screen of Death (BSOD) events. + +## Dependencies + +- [Solution: BSOD Monitoring](/docs/fc85a090-94c2-4f91-8055-9c8e52d91ad1) + +## Group Setup Location + +- **Group Path:** `ENDPOINTS` ➞ `Groups` +- **Group Type:** `Dynamic Group` + +## Group Summary + +- **Group Name:** `BSOD Monitoring` +- **Category:** `Monitoring` +- **Description:** `Contains endpoints with BSOD monitoring enabled based on the configured custom fields. Devices in this group are monitored for Blue Screen of Death (BSOD) events.` + +![Image1](../../../static/img/docs/607ed709-2b00-4f6c-a1aa-6d234d0a5c0e/image1.webp) + +## Criteria + +The group is defined by the following **criteria blocks**, joined by an **OR**. Each block uses **AND** logic between its conditions. + +| Block | Criteria Name | Operator | Value(s) | +|-------|--------------------------|----------------------|------------| +| 1 | BSOD_Monitoring_Enable | Contains any of | `Enable` | +| 1 | BSOD_Monitoring_Enable_Endpoint | Does Not Contain any of | `Disable` | +| 1 | BSOD_Monitoring_Enable_Site | Does Not Contain any of | `Disable` | +| 1 | OS Type | Contains any of | `Windows` | +| 1 | Available | Equal | `True` | +| 2 | BSOD_Monitoring_Enable_Site | Contains any of | `Enable` | +| 2 | BSOD_Monitoring_Enable_Endpoint | Does Not Contain any of | `Disable` | +| 2 | OS Type | Contains any of | `Windows` | +| 2 | Available | Equal | `True` | +| 3 | BSOD_Monitoring_Enable_Endpoint | Contains any of | `Enable` | +| 3 | OS Type | Contains any of | `Windows` | +| 3 | Available | Equal | `True` | + +- **Block 1:** Targets Windows machines where the monitoring is enabled at Company level. Custom field (**BSOD_Monitoring_Enable**) is enabled, provided that the feature has not been explicitly disabled at the site level (**BSOD_Monitoring_Enable_Site**) or the individual endpoint level (**BSOD_Monitoring_Enable_Endpoint**). +- **Block 2:** Targets Windows Machines where the site‑level setting (**BSOD_Monitoring_Enable_Site**) is explicitly enabled, provided that it has not been overridden and disabled at the individual endpoint level (**BSOD_Monitoring_Enable_Endpoint**). +- **Block 3:** Targets **Any Windows Device** (Server or Workstation) where the feature is explicitly enabled directly at the individual endpoint level (**BSOD_Monitoring_Enable_Endpoint**). + + +**Logic:** +A machine matches the group if it meets **ALL** criteria in **Block 1**, **OR** **ALL** criteria in **Block 2**, **OR** **ALL** criteria in **Block 3**. + +![Image2](../../../static/img/docs/607ed709-2b00-4f6c-a1aa-6d234d0a5c0e/image2.webp) + +## Completed Group + +![Image3](../../../static/img/docs/607ed709-2b00-4f6c-a1aa-6d234d0a5c0e/image3.webp) + +## Changelog + +### 2026-07-21 + +- Initial version of the document diff --git a/docs/cwrmm/monitors/bsod-monitoring.md b/docs/cwrmm/monitors/bsod-monitoring.md new file mode 100644 index 000000000..72054a793 --- /dev/null +++ b/docs/cwrmm/monitors/bsod-monitoring.md @@ -0,0 +1,201 @@ +--- +id: 'e239e458-56e6-4859-ab30-a7592366b824' +slug: /e239e458-56e6-4859-ab30-a7592366b824 +title: 'BSOD Monitoring' +title_meta: 'BSOD Monitoring' +keywords: ['BSOD', 'bluescreen', 'crashdump'] +description: 'checks the Windows System event log for BSOD-related events (Event IDs 41, 1001, and 6008) within the configured monitoring period.' +tags: ['bluescreen', 'alerting', 'application'] +draft: false +unlisted: false +last_update: + date: 2026-07-21 +--- + +## Summary + +Reads the BSOD monitoring configuration from the local JSON file created by the BSOD Monitoring Configuration Writer task. It checks the Windows System event log for BSOD-related events (Event IDs 41, 1001, and 6008) within the configured monitoring period. If the number of detected events exceeds the configured threshold, the monitor reports a failure; otherwise, it returns a healthy status. + +### How It Works + +1. **Configuration File** + At each check interval, the monitor reads the file `C:\ProgramData\_Automation\Script\BSODMonitoring\BSODMonitoring.json`. This file contains two values: + + * **Threshold** – the maximum number of BSOD-related events allowed before an alert is generated. + * **Days** – the number of previous days to search the Windows System event log. + +2. **BSOD Event Monitoring** + The monitor scans the Windows **System** event log for the following BSOD-related events within the configured time period: + + * **Event ID 41** – Kernel-Power (unexpected shutdown or restart). + * **Event ID 1001** – BugCheck (Blue Screen of Death). + * **Event ID 6008** – Unexpected shutdown. + +3. **Threshold Evaluation** + The total number of matching events is compared against the configured **Threshold**. + + * **If the event count exceeds the threshold:** The monitor generates a failure. + * **If the event count is within the threshold:** The monitor reports a healthy status. + +4. **Alert & Resolution** + When a failure occurs, the monitor outputs the number of BSOD-related events detected during the configured monitoring period. Once the event count falls back within the configured threshold, the monitor returns a healthy status, allowing the monitor set to