Free tools Windows power users keep installed
One-click scans. No signup required.
Use Get-Counter to collect performance data, Get-WinEvent to inspect recorded events, and logman.exe when you need a durable capture for later analysis. Start by discovering counter paths on the target server, then choose a sampling interval and collection period that fit the problem. A single sample is a point in time, not a monitoring history.
Choose the data source for the question
Windows Server monitoring scripts work best when they collect the kind of evidence the problem calls for. Performance counters track resource and performance measurements; event logs record system or application events. Microsoft documents both Get-Counter and Get-WinEvent in the PowerShell.Diagnostics module.
| Need | Use | What it gives you |
|---|---|---|
| Check CPU, memory, disk, or other measured activity | Get-Counter |
Performance-counter samples, collected locally or from a remote computer. See Get-Counter documentation. |
| Find recorded system or application events | Get-WinEvent |
Event-log records or event tracing log data, with local and remote retrieval documented in the PowerShell.Diagnostics module. |
| Investigate an intermittent issue over a longer period | Performance Monitor data collector, configured with logman.exe |
A saved counter log that can be reviewed after the capture. Microsoft’s Performance Monitor troubleshooting workflow shows this approach. |
Do not treat counters as a high-frequency application profiler. Microsoft says they are intended for administrative and diagnostic discovery and collection, and are not designed to be collected more than once per second. For profiling or a need for lower-overhead, higher-frequency data, consider Event Tracing for Windows (ETW) or direct APIs instead. See About Performance Counters.
Discover and validate counter paths
Counter names and paths can vary with the target system’s language and available counter sets. Query the machine where the script will run rather than assuming an English path will work everywhere. The following commands list counter sets and display paths in the Memory set:
#1 Best Overall
Get-Counter -ListSet *
(Get-Counter -ListSet Memory).Paths
Use Get-Counter -ListSet output to identify a set relevant to the resource you want to examine, then inspect its Paths. Validate the chosen path on the intended server before automating it. For a localized Windows installation, discover the localized path on that host instead of copying an English counter name from another machine. Microsoft documents counter-set discovery and paths in Get-Counter.
Collect bounded samples with PowerShell
For a repeatable diagnostic run, set both the interval and the number of samples. This example requests the processor-time counter from a remote server every five seconds, for twelve samples:
$counter = 'Processor(*)% Processor Time'
Get-Counter -Counter $counter -ComputerName 'Server01' -SampleInterval 5 -MaxSamples 12
The example uses a wildcard instance to request processor instances. Confirm that this exact path exists on the target before relying on it; counter paths are installation- and language-dependent. Microsoft documents -ComputerName, -SampleInterval, and -MaxSamples for Get-Counter in its cmdlet reference.
Understand the sampling controls
-SampleIntervalsets the seconds between samples. The cmdlet’s default is one second; choose a larger interval when the diagnostic question does not need that cadence.-MaxSamplesbounds the run, making it suitable for a finite diagnostic collection.-Continuousis for an ongoing live stream. Use it only when a continuing session is intended, and plan how you will stop and preserve the data.
Keep collection at one second or slower. A long-running script that prints samples to an interactive console is not a durable incident record; use a collector log for extended troubleshooting so the data remains available for later analysis.
Quick wins for a faster PC:
Fix the driver behind crashes, sound loss and screen glitchesFind Drivers →Repair Windows errors before they cause bigger problemsFix Now →Capture a longer troubleshooting window with logman
For an intermittent issue, collect over a period that can expose trends rather than depending on a one-time reading. Microsoft’s Performance Monitor troubleshooting example uses logman to create a counter collector, start it, and stop it after the capture. Its sample uses a one-second interval and a 2 GB maximum file size; these are example settings, not universal requirements. Choose the counter set, interval, file location, and size for the server and investigation.
Rank #2
A basic sequence follows the documented create/start/stop pattern. Replace the illustrative counter path and location to match the target system and collection plan:
logman.exe create counter ServerTroubleshooting -c "Processor(*)% Processor Time" -si 00:00:01 -f bin -max 2048 -o C:PERFLOGSServerTroubleshooting
logman.exe start ServerTroubleshooting
rem Stop the collector after the diagnostic window:
logman.exe stop ServerTroubleshooting
Create the destination directory before starting if it does not exist, and verify that the account running the commands can write there. The example uses a binary log format, a one-second interval and a 2 GB maximum because those settings appear in Microsoft’s documented example; they are not recommended defaults for every workload. For the full context, see Troubleshoot issues using Performance Monitor.
