<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic splunk-perfmon.exe exited with code -1 in Getting Data In</title>
    <link>https://community.splunk.com/t5/Getting-Data-In/splunk-perfmon-exe-exited-with-code-1/m-p/66436#M13351</link>
    <description>&lt;P&gt;Hello,&lt;/P&gt;

&lt;P&gt;I am trying to find out why I receive &lt;STRONG&gt;"ExecProcessor - Ran script: "$SPLUNK_HOME\bin\splunk-perfmon.exe" -index perfmon, took 46.88 milliseconds to run, 0 bytes read, exited with code -1"&lt;/STRONG&gt;.&lt;/P&gt;

&lt;P&gt;I am layering the following apps: splunk_Windows_TA, TA-DNSServer-NT6,TA-DomainController-NT6.&lt;/P&gt;

&lt;P&gt;Below is my btool output for inputs.conf in debug mode:&lt;BR /&gt;
&lt;CODE&gt;&lt;/CODE&gt;&lt;PRE&gt;&lt;CODE&gt;&lt;BR /&gt;
system     [SSL]&lt;BR /&gt;
system     _rcvbuf = 1572864&lt;BR /&gt;
system     cipherSuite = ALL:!aNULL:!eNULL:!LOW:!EXP:RC4+RSA:+HIGH:+MEDIUM&lt;BR /&gt;
Splunk_TA_ evt_dc_name = &lt;BR /&gt;
Splunk_TA_ evt_dns_name = &lt;BR /&gt;
system     evt_resolve_ad_obj = 0&lt;BR /&gt;
system     host = fozzie&lt;BR /&gt;
system     index = default&lt;BR /&gt;
Splunk_TA_ [WinEventLog:Application]&lt;BR /&gt;
system     _rcvbuf = 1572864&lt;BR /&gt;
Splunk_TA_ checkpointInterval = 5&lt;BR /&gt;
Splunk_TA_ current_only = 0&lt;BR /&gt;
Splunk_TA_ disabled = 0&lt;BR /&gt;
Splunk_TA_ evt_dc_name = &lt;BR /&gt;
Splunk_TA_ evt_dns_name = &lt;BR /&gt;
system     evt_resolve_ad_obj = 0&lt;BR /&gt;
system     host = fozzie&lt;BR /&gt;
Splunk_TA_ index = winevents&lt;BR /&gt;
Splunk_TA_ start_from = oldest&lt;BR /&gt;
TA-DomainC [WinEventLog:DFS Replication]&lt;BR /&gt;
system     _rcvbuf = 1572864&lt;BR /&gt;
TA-DomainC disabled = 0&lt;BR /&gt;
Splunk_TA_ evt_dc_name = &lt;BR /&gt;
Splunk_TA_ evt_dns_name = &lt;BR /&gt;
system     evt_resolve_ad_obj = 0&lt;BR /&gt;
system     host = fozzie&lt;BR /&gt;
TA-DomainC index = winevents&lt;BR /&gt;
TA-DomainC queue = parsingQueue&lt;BR /&gt;
TA-DomainC sourcetype = "WinEventLog:DFS Replication"&lt;BR /&gt;
TA-DNSServ [WinEventLog:DNS Server]&lt;BR /&gt;
system     _rcvbuf = 1572864&lt;BR /&gt;
TA-DNSServ disabled = false&lt;BR /&gt;
Splunk_TA_ evt_dc_name = &lt;BR /&gt;
Splunk_TA_ evt_dns_name = &lt;BR /&gt;
system     evt_resolve_ad_obj = 0&lt;BR /&gt;
system     host = fozzie&lt;BR /&gt;
TA-DNSServ index = winevents&lt;BR /&gt;
TA-DNSServ queue = parsingQueue&lt;BR /&gt;
TA-DNSServ sourcetype = WinEventLog:DNS-Server&lt;BR /&gt;
TA-DomainC [WinEventLog:Directory Service]&lt;BR /&gt;
system     _rcvbuf = 1572864&lt;BR /&gt;
TA-DomainC disabled = 0&lt;BR /&gt;
Splunk_TA_ evt_dc_name = &lt;BR /&gt;
Splunk_TA_ evt_dns_name = &lt;BR /&gt;
system     evt_resolve_ad_obj = 0&lt;BR /&gt;
system     host = fozzie&lt;BR /&gt;
TA-DomainC index = winevents&lt;BR /&gt;
TA-DomainC queue = parsingQueue&lt;BR /&gt;
TA-DomainC sourcetype = "WinEventLog:Directory Service"&lt;BR /&gt;
TA-DomainC [WinEventLog:File Replication Service]&lt;BR /&gt;
system     _rcvbuf = 1572864&lt;BR /&gt;
TA-DomainC disabled = 0&lt;BR /&gt;
Splunk_TA_ evt_dc_name = &lt;BR /&gt;
Splunk_TA_ evt_dns_name = &lt;BR /&gt;
system     evt_resolve_ad_obj = 0&lt;BR /&gt;
system     host = fozzie&lt;BR /&gt;
TA-DomainC index = winevents&lt;BR /&gt;
TA-DomainC queue = parsingQueue&lt;BR /&gt;
TA-DomainC sourcetype = "WinEventLog:File Replication Service"&lt;BR /&gt;
system     [WinEventLog:ForwardedEvents]&lt;BR /&gt;
system     _rcvbuf = 1572864&lt;BR /&gt;
system     checkpointInterval = 5&lt;BR /&gt;
system     current_only = 0&lt;BR /&gt;
system     disabled = 1&lt;BR /&gt;
Splunk_TA_ evt_dc_name = &lt;BR /&gt;
Splunk_TA_ evt_dns_name = &lt;BR /&gt;
system     evt_resolve_ad_obj = 0&lt;BR /&gt;
system     host = fozzie&lt;BR /&gt;
system     index = default&lt;BR /&gt;
system     start_from = oldest&lt;BR /&gt;
system     [WinEventLog:HardwareEvents]&lt;BR /&gt;
system     _rcvbuf = 1572864&lt;BR /&gt;
system     checkpointInterval = 5&lt;BR /&gt;
system     current_only = 0&lt;BR /&gt;
system     disabled = 1&lt;BR /&gt;
Splunk_TA_ evt_dc_name = &lt;BR /&gt;
Splunk_TA_ evt_dns_name = &lt;BR /&gt;
system     evt_resolve_ad_obj = 0&lt;BR /&gt;
system     host = fozzie&lt;BR /&gt;
system     index = default&lt;BR /&gt;
system     start_from = oldest&lt;BR /&gt;
system     [WinEventLog:Internet Explorer]&lt;BR /&gt;
system     _rcvbuf = 1572864&lt;BR /&gt;
system     checkpointInterval = 5&lt;BR /&gt;
system     current_only = 0&lt;BR /&gt;
system     disabled = 1&lt;BR /&gt;
Splunk_TA_ evt_dc_name = &lt;BR /&gt;
Splunk_TA_ evt_dns_name = &lt;BR /&gt;
system     evt_resolve_ad_obj = 0&lt;BR /&gt;
system     host = fozzie&lt;BR /&gt;
system     index = default&lt;BR /&gt;
system     start_from = oldest&lt;BR /&gt;
TA-DomainC [WinEventLog:Key Management Service]&lt;BR /&gt;
system     _rcvbuf = 1572864&lt;BR /&gt;
TA-DomainC disabled = 0&lt;BR /&gt;
Splunk_TA_ evt_dc_name = &lt;BR /&gt;
Splunk_TA_ evt_dns_name = &lt;BR /&gt;
system     evt_resolve_ad_obj = 0&lt;BR /&gt;
system     host = fozzie&lt;BR /&gt;
TA-DomainC index = winevents&lt;BR /&gt;
TA-DomainC queue = parsingQueue&lt;BR /&gt;
TA-DomainC sourcetype = "WinEventLog:Key Management Service"&lt;BR /&gt;
Splunk_TA_ [WinEventLog:Security]&lt;BR /&gt;
system     _rcvbuf = 1572864&lt;BR /&gt;
Splunk_TA_ checkpointInterval = 5&lt;BR /&gt;
Splunk_TA_ current_only = 0&lt;BR /&gt;
Splunk_TA_ disabled = 0&lt;BR /&gt;
Splunk_TA_ evt_dc_name = &lt;BR /&gt;
Splunk_TA_ evt_dns_name = &lt;BR /&gt;
Splunk_TA_ evt_resolve_ad_obj = 1&lt;BR /&gt;
system     host = fozzie&lt;BR /&gt;