automatically resolve the alert if automatic resolution is enabled. + + +## Dependencies + +- [Solution: BSOD Monitoring](/docs/fc85a090-94c2-4f91-8055-9c8e52d91ad1) +- [Task : BSOD Monitoring Configuration Writer](/docs/21f7afea-94a7-4bd9-b46f-7f8a20819eb7) + +## Monitor Setup Location + +**Monitors Path:** `ENDPOINTS` ➞ `Alerts` ➞ `Monitors` + +## Monitor Summary + +- **Name:** `BSOD Monitoring` +- **Description:** `Reads the BSOD monitoring configuration from the local JSON file created by the BSOD Monitoring Configuration Writer task. It checks the Windows System event log for BSOD-related events (Event IDs 41, 1001, and 6008) within the configured monitoring period. If the number of detected events exceeds the configured threshold, the monitor reports a failure; otherwise, it returns a healthy status.` +- **Type:** `Script` +- **Severity:** `Others` +- **Family:** `Desktop Health` + +![Image1](../../../static/img/docs/e239e458-56e6-4859-ab30-a7592366b824/image1.webp) + +## Targeted Resources + +- **Target Type:** `Device Groups` +- **Group Name:** `[Group : BSOD Monitoring](/docs/607ed709-2b00-4f6c-a1aa-6d234d0a5c0e)` + +![Image2](../../../static/img/docs/e239e458-56e6-4859-ab30-a7592366b824/image2.webp) + +## Conditions + +- **Run script on:** `Schedule` +- **Repeat every:** `24` `Hour(s)` +- **Script Language:** `PowerShell` +- **Use Generative AI Assist for script creation:** `False` + +- **PowerShell Script Editor:** + +```PowerShell +<# +.SYNOPSIS + Monitors BSOD-related system events against the configured threshold and monitoring period. + +.DESCRIPTION + This script is executed periodically by a monitor set. It reads BSOD monitoring values + from the local JSON configuration file placed by the BSOD Monitoring Configuration Writer task. + + The configuration file contains the following settings: + Threshold: + Defines the maximum number of BSOD-related events allowed within the configured + monitoring period. If the event count exceeds this value, the monitor reports a failure. + Days: + Defines the number of previous days to check for BSOD-related events in the Windows + System event log. + + The script checks the Windows System event log for the following BSOD-related events: + - Event ID 41: + Kernel-Power event indicating an unexpected system shutdown or restart. + - Event ID 1001: + BugCheck event generated when the system encounters a Blue Screen of Death (BSOD). + - Event ID 6008: + Unexpected shutdown event indicating the previous system shutdown was not clean. + + If the number of detected events exceeds the configured threshold within the defined number + of days, the script generates a failure output with the event count. + + If the number of detected events is within the configured threshold, the script returns a + healthy status message. + +.NOTES + Script Name = BSOD Monitoring + Configuration = $env:ProgramData\_Automation\Script\BSODMonitoring\BSODMonitoring.json + Configuration Values: + Threshold = Maximum allowed BSOD-related events before triggering an alert. + Days = Number of previous days to evaluate BSOD-related events. + Monitored Log = Windows System Event Log + Event IDs = 41, 1001, 6008 + +.OUTPUTS + - On alert: + FAIL - Found BSOD-related events (Event IDs: 41, 1001, 6008) in the last days. + - On healthy state: + PASS - Found BSOD-related events (Event IDs: 41, 1001, 6008) in the last days. +#> + +#region globals +$ProgressPreference = 'SilentlyContinue' +$WarningPreference = 'SilentlyContinue' +#endregion + +#region variables +$projectName = 'BSODMonitoring' +$workingDirectory = '{0}\_Automation\Script\{1}' -f $env:ProgramData, $projectName +$configPath = '{0}\{1}.json' -f $workingDirectory, $projectName +#endregion + +#region config import +if (-not (Test-Path -Path $configPath)) { + return 'BSOD monitoring configuration file not found. Skipping check.' +} + +try { + $rawJson = Get-Content -Path $configPath -Raw -Encoding UTF8 -ErrorAction Stop + $config = $rawJson | ConvertFrom-Json -ErrorAction Stop +} catch { + return ('Failed to read or parse the configuration file. Error: {0}' -f $Error[0].Exception.Message) +} + +[int]$Threshold = $config.Threshold +[int]$Days= $config.Days +#endregion + +$Count = (Get-WinEvent -FilterHashtable @{ + LogName = 'System' + Id = 41,1001,6008 + StartTime = (Get-Date).AddDays(-$Days) +} -ErrorAction SilentlyContinue).Count + +if ($Count -gt $Threshold) { + write-output "FAIL - Found $Count BSOD-related events (Event IDs: 41, 1001, 6008) in the last $Days days." + exit 1 +} +else { + write-output "PASS - Found $Count BSOD-related events (Event IDs: 41, 1001, 6008) in the last $Days days." + exit 0 +} +``` + +- **Criteria:** `Contains` +- **Operator:** `AND` +- **Script Output:** `Fail - Found` +- **Escalate ticket on script failure:** `Disabled` +- **Add Automation:** `` + +![Image3](../../../static/img/docs/e239e458-56e6-4859-ab30-a7592366b824/image3.webp) + +## Ticket Resolution + +- **Automatically Resolve:** `Enabled` +- **Dropdown Option:** `Run same script as above` +- **Criteria:** `Contain` +- **Operator:** `AND` +- **Script Output:** `PASS - Found` + +![Image4](../../../static/img/docs/e239e458-56e6-4859-ab30-a7592366b824/image4.webp) + +## Monitor Output + +**Output:** `Generate Ticket` + +![Image5](../../../static/img/docs/e239e458-56e6-4859-ab30-a7592366b824/image5.webp) + +## Completed Monitor + +![Image6](../../../static/img/docs/e239e458-56e6-4859-ab30-a7592366b824/image6.webp) + +## Changelog + +### 2026-07-21 + +- Initial version of the document \ No newline at end of file diff --git a/docs/cwrmm/tasks/bsod-monitoring-configuration-writer.md b/docs/cwrmm/tasks/bsod-monitoring-configuration-writer.md new file mode 100644 index 000000000..51748b903 --- /dev/null +++ b/docs/cwrmm/tasks/bsod-monitoring-configuration-writer.md @@ -0,0 +1,340 @@ +--- +id: '21f7afea-94a7-4bd9-b46f-7f8a20819eb7' +slug: /21f7afea-94a7-4bd9-b46f-7f8a20819eb7 +title: 'BSOD Monitoring Configuration Writer' +title_meta: 'BSOD Monitoring Configuration Writer' +keywords: ['BSOD', 'bluescreen', 'crashdump'] +description: 'Creates and maintains the JSON configuration file used by the BSOD Monitoring monitor.' +tags: ['bluescreen', 'alerting', 'application'] +draft: false +unlisted: false +last_update: + date: 2026-07-21 +--- + + +## Summary + +Creates and maintains the JSON configuration file used by [Monitor : BSOD Monitoring](/docs/e239e458-56e6-4859-ab30-a7592366b824). The script applies hierarchical RMM variable overrides to define the BSOD event threshold and monitoring period. The actual BSOD detection and alerting logic is performed by an external monitor set that reads and evaluates this configuration file. + +### How It Works + +1. **CW RMM Variable Evaluation** + The script reads the BSOD monitoring settings from the configured CW RMM client-level variables: + + * **ClientThreshold** – Maximum number of BSOD-related events allowed before an alert is triggered. + * **ClientEvaluationDays** – Number of previous days to evaluate for BSOD-related events. + + If either variable is missing or contains an invalid value, the script falls back to the built-in defaults. + +2. **Default Values** + When no valid CW RMM variables are configured, the following defaults are applied: + + * **Threshold** = `3` + * **Days** = `7` + +3. **Configuration File Generation** + The resolved values are written to the following JSON configuration file: + + ```PlainText + C:\ProgramData\_Automation\Script\BSODMonitoring\BSODMonitoring.json + ``` + + The file contains two values: + + * **Threshold** – Maximum number of BSOD-related events allowed before an alert is generated. + * **Days** – Number of previous days to search the Windows System event log for BSOD-related events. + +### Sample Scenario 1: Using Default Values + +No CW RMM variables are configured. The script uses the built-in defaults and generates the following configuration file: + +```json +{ + "Threshold": 3, + "Days": 7 +} +``` + +### Sample Scenario 2: Using CW RMM Variable Overrides + +The administrator configures the following CW RMM variables: + +* `ClientThreshold` = `5` +* `ClientEvaluationDays` = `14` + +The generated configuration file becomes: + +```json +{ + "Threshold": 5, + "Days": 14 +} +``` + +### Ticketing & Alerting Behavior + +* A separate **BSOD Monitoring** monitor reads the configuration file and periodically scans the Windows **System** event log. +* The monitor counts BSOD-related events (**Event IDs 41, 1001, and 6008**) that occurred within the configured number of days. +* If the number of events exceeds the configured **Threshold**, the monitor reports a failure and generates an alert. +* Once the event count falls back within the configured threshold, the monitor returns to a healthy state. If automatic resolution is enabled in the monitor set, the associated alert or ticket is resolved automatically. + +## Sample Run + +![Image2](../../../static/img/docs/21f7afea-94a7-4bd9-b46f-7f8a20819eb7/image1.webp) + +## Dependencies + +- [Custom Field: BSOD_Evaluation_Days](/docs/82703d2b-8e7d-4e69-b57b-493977056903) +- [Custom Field: BSOD_Threshold](/docs/94877b6f-56ed-4e42-a33c-55ef441e10bf) +- [Solution: BSOD Monitoring](/docs/fc85a090-94c2-4f91-8055-9c8e52d91ad1) + +## Custom Fields + +The following table lists all custom fields used by the to determine the BSOD Monitoring. The `Enable` fields are not listed here; they are used exclusively by the automation group to decide whether the script runs at all. + +| Name | Level | Type | Help Text | Default | Editable | Description | +|----------------------|----------|-----|----------|------------------|----------|---------| +| [Custom Field: BSOD_Evaluation_Days](/docs/82703d2b-8e7d-4e69-b57b-493977056903) | Company | Text | Number of previous days to check for BSOD-related events in the Windows System event log. Default is 7 days. | - | Yes | Number of previous days to check for BSOD-related events in the Windows System event log. Default is 7 days. | +| [Custom Field: BSOD_Threshold](/docs/94877b6f-56ed-4e42-a33c-55ef441e10bf) | Company | Text | Maximum allowed BSOD-related events before triggering an alert. Default Value is '3'. | - | Yes | Maximum allowed BSOD-related events before triggering an alert. Default Value is '3'. | + +--- + +![Image2](../../../static/img/docs/21f7afea-94a7-4bd9-b46f-7f8a20819eb7/image2.webp) + +## Task Setup Path + +- **Tasks Path:** `AUTOMATION` ➞ `Tasks` +- **Task Type:** `Script Editor` + +## Task Creation + +### **Description** + +- **Name:** `BSOD Monitoring Configuration Writer` +- **Description:** `Creates and maintains the JSON configuration file used by the BSOD Monitoring monitor. The script applies hierarchical RMM variable overrides to define the BSOD event threshold and monitoring period. The actual BSOD detection and alerting logic is performed by an external monitor set that reads and evaluates this configuration file.