Troubleshooting instructions for Windows server monitor being reported down after Windows BSOD (CrowdStrike)

Troubleshooting instructions for Windows server monitor being reported down after Windows BSOD (CrowdStrike)

Issue

The server monitor is down on the devices affected by the recent Windows-CrowdStrike BSOD issue.

Cause

After the BSOD, the affected devices are unable to start the Site24x7 Windows Agent service. When the customer tries to start the agent, it fails with error code 1608.


Upon analyzing the root cause of this issue, we found that all the groups and users that were previously associated with the agent install directory have been cleared after the BSOD.

Resolution

Add SYSTEM and Administrators to the groups and usernames for the agent install directory and grant full control permission.
To perform this fix easily, we have created a script. When this script is executed as an administrator, all the required users and groups with permissions will be added to the directory.