<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: Windows Perfmon data not collecting in Getting Data In</title>
    <link>https://community.splunk.com/t5/Getting-Data-In/Windows-Perfmon-data-not-collecting/m-p/692900#M115172</link>
    <description>&lt;P&gt;We apply a range of GPO settings to get us close to a CIS Level One hardening. This does usually include the Windows Firewall, but it's set to off where it needs to be and it's off here.&amp;nbsp;&lt;/P&gt;</description>
    <pubDate>Wed, 10 Jul 2024 16:02:32 GMT</pubDate>
    <dc:creator>mooree</dc:creator>
    <dc:date>2024-07-10T16:02:32Z</dc:date>
    <item>
      <title>Windows Perfmon data not collecting</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/Windows-Perfmon-data-not-collecting/m-p/692860#M115165</link>
      <description>&lt;P&gt;Splunk is faliing to collect perfmon data from our Windows 2022 servers.&amp;nbsp;&lt;/P&gt;&lt;P&gt;I've extracted and deployed the stanzas from the Splunk TA for windows to collect selected perfmon stats from servers. We use a deployment server to push this out. Here's a sample:&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;LI-CODE lang="markup"&gt;[perfmon://CPU]
counters = % Processor Time 
disabled = 0
instances = *
interval = 10
mode = single
object = Processor
useEnglishOnly=true
index=2_###_test&lt;/LI-CODE&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;The Splunk Universal Forwarder now restarts as expected on deployment (missed that first time &lt;span class="lia-unicode-emoji" title=":winking_face:"&gt;😉&lt;/span&gt;) .&amp;nbsp; There are no apparent errors in splunkd.log.&amp;nbsp;&lt;/P&gt;&lt;P&gt;Nothing turns up!&amp;nbsp;Metrics confirms nothing being sent to that index from the UF.&amp;nbsp;&lt;/P&gt;&lt;P&gt;I'm guessing that our Security lockdown is preventing collection, but with no error messages anywhere it's hard to diagnose!&amp;nbsp;&lt;/P&gt;&lt;P&gt;Perfmon works on the server target so we know that the data is there and working.&amp;nbsp;&lt;/P&gt;&lt;P&gt;Splunk is 9.2.1. it's running in "least privilege" mode on the UF (the new default).&amp;nbsp;&lt;/P&gt;&lt;P&gt;Any hints and pointers most welcome!&amp;nbsp;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Wed, 10 Jul 2024 08:41:40 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/Windows-Perfmon-data-not-collecting/m-p/692860#M115165</guid>
      <dc:creator>mooree</dc:creator>
      <dc:date>2024-07-10T08:41:40Z</dc:date>
    </item>
    <item>
      <title>Re: Windows Perfmon data not collecting</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/Windows-Perfmon-data-not-collecting/m-p/692870#M115169</link>
      <description>&lt;P&gt;Hi&amp;nbsp;&lt;a href="https://community.splunk.com/t5/user/viewprofilepage/user-id/41432"&gt;@mooree&lt;/a&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;from the UF, do you receive other regular logs/app logs to the indexer?&lt;/P&gt;&lt;P&gt;using the btool, pls verify if the perfmon input is getting read by UF..&amp;nbsp;&lt;/P&gt;&lt;LI-CODE lang="markup"&gt;$SPLUNK_HOME$/bin/splunk btool inputs list --debug&lt;/LI-CODE&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Wed, 10 Jul 2024 10:22:26 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/Windows-Perfmon-data-not-collecting/m-p/692870#M115169</guid>
      <dc:creator>inventsekar</dc:creator>
      <dc:date>2024-07-10T10:22:26Z</dc:date>
    </item>
    <item>
      <title>Re: Windows Perfmon data not collecting</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/Windows-Perfmon-data-not-collecting/m-p/692875#M115170</link>
      <description>&lt;P&gt;What do you mean by "Security Lockdown"? Are there any local host firewall settings that are active on that server?&lt;/P&gt;</description>
      <pubDate>Wed, 10 Jul 2024 12:16:48 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/Windows-Perfmon-data-not-collecting/m-p/692875#M115170</guid>
      <dc:creator>JohnEGones</dc:creator>
      <dc:date>2024-07-10T12:16:48Z</dc:date>
    </item>
    <item>