Splunk_TA_ index = winevents&lt;BR /&gt;
Splunk_TA_ start_from = oldest&lt;BR /&gt;
system     [WinEventLog:Setup]&lt;BR /&gt;
system     _rcvbuf = 1572864&lt;BR /&gt;
system     checkpointInterval = 5&lt;BR /&gt;
system     current_only = 0&lt;BR /&gt;
system     disabled = 1&lt;BR /&gt;
Splunk_TA_ evt_dc_name = &lt;BR /&gt;
Splunk_TA_ evt_dns_name = &lt;BR /&gt;
system     evt_resolve_ad_obj = 0&lt;BR /&gt;
system     host = fozzie&lt;BR /&gt;
system     index = default&lt;BR /&gt;
system     start_from = oldest&lt;BR /&gt;
Splunk_TA_ [WinEventLog:System]&lt;BR /&gt;
system     _rcvbuf = 1572864&lt;BR /&gt;
Splunk_TA_ checkpointInterval = 5&lt;BR /&gt;
Splunk_TA_ current_only = 0&lt;BR /&gt;
Splunk_TA_ disabled = 0&lt;BR /&gt;
Splunk_TA_ evt_dc_name = &lt;BR /&gt;
Splunk_TA_ evt_dns_name = &lt;BR /&gt;
system     evt_resolve_ad_obj = 0&lt;BR /&gt;
system     host = fozzie&lt;BR /&gt;
Splunk_TA_ index = winevents&lt;BR /&gt;
Splunk_TA_ start_from = oldest&lt;BR /&gt;
system     [batch://C:\Program Files\splunk\var\spool\splunk]&lt;BR /&gt;
system     _rcvbuf = 1572864&lt;BR /&gt;
system     crcSalt = &lt;SOURCE&gt;&lt;BR /&gt;
Splunk_TA_ evt_dc_name = &lt;BR /&gt;
Splunk_TA_ evt_dns_name = &lt;BR /&gt;
system     evt_resolve_ad_obj = 0&lt;BR /&gt;
system     host = fozzie&lt;BR /&gt;
system     index = default&lt;BR /&gt;
system     move_policy = sinkhole&lt;BR /&gt;
system     [batch://C:\Program Files\splunk\var\spool\splunk...stash_new]&lt;BR /&gt;
system     _rcvbuf = 1572864&lt;BR /&gt;
system     crcSalt = &lt;SOURCE&gt;&lt;BR /&gt;
Splunk_TA_ evt_dc_name = &lt;BR /&gt;
Splunk_TA_ evt_dns_name = &lt;BR /&gt;
system     evt_resolve_ad_obj = 0&lt;BR /&gt;
system     host = fozzie&lt;BR /&gt;
system     index = default&lt;BR /&gt;
system     move_policy = sinkhole&lt;BR /&gt;
system     queue = stashparsing&lt;BR /&gt;
system     sourcetype = stash_new&lt;BR /&gt;
system     [fschange:C:\Program Files\splunk\etc]&lt;BR /&gt;
system     _rcvbuf = 1572864&lt;BR /&gt;
system     delayInMills = 100&lt;BR /&gt;
Splunk_TA_ evt_dc_name = &lt;BR /&gt;
Splunk_TA_ evt_dns_name = &lt;BR /&gt;
system     evt_resolve_ad_obj = 0&lt;BR /&gt;
system     filesPerDelay = 10&lt;BR /&gt;
system     followLinks = false&lt;BR /&gt;
system     fullEvent = false&lt;BR /&gt;
system     hashMaxSize = -1&lt;BR /&gt;
system     host = fozzie&lt;BR /&gt;
system     index = default&lt;BR /&gt;
system     pollPeriod = 600&lt;BR /&gt;
system     recurse = true&lt;BR /&gt;
system     sendEventMaxSize = -1&lt;BR /&gt;
system     signedaudit = true&lt;BR /&gt;
Splunk_TA_ [fschange:C:\Windows\System32\drivers\etc]&lt;BR /&gt;
system     _rcvbuf = 1572864&lt;BR /&gt;
Splunk_TA_ evt_dc_name = &lt;BR /&gt;
Splunk_TA_ evt_dns_name = &lt;BR /&gt;
system     evt_resolve_ad_obj = 0&lt;BR /&gt;
Splunk_TA_ hashMaxSize = 1048576&lt;BR /&gt;
system     host = fozzie&lt;BR /&gt;
Splunk_TA_ index = winevents&lt;BR /&gt;
Splunk_TA_ pollPeriod = 30&lt;BR /&gt;
system     [monitor://C:\Program Files\splunk\etc\splunk.version]&lt;BR /&gt;
system     _TCP_ROUTING = *&lt;BR /&gt;
system     _rcvbuf = 1572864&lt;BR /&gt;
Splunk_TA_ evt_dc_name = &lt;BR /&gt;
Splunk_TA_ evt_dns_name = &lt;BR /&gt;
system     evt_resolve_ad_obj = 0&lt;BR /&gt;
system     host = fozzie&lt;BR /&gt;
system     index = _internal&lt;BR /&gt;
system     sourcetype = splunk_version&lt;BR /&gt;
system     [monitor://C:\Program Files\splunk\var\log\splunk]&lt;BR /&gt;
system     _rcvbuf = 1572864&lt;BR /&gt;
Splunk_TA_ evt_dc_name = &lt;BR /&gt;
Splunk_TA_ evt_dns_name = &lt;BR /&gt;
system     evt_resolve_ad_obj = 0&lt;BR /&gt;
system     host = fozzie&lt;BR /&gt;
system     index = _internal&lt;BR /&gt;
Splunk_TA_ [monitor://C:\Windows\System32\DHCP]&lt;BR /&gt;
system     _rcvbuf = 1572864&lt;BR /&gt;
Splunk_TA_ crcSalt = &lt;SOURCE&gt;&lt;BR /&gt;
Splunk_TA_ disabled = 1&lt;BR /&gt;
Splunk_TA_ evt_dc_name = &lt;BR /&gt;
Splunk_TA_ evt_dns_name = &lt;BR /&gt;
system     evt_resolve_ad_obj = 0&lt;BR /&gt;
system     host = fozzie&lt;BR /&gt;
system     index = default&lt;BR /&gt;
Splunk_TA_ sourcetype = DhcpSrvLog&lt;BR /&gt;
Splunk_TA_ whitelist = DhcpSrvLog*&lt;BR /&gt;
TA-DNSServ [monitor://C:\Windows\System32\Dns\dns.log]&lt;BR /&gt;
system     _rcvbuf = 1572864&lt;BR /&gt;
TA-DNSServ disabled = false&lt;BR /&gt;
Splunk_TA_ evt_dc_name = &lt;BR /&gt;
Splunk_TA_ evt_dns_name = &lt;BR /&gt;
system     evt_resolve_ad_obj = 0&lt;BR /&gt;
system     host = fozzie&lt;BR /&gt;
TA-DNSServ index = msad&lt;BR /&gt;
TA-DNSServ sourcetype = MSAD:NT6:DNS&lt;BR /&gt;
Splunk_TA_ [monitor://C:\Windows\WindowsUpdate.log]&lt;BR /&gt;
system     _rcvbuf = 1572864&lt;BR /&gt;
Splunk_TA_ disabled = 0&lt;BR /&gt;
Splunk_TA_ evt_dc_name = &lt;BR /&gt;
Splunk_TA_ evt_dns_name = &lt;BR /&gt;
system     evt_resolve_ad_obj = 0&lt;BR /&gt;
system     host = fozzie&lt;BR /&gt;
Splunk_TA_ index = winevents&lt;BR /&gt;
Splunk_TA_ sourcetype = WindowsUpdateLog&lt;BR /&gt;
TA-DomainC [monitor://C:\Windows\debug\netlogon.log]&lt;BR /&gt;
system     _rcvbuf = 1572864&lt;BR /&gt;
TA-DomainC disabled = false&lt;BR /&gt;
Splunk_TA_ evt_dc_name = &lt;BR /&gt;
Splunk_TA_ evt_dns_name = &lt;BR /&gt;
system     evt_resolve_ad_obj = 0&lt;BR /&gt;
system     host = fozzie&lt;BR /&gt;
TA-DomainC index = msad&lt;BR /&gt;
TA-DomainC sourcetype = MSAD:NT6:Netlogon&lt;BR /&gt;
Splunk_TA_ [perfmon://CPUTime]&lt;BR /&gt;
Splunk_TA_ counters = % Processor Time;% User Time&lt;BR /&gt;
Splunk_TA_ disabled = 1&lt;BR /&gt;
system     host = fozzie&lt;BR /&gt;