` +- **Category:** `Monitoring` + +![Image3](../../../static/img/docs/21f7afea-94a7-4bd9-b46f-7f8a20819eb7/image3.webp) + +### **Script Editor** + +#### **Row 1 Function: Set Pre-defined Variable ( @ClientThreshold@ = BSOD_Threshold)** + +- **Notes:** `ClientThreshold` +- **Continue on Failure:** `False` +- **Operating System:** `Windows` +- **Variable Name:** `ClientThreshold` +- **Custom Field:** `BSOD_Threshold` + +![Image4](../../../static/img/docs/21f7afea-94a7-4bd9-b46f-7f8a20819eb7/image4.webp) + +#### **Row 2 Function: Set Pre-defined Variable ( @ClientEvaluationDays@ = BSOD_Evaluation_Days)** + +- **Notes:** `ClientEvaluationDays` +- **Continue on Failure:** `False` +- **Operating System:** `Windows` +- **Variable Name:** `ClientEvaluationDays` +- **Custom Field:** `BSOD_Evaluation_Days` + +![Image5](../../../static/img/docs/21f7afea-94a7-4bd9-b46f-7f8a20819eb7/image5.webp) + +#### **Row 3 Function: PowerShell script** + +- **Notes:** `` +- **Use Generative AI Assist for script creation:** `False` +- **Expected time of script execution in seconds:** `300` +- **Continue on Failure:** `False` +- **Run As:** `System` +- **Operating System:** `Windows` +- **PowerShell Script Editor:** + +```PowerShell +<# +.SYNOPSIS + Creates the BSOD Monitoring configuration file with threshold and monitoring period values. + Designed to be run by the 'BSOD Monitoring Configuration Writer' task in CW RMM. + +.DESCRIPTION + This script creates and maintains the local configuration file used by the BSOD Monitoring + monitor script. + + The script retrieves threshold values from CW RMM client-level variables and applies them + using a hierarchical override approach. If valid RMM variables are not available, hardcoded + workstation defaults are applied. + + Configuration values: + Threshold: + Defines the maximum number of BSOD-related events allowed before triggering an alert. + If the number of detected BSOD events exceeds this value, the BSOD Monitoring script + reports a failure condition. + + Days: + Defines the number of previous days to evaluate when checking the Windows System event + log for BSOD-related events. + + The script creates the working directory if it does not exist and writes the configuration + values into a JSON file consumed by the BSOD Monitoring monitor. + + The monitored BSOD events include: + - Event ID 41: + Kernel-Power event indicating an unexpected system shutdown or restart. + - Event ID 1001: + BugCheck event generated during a Blue Screen of Death (BSOD). + - Event ID 6008: + Unexpected shutdown event indicating the previous shutdown was not clean. + +.NOTES + Script Name = BSOD Monitoring Configuration Writer + Configuration = $env:ProgramData\_Automation\Script\BSODMonitoring\BSODMonitoring.json + RMM Variables: + clientLevelDays: + Client-level override value for the number of days to check for BSOD events. + clientLevelThreshold: + Client-level override value for the maximum allowed BSOD events. + + Default Values: + Days = 7 + Threshold = 3 + + Configuration Output: + Threshold = Maximum allowed BSOD-related events before triggering an alert. + Days = Number of previous days used for BSOD event evaluation. + +.OUTPUTS + - On successful configuration creation: + Configuration file '' written successfully. + + Configuration: + Threshold = + Days = + + - On failure: + Throws an error if the working directory or configuration file cannot be created. +#> + +#region globals +$ProgressPreference = 'SilentlyContinue' +$WarningPreference = 'SilentlyContinue' +#endregion + +#region variables +$projectName = 'BSODMonitoring' +$workingDirectory = '{0}\_Automation\Script\{1}' -f $env:ProgramData, $projectName +$configFilePath = '{0}\{1}.json' -f $workingDirectory, $projectName +#endregion + +#region rmm variables +$clientLevelDays = '@ClientEvaluationDays@' +$clientLevelThreshold = '@ClientThreshold@' +#endregion + +# Hard defaults if nothing is configured +$defaultDays = 7 +$defaultThreshold = 3 +#endregion + +#region set thresholds based on rmm variables +[int]$Days = if ( + -not [string]::IsNullOrEmpty($clientLevelDays) -and + $clientLevelDays -notmatch 'ClientEvaluationDays' -and + $clientLevelDays -match '^\d+$' +) { + [int]$clientLevelDays +} else { + $defaultDays +} + +[int]$Threshold = if ( + -not [string]::IsNullOrEmpty($clientLevelThreshold) -and + $clientLevelThreshold -notmatch 'ClientThreshold' -and + $clientLevelThreshold -match '^\d+$' +) { + [int]$clientLevelThreshold +} else { + $defaultThreshold +} + +#region working directory +if (-not (Test-Path -Path $workingDirectory)) { + try { + New-Item -Path $workingDirectory -ItemType 'Directory' -Force -ErrorAction Stop | Out-Null + } catch { + throw ('Failed to create the working directory {2}{0}{2}. Error: {1}' -f $workingDirectory, $Error[0].Exception.Message, [char]34) + } +} +#endregion + +#region config file +$config = @{ + Threshold = $Threshold + Days = $Days +} +try { + $config | ConvertTo-Json -Depth 3 | Set-Content -Path $configFilePath -Force -Encoding 'UTF8' -ErrorAction Stop +} catch { + throw ('Failed to write the configuration file {2}{0}{2}. Error: {1}' -f $configFilePath, $Error[0].Exception.Message, [char]34) +} + +return ('Configuration file ''{0}'' written successfully.