Retrieve event records when the question is about events
If you need to know whether Windows or an application recorded an error, warning, or other event, query the event source rather than sampling a performance counter. Get-WinEvent is the PowerShell cmdlet for event-log and event tracing retrieval. The PowerShell.Diagnostics module documents its local and remote retrieval scope: Microsoft.PowerShell.Diagnostics.
Keep event collection focused on the log and time window relevant to the incident. A counter trend can show that resource use changed; an event record can help establish what Windows or an application logged around that time. These are complementary sources, not interchangeable answers.
Set thresholds in workload context
A threshold is a prompt to investigate, not a universal definition of an unhealthy server. Sustained utilization, a brief spike, available memory, workload type, and the timing of user impact all affect what a reading means. Set alert criteria against the server’s normal operating pattern and the operational impact you need to catch.
Rank #3
Server Manager’s documented defaults are an 85% CPU alert threshold and 2 MB of remaining memory. Those are Server Manager defaults, not general health criteria or recommended thresholds for every environment. Its documented performance collection is off until started. See Microsoft’s Server Manager performance, event, and service data documentation for the scope and defaults.
Plan the collection before automating it
- Define the question: choose counters for resource behavior, events for recorded occurrences, or a saved counter log for a longer diagnostic window.
- Discover on the target: enumerate sets and paths on the server where collection will run, especially when servers use different Windows languages or configurations.
- Choose a cadence: use a bounded sample count for a short check, or a collector log for an incident window. Do not sample counters faster than once per second.
- Choose retention deliberately: specify where files go and how much space a log may use; a capture that fills a volume can create a separate operational problem.
- Interpret trends, not isolated values: compare samples with a known operating baseline and relevant events before deciding an alert represents a fault.
Microsoft’s Windows Server monitoring training also covers Performance Monitor, Resource Monitor, custom collector sets, Resource Metering, Windows Admin Center, and System Insights across monitoring and capacity planning. Those tools address different administrative needs; the training material does not establish a product ranking or feature parity. See Monitor Windows Server performance.
Troubleshoot common collection problems
The counter path is not found
Confirm that the counter set exists on the target and that the path uses the target’s localized counter names. Re-run Get-Counter -ListSet * and inspect the relevant set’s Paths on that machine. Avoid treating a path copied from another language or Windows installation as universal.
A remote query fails
Check that the computer name resolves to the intended server and that the account and environment permit remote collection. Then validate the counter path locally on the target. The -ComputerName parameter supports remote collection, but a path valid on the querying machine may not be valid on the remote one. See the Get-Counter reference.
The output does not show a useful trend
A single sample cannot reveal whether a condition is intermittent or sustained. Increase the bounded sample count and choose an interval suited to the duration of the issue, or use a Performance Monitor collector log for a longer capture. Keep the interval at one second or slower.
Rank #4
- Mastering Active Directory: Design, deploy, and protect Active Directory Domain Services for Windows Server 2022, 3rd Edition
- ABIS BOOK
- Packt Publishing
The capture stops or cannot write its log
For logman, verify the collector name, output path, destination directory, available storage, and write permissions. Use logman.exe stop with the same collector name used to create and start it. Adjust the example’s maximum file size and output location to the environment rather than assuming the documentation’s example values fit your server.
A high counter value does not match user impact
Do not turn an isolated value into an alert without workload context. Compare the time series with the server’s normal pattern and check relevant event records. Server Manager’s documented alert defaults are interface defaults; they do not establish suitable thresholds for your application or service.
Or skip the browser setup
If your monitoring workflow also needs website screenshots—for a status page, incident dashboard, or other URL—ScreenshotNeo provides a one-request screenshot API. It accepts a URL and returns PNG, JPEG, WebP, or PDF; this does not replace Windows performance-counter or event-log collection.
cURL example (see the ScreenshotNeo API documentation):
curl -G "https://api.screenshotneo.com/v1/shot" -d access_key=YOUR_API_KEY --data-urlencode url=https://stripe.com -o shot.webp
ScreenshotNeo accepts cookie and consent banners before capture and removes more than 60 known consent platforms, newsletter popups, and chat widgets; each cleanup step can be turned off. Bot checks, blank pages, timeouts, failed loads, and cache hits are not billed, and response headers identify the page verdict and billing status. Its MCP server gives AI agents tools for screenshots, page information, and PDF capture. The Free plan includes 1,000 screenshots per month with no card; paid plans start at $5 for 3,000 shots.
Sign up for 1,000 free screenshots a month, with no card required.
Quick Recap
Product prices and availability are accurate as of the date/time indicated and are subject to change. Any price and availability information displayed on Amazon at the time of purchase will apply.