system     index = default&lt;BR /&gt;
Splunk_TA_ instances = _Total&lt;BR /&gt;
Splunk_TA_ interval = 10&lt;BR /&gt;
Splunk_TA_ object = Processor&lt;BR /&gt;
TA-DomainC [perfmon://DFS_Replicated_Folders]&lt;BR /&gt;
TA-DomainC counters = *&lt;BR /&gt;
TA-DomainC disabled = 0&lt;BR /&gt;
system     host = fozzie&lt;BR /&gt;
TA-DomainC index = perfmon&lt;BR /&gt;
TA-DomainC instances = *&lt;BR /&gt;
TA-DomainC interval = 60&lt;BR /&gt;
TA-DomainC object = DFS Replicated Folders&lt;BR /&gt;
TA-DNSServ [perfmon://DNS]&lt;BR /&gt;
TA-DNSServ counters = *&lt;BR /&gt;
TA-DNSServ disabled = 0&lt;BR /&gt;
system     host = fozzie&lt;BR /&gt;
system     index = default&lt;BR /&gt;
TA-DNSServ interval = 60&lt;BR /&gt;
TA-DNSServ object = DNS&lt;BR /&gt;
Splunk_TA_ [perfmon://FreeDiskSpace]&lt;BR /&gt;
Splunk_TA_ counters = Free Megabytes;% Free Space&lt;BR /&gt;
Splunk_TA_ disabled = 1&lt;BR /&gt;
system     host = fozzie&lt;BR /&gt;
system     index = default&lt;BR /&gt;
Splunk_TA_ instances = *&lt;BR /&gt;
Splunk_TA_ interval = 10&lt;BR /&gt;
Splunk_TA_ object = LogicalDisk&lt;BR /&gt;
Splunk_TA_ [perfmon://LocalNetwork]&lt;BR /&gt;
Splunk_TA_ counters = *&lt;BR /&gt;
Splunk_TA_ disabled = 0&lt;BR /&gt;
system     host = fozzie&lt;BR /&gt;
Splunk_TA_ index = perfmon&lt;BR /&gt;
Splunk_TA_ instances = *&lt;BR /&gt;
Splunk_TA_ interval = 60&lt;BR /&gt;
Splunk_TA_ object = Network Interface&lt;BR /&gt;
Splunk_TA_ [perfmon://LogicalDisk]&lt;BR /&gt;
Splunk_TA_ counters = *&lt;BR /&gt;
Splunk_TA_ disabled = 0&lt;BR /&gt;
system     host = fozzie&lt;BR /&gt;
Splunk_TA_ index = perfmon&lt;BR /&gt;
Splunk_TA_ instances = *&lt;BR /&gt;
Splunk_TA_ interval = 60&lt;BR /&gt;
Splunk_TA_ object = LogicalDisk&lt;BR /&gt;
Splunk_TA_ [perfmon://Memory]&lt;BR /&gt;
Splunk_TA_ counters = *&lt;BR /&gt;
Splunk_TA_ disabled = 0&lt;BR /&gt;
system     host = fozzie&lt;BR /&gt;
Splunk_TA_ index = perfmon&lt;BR /&gt;
Splunk_TA_ instances = *&lt;BR /&gt;
Splunk_TA_ interval = 60&lt;BR /&gt;
Splunk_TA_ object = Memory&lt;BR /&gt;
TA-DomainC [perfmon://NTDS]&lt;BR /&gt;
TA-DomainC counters = *&lt;BR /&gt;
TA-DomainC disabled = 0&lt;BR /&gt;
system     host = fozzie&lt;BR /&gt;
TA-DomainC index = perfmon&lt;BR /&gt;
TA-DomainC interval = 60&lt;BR /&gt;
TA-DomainC object = NTDS&lt;BR /&gt;
Splunk_TA_ [perfmon://Processor]&lt;BR /&gt;
Splunk_TA_ counters = *&lt;BR /&gt;
Splunk_TA_ disabled = 0&lt;BR /&gt;
system     host = fozzie&lt;BR /&gt;
Splunk_TA_ index = perfmon&lt;BR /&gt;
Splunk_TA_ instances = _Total&lt;BR /&gt;
Splunk_TA_ interval = 60&lt;BR /&gt;
Splunk_TA_ object = Processor&lt;BR /&gt;
system     [script]&lt;BR /&gt;
system     _rcvbuf = 1572864&lt;BR /&gt;
Splunk_TA_ evt_dc_name = &lt;BR /&gt;
Splunk_TA_ evt_dns_name = &lt;BR /&gt;
system     evt_resolve_ad_obj = 0&lt;BR /&gt;
system     host = fozzie&lt;BR /&gt;
system     index = default&lt;BR /&gt;
system     interval = 60.0&lt;BR /&gt;
TA-DomainC [script://C:\Program Files\splunk\bin\scripts\splunk-admon.path]&lt;BR /&gt;
system     _rcvbuf = 1572864&lt;BR /&gt;
TA-DomainC disabled = false&lt;BR /&gt;
Splunk_TA_ evt_dc_name = &lt;BR /&gt;
Splunk_TA_ evt_dns_name = &lt;BR /&gt;
system     evt_resolve_ad_obj = 0&lt;BR /&gt;
system     host = fozzie&lt;BR /&gt;
TA-DomainC index = msad&lt;BR /&gt;
TA-DomainC interval = 3600&lt;BR /&gt;
system     persistentQueueSize = 50MB&lt;BR /&gt;
system     queue = winparsing&lt;BR /&gt;
system     source = ActiveDirectory&lt;BR /&gt;
system     sourcetype = ActiveDirectory&lt;BR /&gt;
################## Section in question ########################&lt;BR /&gt;
&lt;STRONG&gt;Splunk_TA_ [script://C:\Program Files\splunk\bin\scripts\splunk-perfmon.path]&lt;BR /&gt;
system     _rcvbuf = 1572864&lt;BR /&gt;
Splunk_TA_ disabled = 0&lt;BR /&gt;
Splunk_TA_ evt_dc_name = &lt;BR /&gt;
Splunk_TA_ evt_dns_name = &lt;BR /&gt;
system     evt_resolve_ad_obj = 0&lt;BR /&gt;
system     host = fozzie&lt;BR /&gt;
Splunk_TA_ index = perfmon&lt;BR /&gt;
Splunk_TA_ interval = 60&lt;BR /&gt;
Splunk_TA_ queue = winparsing&lt;BR /&gt;
Splunk_TA_ source = PerformanceMonitor&lt;/STRONG&gt;&lt;BR /&gt;
############################################################&lt;BR /&gt;
system     [script://C:\Program Files\splunk\bin\scripts\splunk-regmon.path]&lt;BR /&gt;
system     _rcvbuf = 1572864&lt;BR /&gt;
system     disabled = 0&lt;BR /&gt;
Splunk_TA_ evt_dc_name = &lt;BR /&gt;
Splunk_TA_ evt_dns_name = &lt;BR /&gt;
system     evt_resolve_ad_obj = 0&lt;BR /&gt;
system     host = fozzie&lt;BR /&gt;
system     index = default&lt;BR /&gt;
system     interval = 10000000&lt;BR /&gt;
system     persistentQueueSize = 50MB&lt;BR /&gt;
system     queue = winparsing&lt;BR /&gt;
system     source = WinRegistry&lt;BR /&gt;
system     sourcetype = WinRegistry&lt;BR /&gt;
system     [script://C:\Program Files\splunk\bin\scripts\splunk-wmi.path]&lt;BR /&gt;
system     _rcvbuf = 1572864&lt;BR /&gt;
system     disabled = 0&lt;BR /&gt;
Splunk_TA_ evt_dc_name = &lt;BR /&gt;
Splunk_TA_ evt_dns_name = &lt;BR /&gt;
system     evt_resolve_ad_obj = 0&lt;BR /&gt;
system     host = fozzie&lt;BR /&gt;
system     index = default&lt;BR /&gt;
system     interval = 10000000&lt;BR /&gt;
system     persistentQueueSize = 200MB&lt;BR /&gt;
system     queue = winparsing&lt;BR /&gt;
system     source = wmi&lt;BR /&gt;
system     sourcetype = wmi&lt;BR /&gt;
Splunk_TA_ [script://C:\Program Files\splunk\etc\apps\Splunk_TA_windows\bin\win_installed_apps.bat]&lt;BR /&gt;
system     _rcvbuf = 1572864&lt;BR /&gt;
Splunk_TA_ disabled = 0&lt;BR /&gt;
Splunk_TA_ evt_dc_name = &lt;BR /&gt;