{1}{1}Configuration:{1}{2}' -f $configFilePath, [System.Environment]::NewLine, ($config | Out-String)) +#endregion +``` + +![Image6](../../../static/img/docs/21f7afea-94a7-4bd9-b46f-7f8a20819eb7/image6.webp) + +#### **Row 4 Function: Script Log** + +- **Notes:** `` +- **Continue on Failure:** `False` +- **Operating System:** `Windows` +- **Script Log Message:** `%Output%` + +![Image7](../../../static/img/docs/21f7afea-94a7-4bd9-b46f-7f8a20819eb7/image7.webp) + +## Completed Script + +![Image8](../../../static/img/docs/21f7afea-94a7-4bd9-b46f-7f8a20819eb7/image8.webp) + +## Output + +- Script Log +- JSON File at `C:\ProgramData\_Automation\Script\BSODMonitoring\BSODMonitoring.json` + +## Schedule Task + +### Task Details + +- **Name:** `BSOD Monitoring Configuration Writer` +- **Description:** `Creates and maintains the JSON configuration file used by the BSOD Monitoring monitor. The script applies hierarchical RMM variable overrides to define the BSOD event threshold and monitoring period. The actual BSOD detection and alerting logic is performed by an external monitor set that reads and evaluates this configuration file.` +- **Category:** `Monitoring` + +![Image3](../../../static/img/docs/21f7afea-94a7-4bd9-b46f-7f8a20819eb7/image3.webp) + +### Schedule + +- **Schedule Type:** `Schedule` +- **Timezone:** `Local Machine Time` +- **Start:** `` +- **Trigger:** `Time` `At` `` +- **Recurrence:** `Every day` +- **Execute at next agent check-in:** `True` +- **Stop After:** `22` +- **Unit:** `Hour(s)` + +![Image9](../../../static/img/docs/21f7afea-94a7-4bd9-b46f-7f8a20819eb7/image9.webp) + +### Targeted Resource + +**Device Group:** `BSOD Monitoring` + +![Image10](../../../static/img/docs/21f7afea-94a7-4bd9-b46f-7f8a20819eb7/image10.webp) + +### Completed Scheduled Task + +![Image11](../../../static/img/docs/21f7afea-94a7-4bd9-b46f-7f8a20819eb7/image11.webp) + +## Changelog + +### 2026-07-21 + +- Initial version of the document diff --git a/docs/solutions/bsod-monitoring-cw-rmm.md b/docs/solutions/bsod-monitoring-cw-rmm.md new file mode 100644 index 000000000..47acd0506 --- /dev/null +++ b/docs/solutions/bsod-monitoring-cw-rmm.md @@ -0,0 +1,187 @@ +--- +id: 'fc85a090-94c2-4f91-8055-9c8e52d91ad1' +slug: /fc85a090-94c2-4f91-8055-9c8e52d91ad1 +title: 'BSOD Monitoring' +title_meta: 'BSOD Monitoring' +keywords: ['BSOD', 'bluescreen', 'crashdump'] +description: 'Monitors Windows endpoints for Blue Screen of Death (BSOD) related events by periodically scanning the Windows System event logs.' +tags: ['bluescreen', 'alerting', 'application'] +draft: false +unlisted: false +last_update: + date: 2026-07-21 +--- + +## Purpose + +The BSOD Monitoring solution monitors Windows endpoints for Blue Screen of Death (BSOD) related events by periodically scanning the Windows System event log. It generates an alert only when the number of BSOD-related events exceeds a configurable threshold within a specified monitoring period. + +The solution consists of two components: + - A **Configuration Writer** task that creates a local JSON configuration file containing the monitoring settings. + - A **Monitor** that periodically reads the configuration file, checks the Windows System event log, and generates alerts when the configured threshold is exceeded. + +This approach allows monitoring policies to be managed centrally through CW RMM variables without modifying the monitoring script. + +### Key Capabilities + +1. **Configurable Threshold** + Configure the maximum number of BSOD-related events that are allowed before an alert is generated. + +2. **Configurable Monitoring Period** + Define the number of previous days that the monitor searches the Windows **System** event log for BSOD-related events. + +3. **Centralized Configuration** + Monitoring settings are stored in a local JSON configuration file generated by the **BSOD Monitoring Configuration Writer** task. This allows threshold changes to be managed through CW RMM variables without modifying the monitor script. + +4. **Automatic Recovery** + When the number of detected BSOD-related events falls back within the configured threshold, the monitor reports a healthy state. If automatic resolution is enabled in the monitor set, the associated alert or ticket is resolved automatically. + +### Important Caveats & Behavior + +1. **Configuration Updates** + Changes to the CW RMM variables are not applied until the **BSOD Monitoring Configuration