      <title>Re: Windows Perfmon data not collecting</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/Windows-Perfmon-data-not-collecting/m-p/692899#M115171</link>
      <description>&lt;P class="lia-align-left"&gt;Thanks for the thoughts - I've re-checked both and:&lt;/P&gt;&lt;UL&gt;&lt;LI&gt;inputs all good and showing&amp;nbsp; in the btool output.&lt;/LI&gt;&lt;LI&gt;All other logs and events are getting through fine.&amp;nbsp;&amp;nbsp;&lt;/LI&gt;&lt;/UL&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Wed, 10 Jul 2024 16:00:11 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/Windows-Perfmon-data-not-collecting/m-p/692899#M115171</guid>
      <dc:creator>mooree</dc:creator>
      <dc:date>2024-07-10T16:00:11Z</dc:date>
    </item>
    <item>
      <title>Re: Windows Perfmon data not collecting</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/Windows-Perfmon-data-not-collecting/m-p/692900#M115172</link>
      <description>&lt;P&gt;We apply a range of GPO settings to get us close to a CIS Level One hardening. This does usually include the Windows Firewall, but it's set to off where it needs to be and it's off here.&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Wed, 10 Jul 2024 16:02:32 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/Windows-Perfmon-data-not-collecting/m-p/692900#M115172</guid>
      <dc:creator>mooree</dc:creator>
      <dc:date>2024-07-10T16:02:32Z</dc:date>
    </item>
    <item>
      <title>Re: Windows Perfmon data not collecting</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/Windows-Perfmon-data-not-collecting/m-p/692901#M115173</link>
      <description>&lt;P&gt;&lt;a href="https://community.splunk.com/t5/user/viewprofilepage/user-id/41432"&gt;@mooree&lt;/a&gt;&amp;nbsp;&lt;BR /&gt;&lt;BR /&gt;You write:&lt;BR /&gt;&lt;BR /&gt;"&lt;/P&gt;&lt;UL&gt;&lt;LI&gt;All other logs and events are getting through fine.&amp;nbsp; "&lt;BR /&gt;&lt;BR /&gt;these are&amp;nbsp; (other&amp;nbsp; - non-metric) logs from that 2022 server?&lt;/LI&gt;&lt;/UL&gt;</description>
      <pubDate>Wed, 10 Jul 2024 16:05:54 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/Windows-Perfmon-data-not-collecting/m-p/692901#M115173</guid>
      <dc:creator>JohnEGones</dc:creator>
      <dc:date>2024-07-10T16:05:54Z</dc:date>
    </item>
    <item>
      <title>Re: Windows Perfmon data not collecting</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/Windows-Perfmon-data-not-collecting/m-p/692903#M115175</link>
      <description>&lt;P&gt;This may be a relevant source for additional troubleshooting:&lt;BR /&gt;&lt;BR /&gt;&lt;A href="https://community.splunk.com/t5/Getting-Data-In/What-s-the-best-way-to-get-Windows-Perfmon-data-into-a-Metrics/m-p/428570" target="_blank"&gt;Solved: What's the best way to get Windows Perfmon data in... - Splunk Community&lt;/A&gt;&lt;/P&gt;</description>
      <pubDate>Wed, 10 Jul 2024 16:10:10 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/Windows-Perfmon-data-not-collecting/m-p/692903#M115175</guid>
      <dc:creator>JohnEGones</dc:creator>
      <dc:date>2024-07-10T16:10:10Z</dc:date>
    </item>
    <item>
      <title>Re: Windows Perfmon data not collecting</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/Windows-Perfmon-data-not-collecting/m-p/692905#M115177</link>
      <description>&lt;P&gt;Yes - It's only perfmon data we're not getting.&amp;nbsp;&lt;SPAN&gt;Splunk internals and event log events are both OK. AFAIK (and intended) these are not being collected as metrics.&amp;nbsp;&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN&gt;I'd been through the article you referenced, and heve now been back and checked my workings.&amp;nbsp; We've not installed the Windows add-on to every layer yet - I've just used bit of inputs.conf from it initially to get the data to look at and will then go back to all the clever bit once the basics are working.&amp;nbsp;&lt;/SPAN&gt;&lt;/P&gt;</description>
      <pubDate>Wed, 10 Jul 2024 16:20:08 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/Windows-Perfmon-data-not-collecting/m-p/692905#M115177</guid>
      <dc:creator>mooree</dc:creator>
      <dc:date>2024-07-10T16:20:08Z</dc:date>