Splunk_TA_ evt_dns_name = &lt;BR /&gt;
system     evt_resolve_ad_obj = 0&lt;BR /&gt;
system     host = fozzie&lt;BR /&gt;
Splunk_TA_ index = winevents&lt;BR /&gt;
Splunk_TA_ interval = 86400&lt;BR /&gt;
Splunk_TA_ sourcetype = Script:InstalledApps&lt;BR /&gt;
Splunk_TA_ [script://C:\Program Files\splunk\etc\apps\Splunk_TA_windows\bin\win_listening_ports.bat]&lt;BR /&gt;
system     _rcvbuf = 1572864&lt;BR /&gt;
Splunk_TA_ disabled = 0&lt;BR /&gt;
Splunk_TA_ evt_dc_name = &lt;BR /&gt;
Splunk_TA_ evt_dns_name = &lt;BR /&gt;
system     evt_resolve_ad_obj = 0&lt;BR /&gt;
system     host = fozzie&lt;BR /&gt;
Splunk_TA_ index = winevents&lt;BR /&gt;
Splunk_TA_ interval = 3600&lt;BR /&gt;
Splunk_TA_ sourcetype = Script:ListeningPorts&lt;BR /&gt;
TA-DNSServ [script://C:\Program Files\splunk\etc\apps\TA-DNSServer-NT6\bin\runpowershell.cmd dns-health.ps1]&lt;BR /&gt;
system     _rcvbuf = 1572864&lt;BR /&gt;
TA-DNSServ disabled = false&lt;BR /&gt;
Splunk_TA_ evt_dc_name = &lt;BR /&gt;
Splunk_TA_ evt_dns_name = &lt;BR /&gt;
system     evt_resolve_ad_obj = 0&lt;BR /&gt;
system     host = fozzie&lt;BR /&gt;
TA-DNSServ index = msad&lt;BR /&gt;
TA-DNSServ interval = 3600&lt;BR /&gt;
TA-DNSServ source = Powershell&lt;BR /&gt;
TA-DNSServ sourcetype = MSAD:NT6:DNS-Health&lt;BR /&gt;
TA-DNSServ [script://C:\Program Files\splunk\etc\apps\TA-DNSServer-NT6\bin\runpowershell.cmd dns-zoneinfo.ps1]&lt;BR /&gt;
system     _rcvbuf = 1572864&lt;BR /&gt;
TA-DNSServ disabled = false&lt;BR /&gt;
Splunk_TA_ evt_dc_name = &lt;BR /&gt;
Splunk_TA_ evt_dns_name = &lt;BR /&gt;
system     evt_resolve_ad_obj = 0&lt;BR /&gt;
system     host = fozzie&lt;BR /&gt;
TA-DNSServ index = msad&lt;BR /&gt;
TA-DNSServ interval = 3600&lt;BR /&gt;
TA-DNSServ source = Powershell&lt;BR /&gt;
TA-DNSServ sourcetype = MSAD:NT6:DNS-Zone-Information&lt;BR /&gt;
TA-DomainC [script://C:\Program Files\splunk\etc\apps\TA-DomainController-NT6\bin\runpowershell.cmd ad-health.ps1]&lt;BR /&gt;
system     _rcvbuf = 1572864&lt;BR /&gt;
TA-DomainC disabled = false&lt;BR /&gt;
Splunk_TA_ evt_dc_name = &lt;BR /&gt;
Splunk_TA_ evt_dns_name = &lt;BR /&gt;
system     evt_resolve_ad_obj = 0&lt;BR /&gt;
system     host = fozzie&lt;BR /&gt;
TA-DomainC index = msad&lt;BR /&gt;
TA-DomainC interval = 300&lt;BR /&gt;
TA-DomainC source = Powershell&lt;BR /&gt;
TA-DomainC sourcetype = MSAD:NT6:Health&lt;BR /&gt;
TA-DomainC [script://C:\Program Files\splunk\etc\apps\TA-DomainController-NT6\bin\runpowershell.cmd ad-repl-stat.ps1]&lt;BR /&gt;
system     _rcvbuf = 1572864&lt;BR /&gt;
TA-DomainC disabled = false&lt;BR /&gt;
Splunk_TA_ evt_dc_name = &lt;BR /&gt;
Splunk_TA_ evt_dns_name = &lt;BR /&gt;
system     evt_resolve_ad_obj = 0&lt;BR /&gt;
system     host = fozzie&lt;BR /&gt;
TA-DomainC index = msad&lt;BR /&gt;
TA-DomainC interval = 300&lt;BR /&gt;
TA-DomainC source = Powershell&lt;BR /&gt;
TA-DomainC sourcetype = MSAD:NT6:Replication&lt;BR /&gt;
TA-DomainC [script://C:\Program Files\splunk\etc\apps\TA-DomainController-NT6\bin\runpowershell.cmd siteinfo.ps1]&lt;BR /&gt;
system     _rcvbuf = 1572864&lt;BR /&gt;
TA-DomainC disabled = false&lt;BR /&gt;
Splunk_TA_ evt_dc_name = &lt;BR /&gt;
Splunk_TA_ evt_dns_name = &lt;BR /&gt;
system     evt_resolve_ad_obj = 0&lt;BR /&gt;
system     host = fozzie&lt;BR /&gt;
TA-DomainC index = msad&lt;BR /&gt;
TA-DomainC interval = 3600&lt;BR /&gt;
TA-DomainC source = Powershell&lt;BR /&gt;
TA-DomainC sourcetype = MSAD:NT6:SiteInfo&lt;BR /&gt;
system     [splunktcp]&lt;BR /&gt;
system     _rcvbuf = 1572864&lt;BR /&gt;
system     acceptFrom = *&lt;BR /&gt;
system     connection_host = ip&lt;BR /&gt;
Splunk_TA_ evt_dc_name = &lt;BR /&gt;
Splunk_TA_ evt_dns_name = &lt;BR /&gt;
system     evt_resolve_ad_obj = 0&lt;BR /&gt;
system     host = fozzie&lt;BR /&gt;
system     index = default&lt;BR /&gt;
system     route = has_key:_replicationBucketUUID:replicationQueue;has_key:_dstrx:typingQueue;has_key:_linebreaker:indexQueue;absent_key:_linebreaker:parsingQueue&lt;BR /&gt;
system     [tcp]&lt;BR /&gt;
system     _rcvbuf = 1572864&lt;BR /&gt;
system     acceptFrom = *&lt;BR /&gt;
system     connection_host = dns&lt;BR /&gt;
Splunk_TA_ evt_dc_name = &lt;BR /&gt;
Splunk_TA_ evt_dns_name = &lt;BR /&gt;
system     evt_resolve_ad_obj = 0&lt;BR /&gt;
system     host = fozzie&lt;BR /&gt;
system     index = default&lt;BR /&gt;
system     [udp]&lt;BR /&gt;
system     _rcvbuf = 1572864&lt;BR /&gt;
system     connection_host = ip&lt;BR /&gt;
Splunk_TA_ evt_dc_name = &lt;BR /&gt;
Splunk_TA_ evt_dns_name = &lt;BR /&gt;
system     evt_resolve_ad_obj = 0&lt;BR /&gt;
system     host = fozzie&lt;BR /&gt;
system     index = default&lt;/SOURCE&gt;&lt;/SOURCE&gt;&lt;/SOURCE&gt;&lt;/CODE&gt;&lt;/PRE&gt;&lt;/P&gt;

&lt;P&gt;&lt;CODE&gt;&lt;/CODE&gt;&lt;/P&gt;</description>
    <pubDate>Mon, 17 Dec 2012 23:18:16 GMT</pubDate>
    <dc:creator>bmacias84</dc:creator>
    <dc:date>2012-12-17T23:18:16Z</dc:date>
    <item>
      <title>splunk-perfmon.exe exited with code -1</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/splunk-perfmon-exe-exited-with-code-1/m-p/66436#M13351</link>
      <description>&lt;P&gt;Hello,&lt;/P&gt;

&lt;P&gt;I am trying to find out why I receive &lt;STRONG&gt;"ExecProcessor - Ran script: "$SPLUNK_HOME\bin\splunk-perfmon.exe" -index perfmon, took 46.88 milliseconds to run, 0 bytes read, exited with code -1"&lt;/STRONG&gt;.&lt;/P&gt;

&lt;P&gt;I am layering the following apps: splunk_Windows_TA, TA-DNSServer-NT6,TA-DomainController-NT6.&lt;/P&gt;

&lt;P&gt;Below is my btool output for inputs.conf in debug mode:&lt;BR /&gt;