Writer** task runs again. Running the task manually updates the configuration immediately. + +2. **Monitor Execution** + The monitor reads the local configuration file each time it runs and evaluates the Windows **System** event log using the configured settings. + +3. **Monitored Events** + The monitor searches the Windows **System** event log for the following BSOD-related events: + + * **Event ID 41** – Kernel-Power (unexpected shutdown or restart). + * **Event ID 1001** – BugCheck (Blue Screen of Death). + * **Event ID 6008** – Unexpected shutdown. + +4. **Automatic Resolution** + Once the number of detected BSOD-related events falls back within the configured threshold, the monitor returns a healthy state. If automatic resolution is enabled, the associated alert or ticket is resolved automatically. + +## Associated Content + +### Group + +| Name | Purpose | +| ------------------- | -------------------------------------------------------------------- | +| [BSOD Monitoring](/docs/607ed709-2b00-4f6c-a1aa-6d234d0a5c0e) | Dynamic group containing endpoints where BSOD monitoring is enabled. | + +### Task + +| Name | Purpose | +| ---------------------------------------- | --------------------------------------------------------------------------------------------------------- | +| [BSOD Monitoring Configuration Writer](/docs/21f7afea-94a7-4bd9-b46f-7f8a20819eb7) | Creates the local JSON configuration file containing the BSOD monitoring threshold and monitoring period. | + +### Monitor + +| Name | Purpose | +| ---------------------------------------- | --------------------------------------------------------------------------------------------------------- | +| [BSOD Monitoring](/docs/e239e458-56e6-4859-ab30-a7592366b824) | Reads the configuration file, scans the Windows System event log for BSOD-related events, and generates alerts when the configured threshold is exceeded. | + +### Custom Fields + +| Name | Level | Type | Purpose | +|---|---|---|---| +| [BSOD_Evaluation_Days](/docs/82703d2b-8e7d-4e69-b57b-493977056903) | Company | Text | Number of previous days to check for BSOD-related events in the Windows System event log. Default is 7 days. | +| [BSOD_Threshold](/docs/94877b6f-56ed-4e42-a33c-55ef441e10bf) | Company | Text | Maximum allowed BSOD-related events before triggering an alert. Default Value is '3'. | +| [BSOD_Monitoring_Enable](/docs/99388b13-3ba3-4cca-990e-d295e30922f1) | Company | Drop-Down | Enables/disables BSOD monitoring at the Company level. | +| [BSOD_Monitoring_Enable_Site](/docs/eb95e04e-3612-4da6-91d1-815ce2691292) | Site | Drop-Down | Enables/disables BSOD monitoring at the Site level. | +| [BSOD_Monitoring_Enable_Endpoint](/docs/8af0cecf-10f6-4ee0-a068-0834df394708) | Endpoint | Drop-Down |Enables/disables CPU monitoring for servers at the Endpoint level. | + +## Implementation + + +### Step 1: Create the Following Custom Fields + +Create all the custom fields listed below in ConnectWise RMM. These are required for the solution to function correctly. +- [BSOD_Evaluation_Days](/docs/82703d2b-8e7d-4e69-b57b-493977056903) +- [BSOD_Threshold](/docs/94877b6f-56ed-4e42-a33c-55ef441e10bf) +- [BSOD_Monitoring_Enable](/docs/99388b13-3ba3-4cca-990e-d295e30922f1) +- [BSOD_Monitoring_Enable_Site](/docs/eb95e04e-3612-4da6-91d1-815ce2691292) +- [BSOD_Monitoring_Enable_Endpoint](/docs/8af0cecf-10f6-4ee0-a068-0834df394708) + +### Step 2: Create the Group + +Create the dynamic group that will automatically target the enabled machines. + +- [BSOD Monitoring](/docs/607ed709-2b00-4f6c-a1aa-6d234d0a5c0e) + +### Step 3: Create the Configuration Writer Task + +Set up the configuration writer script that will run on the targeted endpoints. + +- [BSOD Monitoring Configuration Writer](/docs/21f7afea-94a7-4bd9-b46f-7f8a20819eb7) + +### Step 4: Create the Monitor + +Set up the monitor that will evaluate CPU usage against the configuration file. + +- [BSOD Monitoring](/docs/e239e458-56e6-4859-ab30-a7592366b824) + + +### Step 5: Schedule the Configuration Writer + +Schedule the [Task : BSOD Monitoring Configuration Writer](/docs/21f7afea-94a7-4bd9-b46f-7f8a20819eb7) to run once per day against the [Group : BSOD Monitoring](/docs/607ed709-2b00-4f6c-a1aa-6d234d0a5c0e), as described in the [Schedule Task](/docs/21f7afea-94a7-4bd9-b46f-7f8a20819eb7#schedule-task) section of the task's document. + + +The monitor can run independently at your preferred monitoring interval. + +### Step 6: Review and Set Threshold Custom Fields + +Review the default values and set the [Custom Field: BSOD_Evaluation_Days](/docs/82703d2b-8e7d-4e69-b57b-493977056903) and [Custom Field: BSOD_Threshold](/docs/94877b6f-56ed-4e42-a33c-55ef441e10bf) as required for your environments. Or could also use the default values. + +### Step 7: Review and Set Enablement Custom Fields + +Set the enablement custom fields ([BSOD_Monitoring_Enable](/docs/99388b13-3ba3-4cca-990e-d295e30922f1), [BSOD_Monitoring_Enable_Site](/docs/eb95e04e-3612-4da6-91d1-815ce2691292), [BSOD_Monitoring_Enable_Endpoint](/docs/8af0cecf-10f6-4ee0-a068-0834df394708)) to `Enable` for the client, location, or specific endpoint to turn the