    </item>
    <item>
      <title>Re: Windows Perfmon data not collecting</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/Windows-Perfmon-data-not-collecting/m-p/692907#M115178</link>
      <description>&lt;P&gt;Per the DOCS, here:&amp;nbsp;&lt;A href="https://docs.splunk.com/Documentation/WindowsAddOn/8.1.2/User/Install" target="_blank"&gt;Install the Splunk Add-on for Windows - Splunk Documentation&lt;/A&gt;&lt;/P&gt;&lt;P&gt;and for metric here:&amp;nbsp;&lt;A href="https://docs.splunk.com/Documentation/AddOns/released/Windows/Configuration#Collect_perfmon_data_and_wmi:uptime_data_in_metric_index" target="_blank"&gt;https://docs.splunk.com/Documentation/AddOns/released/Windows/Configuration#Collect_perfmon_data_and_wmi:uptime_data_in_metric_index&lt;/A&gt;&lt;/P&gt;&lt;P&gt;You should ensure you have a metrics index defined, and install it accordingly at every layer to ensure you're getting the data you need.&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Wed, 10 Jul 2024 16:32:18 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/Windows-Perfmon-data-not-collecting/m-p/692907#M115178</guid>
      <dc:creator>JohnEGones</dc:creator>
      <dc:date>2024-07-10T16:32:18Z</dc:date>
    </item>
    <item>
      <title>Re: Windows Perfmon data not collecting</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/Windows-Perfmon-data-not-collecting/m-p/692939#M115188</link>
      <description>&lt;P&gt;at times these simple issues may give us big headache.&amp;nbsp;&lt;/P&gt;&lt;P&gt;the shortest troubleshooting step is to resinstall the agent.. (do this only if you have min custom configs in the UF)&lt;/P&gt;</description>
      <pubDate>Wed, 10 Jul 2024 21:25:49 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/Windows-Perfmon-data-not-collecting/m-p/692939#M115188</guid>
      <dc:creator>inventsekar</dc:creator>
      <dc:date>2024-07-10T21:25:49Z</dc:date>
    </item>
    <item>
      <title>Re: Windows Perfmon data not collecting</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/Windows-Perfmon-data-not-collecting/m-p/692941#M115190</link>
      <description>&lt;P&gt;See this thread &lt;A href="https://community.splunk.com/t5/Getting-Data-In/Debugging-perfmon-input/m-p/621539#M107042" target="_blank"&gt;https://community.splunk.com/t5/Getting-Data-In/Debugging-perfmon-input/m-p/621539#M107042&lt;/A&gt;&lt;/P&gt;</description>
      <pubDate>Wed, 10 Jul 2024 21:43:12 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/Windows-Perfmon-data-not-collecting/m-p/692941#M115190</guid>
      <dc:creator>PickleRick</dc:creator>
      <dc:date>2024-07-10T21:43:12Z</dc:date>
    </item>
    <item>
      <title>Re: Windows Perfmon data not collecting</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/Windows-Perfmon-data-not-collecting/m-p/695100#M115463</link>
      <description>&lt;P&gt;Hi All&lt;/P&gt;&lt;P&gt;Has anyone managed to solve this issue without reinstalling UF?&lt;/P&gt;&lt;P&gt;We have this problem only on certain Window Servers 2022. Other windows versions are not affected. Also not all Win2022 are affected, only certain machines&lt;/P&gt;&lt;P&gt;Command "&lt;EM&gt;Get-counter -ListSet *&lt;/EM&gt;" returns the following error.&lt;/P&gt;&lt;PRE&gt;Could not find any performance counter sets on the computer: error c0000bc8. Verify that the computer exists, that it is discoverable, and that you have sufficient privileges to view performance counter data on that computer&lt;/PRE&gt;&lt;P&gt;Perfmon counters are available for other users on this machine, so there is problem for SplunkForwarder user.&amp;nbsp;&lt;/P&gt;&lt;P&gt;I've used the "l&lt;EM&gt;odctr /R&lt;/EM&gt;" command but issue still persists. The issue occurred immediately after the upgrade to version 9.1.5, so it's definitely Splunk problem&lt;/P&gt;</description>
      <pubDate>Fri, 02 Aug 2024 13:40:08 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/Windows-Perfmon-data-not-collecting/m-p/695100#M115463</guid>
      <dc:creator>psla</dc:creator>
      <dc:date>2024-08-02T13:40:08Z</dc:date>
    </item>
  </channel>
</rss>