&lt;CODE&gt;&lt;/CODE&gt;&lt;PRE&gt;&lt;CODE&gt;&lt;BR /&gt;
system     [SSL]&lt;BR /&gt;
system     _rcvbuf = 1572864&lt;BR /&gt;
system     cipherSuite = ALL:!aNULL:!eNULL:!LOW:!EXP:RC4+RSA:+HIGH:+MEDIUM&lt;BR /&gt;
Splunk_TA_ evt_dc_name = &lt;BR /&gt;
Splunk_TA_ evt_dns_name = &lt;BR /&gt;
system     evt_resolve_ad_obj = 0&lt;BR /&gt;
system     host = fozzie&lt;BR /&gt;
system     index = default&lt;BR /&gt;
Splunk_TA_ [WinEventLog:Application]&lt;BR /&gt;
system     _rcvbuf = 1572864&lt;BR /&gt;
Splunk_TA_ checkpointInterval = 5&lt;BR /&gt;
Splunk_TA_ current_only = 0&lt;BR /&gt;
Splunk_TA_ disabled = 0&lt;BR /&gt;
Splunk_TA_ evt_dc_name = &lt;BR /&gt;
Splunk_TA_ evt_dns_name = &lt;BR /&gt;
system     evt_resolve_ad_obj = 0&lt;BR /&gt;
system     host = fozzie&lt;BR /&gt;
Splunk_TA_ index = winevents&lt;BR /&gt;
Splunk_TA_ start_from = oldest&lt;BR /&gt;
TA-DomainC [WinEventLog:DFS Replication]&lt;BR /&gt;
system     _rcvbuf = 1572864&lt;BR /&gt;
TA-DomainC disabled = 0&lt;BR /&gt;
Splunk_TA_ evt_dc_name = &lt;BR /&gt;
Splunk_TA_ evt_dns_name = &lt;BR /&gt;
system     evt_resolve_ad_obj = 0&lt;BR /&gt;
system     host = fozzie&lt;BR /&gt;
TA-DomainC index = winevents&lt;BR /&gt;
TA-DomainC queue = parsingQueue&lt;BR /&gt;
TA-DomainC sourcetype = "WinEventLog:DFS Replication"&lt;BR /&gt;
TA-DNSServ [WinEventLog:DNS Server]&lt;BR /&gt;
system     _rcvbuf = 1572864&lt;BR /&gt;
TA-DNSServ disabled = false&lt;BR /&gt;
Splunk_TA_ evt_dc_name = &lt;BR /&gt;
Splunk_TA_ evt_dns_name = &lt;BR /&gt;
system     evt_resolve_ad_obj = 0&lt;BR /&gt;
system     host = fozzie&lt;BR /&gt;
TA-DNSServ index = winevents&lt;BR /&gt;
TA-DNSServ queue = parsingQueue&lt;BR /&gt;
TA-DNSServ sourcetype = WinEventLog:DNS-Server&lt;BR /&gt;
TA-DomainC [WinEventLog:Directory Service]&lt;BR /&gt;
system     _rcvbuf = 1572864&lt;BR /&gt;
TA-DomainC disabled = 0&lt;BR /&gt;
Splunk_TA_ evt_dc_name = &lt;BR /&gt;
Splunk_TA_ evt_dns_name = &lt;BR /&gt;
system     evt_resolve_ad_obj = 0&lt;BR /&gt;
system     host = fozzie&lt;BR /&gt;
TA-DomainC index = winevents&lt;BR /&gt;
TA-DomainC queue = parsingQueue&lt;BR /&gt;
TA-DomainC sourcetype = "WinEventLog:Directory Service"&lt;BR /&gt;
TA-DomainC [WinEventLog:File Replication Service]&lt;BR /&gt;
system     _rcvbuf = 1572864&lt;BR /&gt;
TA-DomainC disabled = 0&lt;BR /&gt;
Splunk_TA_ evt_dc_name = &lt;BR /&gt;
Splunk_TA_ evt_dns_name = &lt;BR /&gt;
system     evt_resolve_ad_obj = 0&lt;BR /&gt;
system     host = fozzie&lt;BR /&gt;
TA-DomainC index = winevents&lt;BR /&gt;
TA-DomainC queue = parsingQueue&lt;BR /&gt;
TA-DomainC sourcetype = "WinEventLog:File Replication Service"&lt;BR /&gt;
system     [WinEventLog:ForwardedEvents]&lt;BR /&gt;
system     _rcvbuf = 1572864&lt;BR /&gt;
system     checkpointInterval = 5&lt;BR /&gt;
system     current_only = 0&lt;BR /&gt;
system     disabled = 1&lt;BR /&gt;
Splunk_TA_ evt_dc_name = &lt;BR /&gt;
Splunk_TA_ evt_dns_name = &lt;BR /&gt;
system     evt_resolve_ad_obj = 0&lt;BR /&gt;
system     host = fozzie&lt;BR /&gt;
system     index = default&lt;BR /&gt;
system     start_from = oldest&lt;BR /&gt;
system     [WinEventLog:HardwareEvents]&lt;BR /&gt;
system     _rcvbuf = 1572864&lt;BR /&gt;
system     checkpointInterval = 5&lt;BR /&gt;
system     current_only = 0&lt;BR /&gt;
system     disabled = 1&lt;BR /&gt;
Splunk_TA_ evt_dc_name = &lt;BR /&gt;
Splunk_TA_ evt_dns_name = &lt;BR /&gt;
system     evt_resolve_ad_obj = 0&lt;BR /&gt;
system     host = fozzie&lt;BR /&gt;
system     index = default&lt;BR /&gt;
system     start_from = oldest&lt;BR /&gt;
system     [WinEventLog:Internet Explorer]&lt;BR /&gt;
system     _rcvbuf = 1572864&lt;BR /&gt;
system     checkpointInterval = 5&lt;BR /&gt;
system     current_only = 0&lt;BR /&gt;
system     disabled = 1&lt;BR /&gt;
Splunk_TA_ evt_dc_name = &lt;BR /&gt;
Splunk_TA_ evt_dns_name = &lt;BR /&gt;
system     evt_resolve_ad_obj = 0&lt;BR /&gt;
system     host = fozzie&lt;BR /&gt;
system     index = default&lt;BR /&gt;
system     start_from = oldest&lt;BR /&gt;
TA-DomainC [WinEventLog:Key Management Service]&lt;BR /&gt;
system     _rcvbuf = 1572864&lt;BR /&gt;
TA-DomainC disabled = 0&lt;BR /&gt;
Splunk_TA_ evt_dc_name = &lt;BR /&gt;
Splunk_TA_ evt_dns_name = &lt;BR /&gt;
system     evt_resolve_ad_obj = 0&lt;BR /&gt;
system     host = fozzie&lt;BR /&gt;
TA-DomainC index = winevents&lt;BR /&gt;
TA-DomainC queue = parsingQueue&lt;BR /&gt;
TA-DomainC sourcetype = "WinEventLog:Key Management Service"&lt;BR /&gt;
Splunk_TA_ [WinEventLog:Security]&lt;BR /&gt;
system     _rcvbuf = 1572864&lt;BR /&gt;
Splunk_TA_ checkpointInterval = 5&lt;BR /&gt;
Splunk_TA_ current_only = 0&lt;BR /&gt;
Splunk_TA_ disabled = 0&lt;BR /&gt;
Splunk_TA_ evt_dc_name = &lt;BR /&gt;
Splunk_TA_ evt_dns_name = &lt;BR /&gt;
Splunk_TA_ evt_resolve_ad_obj = 1&lt;BR /&gt;
system     host = fozzie&lt;BR /&gt;
Splunk_TA_ index = winevents&lt;BR /&gt;
Splunk_TA_ start_from = oldest&lt;BR /&gt;
system     [WinEventLog:Setup]&lt;BR /&gt;
system     _rcvbuf = 1572864&lt;BR /&gt;
system     checkpointInterval = 5&lt;BR /&gt;
system     current_only = 0&lt;BR /&gt;
system     disabled = 1&lt;BR /&gt;
Splunk_TA_ evt_dc_name = &lt;BR /&gt;
Splunk_TA_ evt_dns_name = &lt;BR /&gt;
system     evt_resolve_ad_obj = 0&lt;BR /&gt;
system     host = fozzie&lt;BR /&gt;
system     index = default&lt;BR /&gt;
system     start_from = oldest&lt;BR /&gt;
Splunk_TA_ [WinEventLog:System]&lt;BR /&gt;
system     _rcvbuf = 1572864&lt;BR /&gt;
Splunk_TA_ checkpointInterval = 5&lt;BR /&gt;