solution and monitoring on for them. Machines will not be monitored until they are explicitly enabled via these dropdown fields. + + +## FAQ + +### Q: How does the BSOD Monitoring solution work? + +> The [Task : BSOD Monitoring Configuration Writer](/docs/21f7afea-94a7-4bd9-b46f-7f8a20819eb7) creates a local JSON configuration file containing the monitoring threshold and evaluation period. The [Monitor : BSOD Monitoring](/docs/e239e458-56e6-4859-ab30-a7592366b824) monitor reads this file, scans the Windows **System** event log for Event IDs **41**, **1001**, and **6008**, counts the matching events within the configured number of days, and compares the total against the configured threshold. + +### Q: What are the default monitoring values? + +> If no valid CW RMM variables are configured, the solution uses the following defaults: +> - **Threshold:** 3 events +> - **Evaluation Period:** 7 days + +### Q: I changed the CW RMM variables. When will the new values take effect? + +> The updated values are applied the next time the [Task : BSOD Monitoring Configuration Writer](/docs/21f7afea-94a7-4bd9-b46f-7f8a20819eb7) runs. You can also execute the task manually to update the configuration immediately. + + +### Q: Which Windows events are monitored? + +> The monitor searches the Windows **System** event log for the following BSOD-related events: +> - **Event ID 41** – Kernel-Power (unexpected shutdown or restart) +> - **Event ID 1001** – BugCheck (Blue Screen of Death) +> - **Event ID 6008** – Unexpected Shutdown + + +### Q: When is an alert generated? + +> An alert is generated when the number of detected BSOD-related events within the configured evaluation period exceeds the configured **Threshold**. + +### Q: Will alerts resolve automatically? + +> Yes. When the number of detected BSOD-related events falls back within the configured threshold, the monitor reports a healthy state. If automatic resolution is enabled in the monitor set, the associated alert or ticket is resolved automatically. + + +### Q: The monitor reports "Configuration file not found." What should I do? + +> This indicates that the **BSOD Monitoring Configuration Writer** task has not yet run on the endpoint or the configuration file has been removed. Run the task manually or wait for its next scheduled execution. + + +### Q: Can I modify the JSON configuration file manually? + +> Manual changes are temporary and will be overwritten the next time the [Task : BSOD Monitoring Configuration Writer](/docs/21f7afea-94a7-4bd9-b46f-7f8a20819eb7) runs. Always update the CW RMM variables instead of editing the configuration file directly. + + +### Q: What information does the monitor output contain? + +> The monitor reports the total number of BSOD-related events detected, the monitored Event IDs (**41**, **1001**, and **6008**), and the configured evaluation period. + + +## Changelog + +### 2026-07-21 + +- Initial version of the document \ No newline at end of file diff --git a/static/img/docs/21f7afea-94a7-4bd9-b46f-7f8a20819eb7/image1.webp b/static/img/docs/21f7afea-94a7-4bd9-b46f-7f8a20819eb7/image1.webp new file mode 100644 index 000000000..0ad0b3deb Binary files /dev/null and b/static/img/docs/21f7afea-94a7-4bd9-b46f-7f8a20819eb7/image1.webp differ diff --git a/static/img/docs/21f7afea-94a7-4bd9-b46f-7f8a20819eb7/image10.webp b/static/img/docs/21f7afea-94a7-4bd9-b46f-7f8a20819eb7/image10.webp new file mode 100644 index 000000000..518319bc3 Binary files /dev/null and b/static/img/docs/21f7afea-94a7-4bd9-b46f-7f8a20819eb7/image10.webp differ diff --git a/static/img/docs/21f7afea-94a7-4bd9-b46f-7f8a20819eb7/image11.webp b/static/img/docs/21f7afea-94a7-4bd9-b46f-7f8a20819eb7/image11.webp new file mode 100644 index 000000000..0037e93dc Binary files /dev/null and b/static/img/docs/21f7afea-94a7-4bd9-b46f-7f8a20819eb7/image11.webp differ diff --git a/static/img/docs/21f7afea-94a7-4bd9-b46f-7f8a20819eb7/image2.webp b/static/img/docs/21f7afea-94a7-4bd9-b46f-7f8a20819eb7/image2.webp new file mode 100644 index 000000000..22988a159 Binary files /dev/null and b/static/img/docs/21f7afea-94a7-4bd9-b46f-7f8a20819eb7/image2.webp differ diff --git a/static/img/docs/21f7afea-94a7-4bd9-b46f-7f8a20819eb7/image3.webp b/static/img/docs/21f7afea-94a7-4bd9-b46f-7f8a20819eb7/image3.webp new file mode 100644 index 000000000..3efb21dc0 Binary files /dev/null and b/static/img/docs/21f7afea-94a7-4bd9-b46f-7f8a20819eb7/image3.webp differ diff --git a/static/img/docs/21f7afea-94a7-4bd9-b46f-7f8a20819eb7/image4.webp b/static/img/docs/21f7afea-94a7-4bd9-b46f-7f8a20819eb7/image4.webp new file mode 100644 index 000000000..717960e7b Binary files /dev/null and b/static/img/docs/21f7afea-94a7-4bd9-b46f-7f8a20819eb7/image4.webp differ diff --git a/static/img/docs/21f7afea-94a7-4bd9-b46f-7f8a20819eb7/image5.webp b/static/img/docs/21f7afea-94a7-4bd9-b46f-7f8a20819eb7/image5.webp new file mode 100644 index 000000000..1b46e73c5 Binary files /dev/null and b/static/img/docs/21f7afea-94a7-4bd9-b46f-7f8a20819eb7/image5.webp differ diff --git a/static/img/docs/21f7afea-94a7-4bd9-b46f-7f8a20819eb7/image6.webp b/static/img/docs/21f7afea-94a7-4bd9-b46f-7f8a20819eb7/image6.webp