Articles reference, SMB, updated 2026-10-02

SMB file: a backup on a Windows share or NAS

An SMB file sensor signs in to a Windows file server or a NAS, connects to a share and asks whether one file exists, and if so how big it is and how old. It is for checking that something landed: last night's backup, a router's config export, a nightly report. Nothing is read from the file.

Signing in, reaching the share and finding the file are separate steps, timed and reported separately. A refused login, a share that has been renamed and a backup that did not run are different problems for different people, and the sensor says which one it is.

Before you start

  • An account that can read the share, and nothing more. The probe only ever looks, but the account is the real safeguard. On a NAS, a local user with read-only permission on the one shared folder is ideal.
  • An SMB credential holding that account's username and password, and its domain where it is a domain account. Set it in Credentials on the sensor, or on the device, group or site above it to cover several sensors at once. Without one the sensor is not sent to any probe and reads STALE.
  • SMB 2 or 3, signing in with NTLMv2. That is what Windows Server and current NAS products accept by default. SMB 1 is not supported. Where a server accepts only Kerberos, mount the share on the probe host and use a file sensor.
  • TCP port 445 open from the probe to the server.

Setting it up

SettingWhat to put
TargetLeave the target override empty and the sensor asks the device's own address, which is right when the sensor sits on the file server or NAS.
ShareThe share's name alone, as the server lists it, such as Backups. Not a path, and no slashes.
File pathWithin the share, with either kind of slash, such as routers/edge1.cfg. A dated file can be named with tokens, filled in on UK time: routers/edge1-{{yesterday}}.cfg. See Dated files below before using {{isodate}}. Left empty, the sensor checks only that the account can sign in and reach the share.
PortLeave empty for 445.
IntervalA file that changes once a day does not need checking every minute. 15 minutes to an hour suits a nightly backup. An SMB file sensor is 2 credits a reading.
Failures before a probe calls it down1 is reasonable on a long interval, since a missing backup is not going to reappear on the next poll. Keep 3 on a short one.

What it reads

SlotReading
SV01 File sizeBytes.
SV02 File ageSeconds since the file was last modified, measured against the probe's clock, so a server whose clock is wrong shows a wrong age.
SV03 Login timeMilliseconds to negotiate and sign in. A domain controller getting slow shows here.
SV04 Lookup timeMilliseconds to reach the share and look the file up.
SD01 ModifiedThe modification time, in UTC.
SD02 Kindfile or directory.

The sensor is OK while the file is found, whatever its age, until rules say otherwise. A file that is there but three weeks old is still found, so for a backup the rules below are what make the sensor worth having.

A nightly backup

  1. In Rules, add SV02 greater than 93600 gives CRIT. 93600 seconds is 26 hours: a day plus a margin for a backup that runs a little late.
  2. Add SV01 less than a sensible minimum, such as 1000, gives CRIT. A backup job that ran but wrote an empty or truncated file still updates the age, and only the size catches it.

A file that is missing altogether fills no slot, so these rules do not judge it: it is a failed reading, and the failure threshold turns it into CRIT.

Dated files

Where a device writes a new file each day with the date in its name, the path can follow it with {{isodate}} (today) or {{yesterday}}. Be careful with today. From midnight until the backup runs, today's file does not exist yet, so a sensor looking for it fails every night, and an alarm at ten past midnight soon gets ignored. Look for yesterday's file instead, and a missing one means a backup really did not run.

Where the names cannot be predicted, because they carry a time or a serial number, point the sensor at the folder instead. A folder's modification time changes whenever a file is added to it or removed from it, so the folder's File age is the time since anything last landed there, and the same 26 hour rule works on it. Something deleted from the folder counts too, so this suits a folder that only ever receives.

When it fails

ErrorWhat it means
AUTHThe sign-in was refused: a wrong password, or an account that is disabled, locked out or expired. Or the account signed in but may not use the share, or may not read the file. The message says which.
No error classThere is no share of that name, or the file is not there. The message says which.
REFUSEDNothing is listening on port 445, or a firewall rejected the connection.
CONNECTTIMEOUTNo connection within the connect timeout: the server is off or unreachable, or a firewall is dropping the traffic.
RESPONSETIMEOUTConnected, but a step did not finish in time.
DNSThe hostname could not be looked up on the probe.