Splunk_TA_ current_only = 0&lt;BR /&gt;
Splunk_TA_ disabled = 0&lt;BR /&gt;
Splunk_TA_ evt_dc_name = &lt;BR /&gt;
Splunk_TA_ evt_dns_name = &lt;BR /&gt;
system     evt_resolve_ad_obj = 0&lt;BR /&gt;
system     host = fozzie&lt;BR /&gt;
Splunk_TA_ index = winevents&lt;BR /&gt;
Splunk_TA_ start_from = oldest&lt;BR /&gt;
system     [batch://C:\Program Files\splunk\var\spool\splunk]&lt;BR /&gt;
system     _rcvbuf = 1572864&lt;BR /&gt;
system     crcSalt = &lt;SOURCE&gt;&lt;BR /&gt;
Splunk_TA_ evt_dc_name = &lt;BR /&gt;
Splunk_TA_ evt_dns_name = &lt;BR /&gt;
system     evt_resolve_ad_obj = 0&lt;BR /&gt;
system     host = fozzie&lt;BR /&gt;
system     index = default&lt;BR /&gt;
system     move_policy = sinkhole&lt;BR /&gt;
system     [batch://C:\Program Files\splunk\var\spool\splunk...stash_new]&lt;BR /&gt;
system     _rcvbuf = 1572864&lt;BR /&gt;
system     crcSalt = &lt;SOURCE&gt;&lt;BR /&gt;
Splunk_TA_ evt_dc_name = &lt;BR /&gt;
Splunk_TA_ evt_dns_name = &lt;BR /&gt;
system     evt_resolve_ad_obj = 0&lt;BR /&gt;
system     host = fozzie&lt;BR /&gt;
system     index = default&lt;BR /&gt;
system     move_policy = sinkhole&lt;BR /&gt;
system     queue = stashparsing&lt;BR /&gt;
system     sourcetype = stash_new&lt;BR /&gt;
system     [fschange:C:\Program Files\splunk\etc]&lt;BR /&gt;
system     _rcvbuf = 1572864&lt;BR /&gt;
system     delayInMills = 100&lt;BR /&gt;
Splunk_TA_ evt_dc_name = &lt;BR /&gt;
Splunk_TA_ evt_dns_name = &lt;BR /&gt;
system     evt_resolve_ad_obj = 0&lt;BR /&gt;
system     filesPerDelay = 10&lt;BR /&gt;
system     followLinks = false&lt;BR /&gt;
system     fullEvent = false&lt;BR /&gt;
system     hashMaxSize = -1&lt;BR /&gt;
system     host = fozzie&lt;BR /&gt;
system     index = default&lt;BR /&gt;
system     pollPeriod = 600&lt;BR /&gt;
system     recurse = true&lt;BR /&gt;
system     sendEventMaxSize = -1&lt;BR /&gt;
system     signedaudit = true&lt;BR /&gt;
Splunk_TA_ [fschange:C:\Windows\System32\drivers\etc]&lt;BR /&gt;
system     _rcvbuf = 1572864&lt;BR /&gt;
Splunk_TA_ evt_dc_name = &lt;BR /&gt;
Splunk_TA_ evt_dns_name = &lt;BR /&gt;
system     evt_resolve_ad_obj = 0&lt;BR /&gt;
Splunk_TA_ hashMaxSize = 1048576&lt;BR /&gt;
system     host = fozzie&lt;BR /&gt;
Splunk_TA_ index = winevents&lt;BR /&gt;
Splunk_TA_ pollPeriod = 30&lt;BR /&gt;
system     [monitor://C:\Program Files\splunk\etc\splunk.version]&lt;BR /&gt;
system     _TCP_ROUTING = *&lt;BR /&gt;
system     _rcvbuf = 1572864&lt;BR /&gt;
Splunk_TA_ evt_dc_name = &lt;BR /&gt;
Splunk_TA_ evt_dns_name = &lt;BR /&gt;
system     evt_resolve_ad_obj = 0&lt;BR /&gt;
system     host = fozzie&lt;BR /&gt;
system     index = _internal&lt;BR /&gt;
system     sourcetype = splunk_version&lt;BR /&gt;
system     [monitor://C:\Program Files\splunk\var\log\splunk]&lt;BR /&gt;
system     _rcvbuf = 1572864&lt;BR /&gt;
Splunk_TA_ evt_dc_name = &lt;BR /&gt;
Splunk_TA_ evt_dns_name = &lt;BR /&gt;
system     evt_resolve_ad_obj = 0&lt;BR /&gt;
system     host = fozzie&lt;BR /&gt;
system     index = _internal&lt;BR /&gt;
Splunk_TA_ [monitor://C:\Windows\System32\DHCP]&lt;BR /&gt;
system     _rcvbuf = 1572864&lt;BR /&gt;
Splunk_TA_ crcSalt = &lt;SOURCE&gt;&lt;BR /&gt;
Splunk_TA_ disabled = 1&lt;BR /&gt;
Splunk_TA_ evt_dc_name = &lt;BR /&gt;
Splunk_TA_ evt_dns_name = &lt;BR /&gt;
system     evt_resolve_ad_obj = 0&lt;BR /&gt;
system     host = fozzie&lt;BR /&gt;
system     index = default&lt;BR /&gt;
Splunk_TA_ sourcetype = DhcpSrvLog&lt;BR /&gt;
Splunk_TA_ whitelist = DhcpSrvLog*&lt;BR /&gt;
TA-DNSServ [monitor://C:\Windows\System32\Dns\dns.log]&lt;BR /&gt;
system     _rcvbuf = 1572864&lt;BR /&gt;
TA-DNSServ disabled = false&lt;BR /&gt;
Splunk_TA_ evt_dc_name = &lt;BR /&gt;
Splunk_TA_ evt_dns_name = &lt;BR /&gt;
system     evt_resolve_ad_obj = 0&lt;BR /&gt;
system     host = fozzie&lt;BR /&gt;
TA-DNSServ index = msad&lt;BR /&gt;
TA-DNSServ sourcetype = MSAD:NT6:DNS&lt;BR /&gt;
Splunk_TA_ [monitor://C:\Windows\WindowsUpdate.log]&lt;BR /&gt;
system     _rcvbuf = 1572864&lt;BR /&gt;
Splunk_TA_ disabled = 0&lt;BR /&gt;
Splunk_TA_ evt_dc_name = &lt;BR /&gt;
Splunk_TA_ evt_dns_name = &lt;BR /&gt;
system     evt_resolve_ad_obj = 0&lt;BR /&gt;
system     host = fozzie&lt;BR /&gt;
Splunk_TA_ index = winevents&lt;BR /&gt;
Splunk_TA_ sourcetype = WindowsUpdateLog&lt;BR /&gt;
TA-DomainC [monitor://C:\Windows\debug\netlogon.log]&lt;BR /&gt;
system     _rcvbuf = 1572864&lt;BR /&gt;
TA-DomainC disabled = false&lt;BR /&gt;
Splunk_TA_ evt_dc_name = &lt;BR /&gt;
Splunk_TA_ evt_dns_name = &lt;BR /&gt;
system     evt_resolve_ad_obj = 0&lt;BR /&gt;
system     host = fozzie&lt;BR /&gt;
TA-DomainC index = msad&lt;BR /&gt;
TA-DomainC sourcetype = MSAD:NT6:Netlogon&lt;BR /&gt;
Splunk_TA_ [perfmon://CPUTime]&lt;BR /&gt;
Splunk_TA_ counters = % Processor Time;% User Time&lt;BR /&gt;
Splunk_TA_ disabled = 1&lt;BR /&gt;
system     host = fozzie&lt;BR /&gt;
system     index = default&lt;BR /&gt;
Splunk_TA_ instances = _Total&lt;BR /&gt;
Splunk_TA_ interval = 10&lt;BR /&gt;
Splunk_TA_ object = Processor&lt;BR /&gt;
TA-DomainC [perfmon://DFS_Replicated_Folders]&lt;BR /&gt;
TA-DomainC counters = *&lt;BR /&gt;
TA-DomainC disabled = 0&lt;BR /&gt;
system     host = fozzie&lt;BR /&gt;
TA-DomainC index = perfmon&lt;BR /&gt;
TA-DomainC instances = *&lt;BR /&gt;
TA-DomainC interval = 60&lt;BR /&gt;
TA-DomainC object = DFS Replicated Folders&lt;BR /&gt;
TA-DNSServ [perfmon://DNS]&lt;BR /&gt;
TA-DNSServ counters = *&lt;BR /&gt;
TA-DNSServ disabled = 0&lt;BR /&gt;
system     host = fozzie&lt;BR /&gt;
system     index = default&lt;BR /&gt;
