Check windows-version¶
Overview¶
Checks the installed Windows or Windows Server version against the endoflife.date API and alerts if the version is end-of-life. The lifecycle is chosen by the feature release and the edition, because Home and Pro, Enterprise and Education, and the Long-Term Servicing Channel go out of support on different dates. By default, alerts 30 days before the official EOL date. The offset is configurable.
Important Notes:
- The check must run locally on the host because it reads the version from the local registry.
- Windows 11 still names itself "Windows 10" in the registry. The check tells the two apart by the build number and reports the right one.
- Editions follow the grouping of endoflife.date: Home, Pro, Pro Education and Pro for Workstations share one lifecycle, Enterprise, Education and IoT Enterprise share a longer one, and the Long-Term Servicing Channel (LTSC) editions have their own. An edition outside these groups, such as Windows Team on a Surface Hub, is judged by the shorter Home and Pro lifecycle, and the output says so.
- Windows releases before Windows 10 are all past their end of life and report WARN.
- Unlike the other version checks, there is no
--check-major,--check-minoror--check-patch. endoflife.date names one build number per feature release for all editions, and a newer feature release is not necessarily an upgrade path for the installed edition.
Data Collection:
- Reads build, update revision, feature release, edition and installation type from the registry key
HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersionviareg query - Compares against the endoflife.date API, windows for clients and windows-server for servers (including Server Core), to determine the EOL status
- Caches endoflife.date responses locally for 24 hours to reduce external requests
Fact Sheet¶
| Fact | Value |
|---|---|
| Check Plugin Download | https://github.com/Linuxfabrik/monitoring-plugins/tree/main/check-plugins/windows-version |
| Nagios/Icinga Check Name | check_windows_version |
| Check Interval Recommendation | Every day |
| Can be called without parameters | Yes |
| Runs on | Windows |
| Compiled for Windows | Yes |
| Uses State File | $TEMP/linuxfabrik-lib-version.db |
Help¶
usage: windows-version [-h] [-V] [--always-ok] [--extended-support]
[--insecure] [--no-perfdata] [--no-proxy]
[--offset-eol OFFSET_EOL] [--proxy PROXY]
[--timeout TIMEOUT]
[--unreachable-severity {ok,warn,crit,unknown}]
Checks the installed Windows or Windows Server version against the
endoflife.date API and alerts if the version is end-of-life. The lifecycle is
chosen by the feature release and the edition, because Home and Pro,
Enterprise and Education, and the Long-Term Servicing Channel go out of
support on different dates. By default, alerts 30 days before the official EOL
date. The offset is configurable.
options:
-h, --help show this help message and exit
-V, --version show program's version number and exit
--always-ok Always returns OK.
--extended-support Instead of the end of servicing (default), check for
the end of the paid Extended Security Updates (ESU).
--insecure This option explicitly allows insecure SSL
connections.
--no-perfdata Suppress the performance data section from the output.
The status message and the exit code are unaffected,
so alerting keeps working while trending data is
dropped.
--no-proxy Do not use a proxy, not even one the environment
names. Overrides `--proxy`.
--offset-eol OFFSET_EOL
Alert n days before ("-30") or after an EOL date ("30"
or "+30"). Default: -30 days
--proxy PROXY Proxy to reach the target through. The scheme defaults
to `http` when omitted. Overrides the proxy the
environment names (`http_proxy`, `https_proxy`,
`all_proxy`) together with the exceptions it lists in
`no_proxy`, and is itself overridden by `--no-proxy`.
Without either parameter the environment applies.
Credentials belong into the environment variable
rather than here, because a command-line argument is
visible to every user on the host. Example:
`--proxy=http://proxy.example.com:3128`.
--timeout TIMEOUT Network timeout in seconds. Default: 8 (seconds)
--unreachable-severity {ok,warn,crit,unknown}
State to report when the online source is unreachable.
What is used instead - bundled offline data, a cached
copy, or nothing at all - is named in the output, and
a clean result then only covers what that fallback
could confirm. Default: ok
Documentation:
https://linuxfabrik.github.io/monitoring-plugins/check-plugins/windows-version/
Usage Examples¶
./windows-version --offset-eol=-30
Output:
Windows Server 2025 Standard Evaluation, build 26100.1742 (EOL 2034-11-14 -30d)
A Windows 10 host covered by Extended Security Updates:
./windows-version --extended-support
Output:
Windows 10 Pro 22H2, build 19045.6128 (full support ended on 2025-10-14; EOL 2028-10-10 -30d)
States¶
The end-of-life verdict, --offset-eol, --always-ok and what happens when endoflife.date cannot be reached work the same way in every endoflife.date-based version plugin. They are described in Version Plugins. In addition:
- WARN on every Windows release before Windows 10.
- UNKNOWN if endoflife.date has no cycle for the installed feature release and edition, for example a feature release published only days ago.
- UNKNOWN if the build number cannot be read from the registry.
Perfdata / Metrics¶
| Name | Type | Description |
|---|---|---|
| windows-version | Number | Installed build number, for example 26100 for Windows 11 24H2 and Windows Server 2025. |
Troubleshooting¶
version 26100.6700 unknown¶
endoflife.date does not list the feature release and edition of this host (yet). This happens in the first days after Microsoft publishes a new feature release. The end-of-life dates come from endoflife.date, so a missing or wrong cycle is fixed in their repository, and the check picks the correction up on its next run.
unknown edition <EditionID>, assuming the Home and Pro lifecycle¶
The edition of this host belongs to none of the groups endoflife.date distinguishes. The check assumes the shorter lifecycle, so it warns early rather than late. If the edition in fact follows the Enterprise or LTSC lifecycle, please open an issue with the output of reg query "HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion".
Credits, License¶
- Authors: Linuxfabrik GmbH, Zurich
- License: The Unlicense, see LICENSE file.