new file mode 100644 index 000000000..6002bf27d Binary files /dev/null and b/static/img/docs/21f7afea-94a7-4bd9-b46f-7f8a20819eb7/image6.webp differ diff --git a/static/img/docs/21f7afea-94a7-4bd9-b46f-7f8a20819eb7/image7.webp b/static/img/docs/21f7afea-94a7-4bd9-b46f-7f8a20819eb7/image7.webp new file mode 100644 index 000000000..1341d6acf Binary files /dev/null and b/static/img/docs/21f7afea-94a7-4bd9-b46f-7f8a20819eb7/image7.webp differ diff --git a/static/img/docs/21f7afea-94a7-4bd9-b46f-7f8a20819eb7/image8.webp b/static/img/docs/21f7afea-94a7-4bd9-b46f-7f8a20819eb7/image8.webp new file mode 100644 index 000000000..1f2d9d746 Binary files /dev/null and b/static/img/docs/21f7afea-94a7-4bd9-b46f-7f8a20819eb7/image8.webp differ diff --git a/static/img/docs/21f7afea-94a7-4bd9-b46f-7f8a20819eb7/image9.webp b/static/img/docs/21f7afea-94a7-4bd9-b46f-7f8a20819eb7/image9.webp new file mode 100644 index 000000000..9e236c616 Binary files /dev/null and b/static/img/docs/21f7afea-94a7-4bd9-b46f-7f8a20819eb7/image9.webp differ diff --git a/static/img/docs/607ed709-2b00-4f6c-a1aa-6d234d0a5c0e/image1.webp b/static/img/docs/607ed709-2b00-4f6c-a1aa-6d234d0a5c0e/image1.webp new file mode 100644 index 000000000..50515fcc8 Binary files /dev/null and b/static/img/docs/607ed709-2b00-4f6c-a1aa-6d234d0a5c0e/image1.webp differ diff --git a/static/img/docs/607ed709-2b00-4f6c-a1aa-6d234d0a5c0e/image2.webp b/static/img/docs/607ed709-2b00-4f6c-a1aa-6d234d0a5c0e/image2.webp new file mode 100644 index 000000000..2ad879c00 Binary files /dev/null and b/static/img/docs/607ed709-2b00-4f6c-a1aa-6d234d0a5c0e/image2.webp differ diff --git a/static/img/docs/607ed709-2b00-4f6c-a1aa-6d234d0a5c0e/image3.webp b/static/img/docs/607ed709-2b00-4f6c-a1aa-6d234d0a5c0e/image3.webp new file mode 100644 index 000000000..8f96f569d Binary files /dev/null and b/static/img/docs/607ed709-2b00-4f6c-a1aa-6d234d0a5c0e/image3.webp differ diff --git a/static/img/docs/82703d2b-8e7d-4e69-b57b-493977056903/image1.webp b/static/img/docs/82703d2b-8e7d-4e69-b57b-493977056903/image1.webp new file mode 100644 index 000000000..1996f941c Binary files /dev/null and b/static/img/docs/82703d2b-8e7d-4e69-b57b-493977056903/image1.webp differ diff --git a/static/img/docs/8af0cecf-10f6-4ee0-a068-0834df394708/image1.webp b/static/img/docs/8af0cecf-10f6-4ee0-a068-0834df394708/image1.webp new file mode 100644 index 000000000..9ec0f59e5 Binary files /dev/null and b/static/img/docs/8af0cecf-10f6-4ee0-a068-0834df394708/image1.webp differ diff --git a/static/img/docs/94877b6f-56ed-4e42-a33c-55ef441e10bf/image1.webp b/static/img/docs/94877b6f-56ed-4e42-a33c-55ef441e10bf/image1.webp new file mode 100644 index 000000000..3442ddac0 Binary files /dev/null and b/static/img/docs/94877b6f-56ed-4e42-a33c-55ef441e10bf/image1.webp differ diff --git a/static/img/docs/99388b13-3ba3-4cca-990e-d295e30922f1/image1.webp b/static/img/docs/99388b13-3ba3-4cca-990e-d295e30922f1/image1.webp new file mode 100644 index 000000000..af5eb05c3 Binary files /dev/null and b/static/img/docs/99388b13-3ba3-4cca-990e-d295e30922f1/image1.webp differ diff --git a/static/img/docs/e239e458-56e6-4859-ab30-a7592366b824/image1.webp b/static/img/docs/e239e458-56e6-4859-ab30-a7592366b824/image1.webp new file mode 100644 index 000000000..76c86398f Binary files /dev/null and b/static/img/docs/e239e458-56e6-4859-ab30-a7592366b824/image1.webp differ diff --git a/static/img/docs/e239e458-56e6-4859-ab30-a7592366b824/image2.webp b/static/img/docs/e239e458-56e6-4859-ab30-a7592366b824/image2.webp new file mode 100644 index 000000000..2a31a1961 Binary files /dev/null and b/static/img/docs/e239e458-56e6-4859-ab30-a7592366b824/image2.webp differ diff --git a/static/img/docs/e239e458-56e6-4859-ab30-a7592366b824/image3.webp b/static/img/docs/e239e458-56e6-4859-ab30-a7592366b824/image3.webp new file mode 100644 index 000000000..0bb85697c Binary files /dev/null and b/static/img/docs/e239e458-56e6-4859-ab30-a7592366b824/image3.webp differ diff --git a/static/img/docs/e239e458-56e6-4859-ab30-a7592366b824/image4.webp b/static/img/docs/e239e458-56e6-4859-ab30-a7592366b824/image4.webp new file mode 100644 index 000000000..0ad5c6ca4 Binary files /dev/null and b/static/img/docs/e239e458-56e6-4859-ab30-a7592366b824/image4.webp differ diff --git a/static/img/docs/e239e458-56e6-4859-ab30-a7592366b824/image5.webp b/static/img/docs/e239e458-56e6-4859-ab30-a7592366b824/image5.webp new file mode 100644 index 000000000..b9532c12f Binary files /dev/null and b/static/img/docs/e239e458-56e6-4859-ab30-a7592366b824/image5.webp differ diff --git a/static/img/docs/e239e458-56e6-4859-ab30-a7592366b824/image6.webp b/static/img/docs/e239e458-56e6-4859-ab30-a7592366b824/image6.webp new file mode 100644 index 000000000..0db29fd64 Binary files /dev/null and b/static/img/docs/e239e458-56e6-4859-ab30-a7592366b824/image6.webp differ diff --git a/static/img/docs/eb95e04e-3612-4da6-91d1-815ce2691292/image1.webp b/static/img/docs/eb95e04e-3612-4da6-91d1-815ce2691292/image1.webp new file mode 100644 index 000000000..3c291e973 Binary files /dev/null and b/static/img/docs/eb95e04e-3612-4da6-91d1-815ce2691292/image1.webp differ