TA-DNSServ interval = 60&lt;BR /&gt;
TA-DNSServ object = DNS&lt;BR /&gt;
Splunk_TA_ [perfmon://FreeDiskSpace]&lt;BR /&gt;
Splunk_TA_ counters = Free Megabytes;% Free Space&lt;BR /&gt;
Splunk_TA_ disabled = 1&lt;BR /&gt;
system     host = fozzie&lt;BR /&gt;
system     index = default&lt;BR /&gt;
Splunk_TA_ instances = *&lt;BR /&gt;
Splunk_TA_ interval = 10&lt;BR /&gt;
Splunk_TA_ object = LogicalDisk&lt;BR /&gt;
Splunk_TA_ [perfmon://LocalNetwork]&lt;BR /&gt;
Splunk_TA_ counters = *&lt;BR /&gt;
Splunk_TA_ disabled = 0&lt;BR /&gt;
system     host = fozzie&lt;BR /&gt;
Splunk_TA_ index = perfmon&lt;BR /&gt;
Splunk_TA_ instances = *&lt;BR /&gt;
Splunk_TA_ interval = 60&lt;BR /&gt;
Splunk_TA_ object = Network Interface&lt;BR /&gt;
Splunk_TA_ [perfmon://LogicalDisk]&lt;BR /&gt;
Splunk_TA_ counters = *&lt;BR /&gt;
Splunk_TA_ disabled = 0&lt;BR /&gt;
system     host = fozzie&lt;BR /&gt;
Splunk_TA_ index = perfmon&lt;BR /&gt;
Splunk_TA_ instances = *&lt;BR /&gt;
Splunk_TA_ interval = 60&lt;BR /&gt;
Splunk_TA_ object = LogicalDisk&lt;BR /&gt;
Splunk_TA_ [perfmon://Memory]&lt;BR /&gt;
Splunk_TA_ counters = *&lt;BR /&gt;
Splunk_TA_ disabled = 0&lt;BR /&gt;
system     host = fozzie&lt;BR /&gt;
Splunk_TA_ index = perfmon&lt;BR /&gt;
Splunk_TA_ instances = *&lt;BR /&gt;
Splunk_TA_ interval = 60&lt;BR /&gt;
Splunk_TA_ object = Memory&lt;BR /&gt;
TA-DomainC [perfmon://NTDS]&lt;BR /&gt;
TA-DomainC counters = *&lt;BR /&gt;
TA-DomainC disabled = 0&lt;BR /&gt;
system     host = fozzie&lt;BR /&gt;
TA-DomainC index = perfmon&lt;BR /&gt;
TA-DomainC interval = 60&lt;BR /&gt;
TA-DomainC object = NTDS&lt;BR /&gt;
Splunk_TA_ [perfmon://Processor]&lt;BR /&gt;
Splunk_TA_ counters = *&lt;BR /&gt;
Splunk_TA_ disabled = 0&lt;BR /&gt;
system     host = fozzie&lt;BR /&gt;
Splunk_TA_ index = perfmon&lt;BR /&gt;
Splunk_TA_ instances = _Total&lt;BR /&gt;
Splunk_TA_ interval = 60&lt;BR /&gt;
Splunk_TA_ object = Processor&lt;BR /&gt;
system     [script]&lt;BR /&gt;
system     _rcvbuf = 1572864&lt;BR /&gt;
Splunk_TA_ evt_dc_name = &lt;BR /&gt;
Splunk_TA_ evt_dns_name = &lt;BR /&gt;
system     evt_resolve_ad_obj = 0&lt;BR /&gt;
system     host = fozzie&lt;BR /&gt;
system     index = default&lt;BR /&gt;
system     interval = 60.0&lt;BR /&gt;
TA-DomainC [script://C:\Program Files\splunk\bin\scripts\splunk-admon.path]&lt;BR /&gt;
system     _rcvbuf = 1572864&lt;BR /&gt;
TA-DomainC disabled = false&lt;BR /&gt;
Splunk_TA_ evt_dc_name = &lt;BR /&gt;
Splunk_TA_ evt_dns_name = &lt;BR /&gt;
system     evt_resolve_ad_obj = 0&lt;BR /&gt;
system     host = fozzie&lt;BR /&gt;
TA-DomainC index = msad&lt;BR /&gt;
TA-DomainC interval = 3600&lt;BR /&gt;
system     persistentQueueSize = 50MB&lt;BR /&gt;
system     queue = winparsing&lt;BR /&gt;
system     source = ActiveDirectory&lt;BR /&gt;
system     sourcetype = ActiveDirectory&lt;BR /&gt;
################## Section in question ########################&lt;BR /&gt;
&lt;STRONG&gt;Splunk_TA_ [script://C:\Program Files\splunk\bin\scripts\splunk-perfmon.path]&lt;BR /&gt;
system     _rcvbuf = 1572864&lt;BR /&gt;
Splunk_TA_ disabled = 0&lt;BR /&gt;
Splunk_TA_ evt_dc_name = &lt;BR /&gt;
Splunk_TA_ evt_dns_name = &lt;BR /&gt;
system     evt_resolve_ad_obj = 0&lt;BR /&gt;
system     host = fozzie&lt;BR /&gt;
Splunk_TA_ index = perfmon&lt;BR /&gt;
Splunk_TA_ interval = 60&lt;BR /&gt;
Splunk_TA_ queue = winparsing&lt;BR /&gt;
Splunk_TA_ source = PerformanceMonitor&lt;/STRONG&gt;&lt;BR /&gt;
############################################################&lt;BR /&gt;
system     [script://C:\Program Files\splunk\bin\scripts\splunk-regmon.path]&lt;BR /&gt;
system     _rcvbuf = 1572864&lt;BR /&gt;
system     disabled = 0&lt;BR /&gt;
Splunk_TA_ evt_dc_name = &lt;BR /&gt;
Splunk_TA_ evt_dns_name = &lt;BR /&gt;
system     evt_resolve_ad_obj = 0&lt;BR /&gt;
system     host = fozzie&lt;BR /&gt;
system     index = default&lt;BR /&gt;
system     interval = 10000000&lt;BR /&gt;
system     persistentQueueSize = 50MB&lt;BR /&gt;
system     queue = winparsing&lt;BR /&gt;
system     source = WinRegistry&lt;BR /&gt;
system     sourcetype = WinRegistry&lt;BR /&gt;
system     [script://C:\Program Files\splunk\bin\scripts\splunk-wmi.path]&lt;BR /&gt;
system     _rcvbuf = 1572864&lt;BR /&gt;
system     disabled = 0&lt;BR /&gt;
Splunk_TA_ evt_dc_name = &lt;BR /&gt;
Splunk_TA_ evt_dns_name = &lt;BR /&gt;
system     evt_resolve_ad_obj = 0&lt;BR /&gt;
system     host = fozzie&lt;BR /&gt;
system     index = default&lt;BR /&gt;
system     interval = 10000000&lt;BR /&gt;
system     persistentQueueSize = 200MB&lt;BR /&gt;
system     queue = winparsing&lt;BR /&gt;
system     source = wmi&lt;BR /&gt;
system     sourcetype = wmi&lt;BR /&gt;
Splunk_TA_ [script://C:\Program Files\splunk\etc\apps\Splunk_TA_windows\bin\win_installed_apps.bat]&lt;BR /&gt;
system     _rcvbuf = 1572864&lt;BR /&gt;
Splunk_TA_ disabled = 0&lt;BR /&gt;
Splunk_TA_ evt_dc_name = &lt;BR /&gt;
Splunk_TA_ evt_dns_name = &lt;BR /&gt;
system     evt_resolve_ad_obj = 0&lt;BR /&gt;
system     host = fozzie&lt;BR /&gt;
Splunk_TA_ index = winevents&lt;BR /&gt;
Splunk_TA_ interval = 86400&lt;BR /&gt;
Splunk_TA_ sourcetype = Script:InstalledApps&lt;BR /&gt;
Splunk_TA_ [script://C:\Program Files\splunk\etc\apps\Splunk_TA_windows\bin\win_listening_ports.bat]&lt;BR /&gt;
system     _rcvbuf = 1572864&lt;BR /&gt;
Splunk_TA_ disabled = 0&lt;BR /&gt;
Splunk_TA_ evt_dc_name = &lt;BR /&gt;
Splunk_TA_ evt_dns_name = &lt;BR /&gt;
system     evt_resolve_ad_obj = 0&lt;BR /&gt;
system     host = fozzie&lt;BR /&gt;
Splunk_TA_ index = winevents&lt;BR /&gt;
Splunk_TA_ interval = 3600&lt;BR /&gt;
Splunk_TA_ sourcetype = Script:ListeningPorts&lt;BR /&gt;
TA-DNSServ [script://C:\Program Files\splunk\etc\apps\TA-DNSServer-NT6\bin\runpowershell.cmd dns-health.ps1]&lt;BR /&gt;
system     _rcvbuf = 1572864&lt;BR /&gt;
TA-DNSServ disabled = false&lt;BR /&gt;
Splunk_TA_ evt_dc_name = &lt;BR /&gt;
Splunk_TA_ evt_dns_name = &lt;BR /&gt;
system     evt_resolve_ad_obj = 0&lt;BR /&gt;
system     host = fozzie&lt;BR /&gt;
TA-DNSServ index = msad&lt;BR /&gt;
TA-DNSServ interval = 3600&lt;BR /&gt;
TA-DNSServ source = Powershell&lt;BR /&gt;
TA-DNSServ sourcetype = MSAD:NT6:DNS-Health&lt;BR /&gt;
TA-DNSServ [script://C:\Program Files\splunk\etc\apps\TA-DNSServer-NT6\bin\runpowershell.cmd dns-zoneinfo.ps1]&lt;BR /&gt;
system     _rcvbuf = 1572864&lt;BR /&gt;
TA-DNSServ disabled = false&lt;BR /&gt;
Splunk_TA_ evt_dc_name = &lt;BR /&gt;
Splunk_TA_ evt_dns_name = &lt;BR /&gt;
system     evt_resolve_ad_obj = 0&lt;BR /&gt;
system     host = fozzie&lt;BR /&gt;
TA-DNSServ index = msad&lt;BR /&gt;
TA-DNSServ interval = 3600&lt;BR /&gt;
TA-DNSServ source = Powershell&lt;BR /&gt;
TA-DNSServ sourcetype = MSAD:NT6:DNS-Zone-Information&lt;BR /&gt;
TA-DomainC [script://C:\Program Files\splunk\etc\apps\TA-DomainController-NT6\bin\runpowershell.cmd ad-health.ps1]&lt;BR /&gt;
system     _rcvbuf = 1572864&lt;BR /&gt;
TA-DomainC disabled = false&lt;BR /&gt;
Splunk_TA_ evt_dc_name = &lt;BR /&gt;
Splunk_TA_ evt_dns_name = &lt;BR /&gt;
system     evt_resolve_ad_obj = 0&lt;BR /&gt;
system     host = fozzie&lt;BR /&gt;
TA-DomainC index = msad&lt;BR /&gt;
TA-DomainC interval = 300&lt;BR /&gt;
TA-DomainC source = Powershell&lt;BR /&gt;
TA-DomainC sourcetype = MSAD:NT6:Health&lt;BR /&gt;
TA-DomainC [script://C:\Program Files\splunk\etc\apps\TA-DomainController-NT6\bin\runpowershell.cmd ad-repl-stat.ps1]&lt;BR /&gt;
system     _rcvbuf = 1572864&lt;BR /&gt;
TA-DomainC disabled = false&lt;BR /&gt;
Splunk_TA_ evt_dc_name = &lt;BR /&gt;
Splunk_TA_ evt_dns_name = &lt;BR /&gt;
system     evt_resolve_ad_obj = 0&lt;BR /&gt;
system     host = fozzie&lt;BR /&gt;
TA-DomainC index = msad&lt;BR /&gt;
TA-DomainC interval = 300&lt;BR /&gt;
TA-DomainC source = Powershell&lt;BR /&gt;
TA-DomainC sourcetype = MSAD:NT6:Replication&lt;BR /&gt;
TA-DomainC [script://C:\Program Files\splunk\etc\apps\TA-DomainController-NT6\bin\runpowershell.cmd siteinfo.ps1]&lt;BR /&gt;
system     _rcvbuf = 1572864&lt;BR /&gt;
TA-DomainC disabled = false&lt;BR /&gt;
Splunk_TA_ evt_dc_name = &lt;BR /&gt;
Splunk_TA_ evt_dns_name = &lt;BR /&gt;
system     evt_resolve_ad_obj = 0&lt;BR /&gt;
system     host = fozzie&lt;BR /&gt;
TA-DomainC index = msad&lt;BR /&gt;
TA-DomainC interval = 3600&lt;BR /&gt;
TA-DomainC source = Powershell&lt;BR /&gt;
TA-DomainC sourcetype = MSAD:NT6:SiteInfo&lt;BR /&gt;
system     [splunktcp]&lt;BR /&gt;
system     _rcvbuf = 1572864&lt;BR /&gt;
system     acceptFrom = *&lt;BR /&gt;
system     connection_host = ip&lt;BR /&gt;
Splunk_TA_ evt_dc_name = &lt;BR /&gt;
Splunk_TA_ evt_dns_name = &lt;BR /&gt;
system     evt_resolve_ad_obj = 0&lt;BR /&gt;
system     host = fozzie&lt;BR /&gt;
system     index = default&lt;BR /&gt;
system     route = has_key:_replicationBucketUUID:replicationQueue;has_key:_dstrx:typingQueue;has_key:_linebreaker:indexQueue;absent_key:_linebreaker:parsingQueue&lt;BR /&gt;
system     [tcp]&lt;BR /&gt;
system     _rcvbuf = 1572864&lt;BR /&gt;
system     acceptFrom = *&lt;BR /&gt;
system     connection_host = dns&lt;BR /&gt;
Splunk_TA_ evt_dc_name = &lt;BR /&gt;
Splunk_TA_ evt_dns_name = &lt;BR /&gt;
system     evt_resolve_ad_obj = 0&lt;BR /&gt;
system     host = fozzie&lt;BR /&gt;
system     index = default&lt;BR /&gt;
system     [udp]&lt;BR /&gt;
system     _rcvbuf = 1572864&lt;BR /&gt;
system     connection_host = ip&lt;BR /&gt;
Splunk_TA_ evt_dc_name = &lt;BR /&gt;
Splunk_TA_ evt_dns_name = &lt;BR /&gt;
system     evt_resolve_ad_obj = 0&lt;BR /&gt;
system     host = fozzie&lt;BR /&gt;
system     index = default&lt;/SOURCE&gt;&lt;/SOURCE&gt;&lt;/SOURCE&gt;&lt;/CODE&gt;&lt;/PRE&gt;&lt;/P&gt;

&lt;P&gt;&lt;CODE&gt;&lt;/CODE&gt;&lt;/P&gt;</description>
      <pubDate>Mon, 17 Dec 2012 23:18:16 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/splunk-perfmon-exe-exited-with-code-1/m-p/66436#M13351</guid>
      <dc:creator>bmacias84</dc:creator>
      <dc:date>2012-12-17T23:18:16Z</dc:date>
    </item>
    <item>
      <title>Re: splunk-perfmon.exe exited with code -1</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/splunk-perfmon-exe-exited-with-code-1/m-p/66437#M13352</link>
      <description>&lt;P&gt;This is a non-issue.  I just removed stanza for splunk-perfmon.path and just used the &lt;STRONG&gt;perfmon&lt;/STRONG&gt; inputs.&lt;/P&gt;</description>
      <pubDate>Wed, 19 Dec 2012 17:54:15 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/splunk-perfmon-exe-exited-with-code-1/m-p/66437#M13352</guid>
      <dc:creator>bmacias84</dc:creator>
      <dc:date>2012-12-19T17:54:15Z</dc:date>
    </item>
    <item>
      <title>Re: splunk-perfmon.exe exited with code -1</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/splunk-perfmon-exe-exited-with-code-1/m-p/66438#M13353</link>
      <description>&lt;P&gt;I have this same problem and don't understand your answer?&lt;/P&gt;</description>
      <pubDate>Mon, 24 Feb 2014 21:01:15 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/splunk-perfmon-exe-exited-with-code-1/m-p/66438#M13353</guid>
      <dc:creator>mmattek</dc:creator>
      <dc:date>2014-02-24T21:01:15Z</dc:date>
    </item>
  </channel>
</rss>

