<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: addtional host data in the index, but not displaying data on the graph in Getting Data In</title>
    <link>https://community.splunk.com/t5/Getting-Data-In/addtional-host-data-in-the-index-but-not-displaying-data-on-the/m-p/20410#M2993</link>
    <description>&lt;P&gt;I am afraid at this time the application doesn't support CPU statistics from remote hosts. The issue is that it expects the statistics to come from WMI:CPU sourcetype (if you click on a link along "No results found" message you will see a search string like "search source=WMI:CPUTime host=&lt;HOST_NAME&gt; | eval CPULoad = PercentProcessorTime"). The search doesn't include events forwarder from remote hosts.&lt;/HOST_NAME&gt;&lt;/P&gt;</description>
    <pubDate>Tue, 24 Jan 2012 07:40:05 GMT</pubDate>
    <dc:creator>rovechkin_splun</dc:creator>
    <dc:date>2012-01-24T07:40:05Z</dc:date>
    <item>
      <title>addtional host data in the index, but not displaying data on the graph</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/addtional-host-data-in-the-index-but-not-displaying-data-on-the/m-p/20409#M2992</link>
      <description>&lt;P&gt;Hello,&lt;/P&gt;

&lt;P&gt;I have been try to configure the windows app to display data from additional hosts, but without success.&lt;/P&gt;

&lt;P&gt;We have:-&lt;/P&gt;

&lt;P&gt;1 indexer (windows app (4.2 Rev96023) installed and displaying data for just the Indexer)&lt;BR /&gt;
1 Search head (Windows app installed and display data for the search head and Indexer)&lt;/P&gt;

&lt;P&gt;I’ve looked at the data inputs and determined the WMI data counters are recording data in the ‘default’ (main) index.&lt;/P&gt;

&lt;P&gt;I clone the wmi counters and enter my own hosts&lt;/P&gt;

&lt;P&gt;I allow it to record for a period of time and manually do a search on some of the counters to confirm the data is in the index&lt;/P&gt;

&lt;P&gt;I load the Windows app and select CPU from the performance Management drop down menu, graphs of the search head and indexer appear.&lt;/P&gt;

&lt;P&gt;I use the dropdown box to change to the new additional hosts with the WMI counters I cloned above. The name of the host appears in the drop down list, I select it.&lt;/P&gt;

&lt;P&gt;The graphs come up with ‘no data’, the ‘Average CPU Load Split By Host’ still display, but only display data for the search head and indexer.&lt;/P&gt;

&lt;P&gt;The windows app seems to come with very little information and the help link doesn't work. Can confirm I have followed the correct actions, or are there any additional steps. I did see something about editing a WMI.conf files in the apps/Windows/local folder but not sure what values to put in there.&lt;/P&gt;

&lt;P&gt;Please can you help.&lt;/P&gt;

&lt;P&gt;Thank you&lt;/P&gt;

&lt;P&gt;David &lt;/P&gt;</description>
      <pubDate>Mon, 21 Nov 2011 23:36:51 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/addtional-host-data-in-the-index-but-not-displaying-data-on-the/m-p/20409#M2992</guid>
      <dc:creator>davidfreer</dc:creator>
      <dc:date>2011-11-21T23:36:51Z</dc:date>
    </item>
    <item>
      <title>Re: addtional host data in the index, but not displaying data on the graph</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/addtional-host-data-in-the-index-but-not-displaying-data-on-the/m-p/20410#M2993</link>
      <description>&lt;P&gt;I am afraid at this time the application doesn't support CPU statistics from remote hosts. The issue is that it expects the statistics to come from WMI:CPU sourcetype (if you click on a link along "No results found" message you will see a search string like "search source=WMI:CPUTime host=&lt;HOST_NAME&gt; | eval CPULoad = PercentProcessorTime"). The search doesn't include events forwarder from remote hosts.&lt;/HOST_NAME&gt;&lt;/P&gt;</description>
      <pubDate>Tue, 24 Jan 2012 07:40:05 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/addtional-host-data-in-the-index-but-not-displaying-data-on-the/m-p/20410#M2993</guid>
      <dc:creator>rovechkin_splun</dc:creator>
      <dc:date>2012-01-24T07:40:05Z</dc:date>
    </item>
  </channel>
</rss>

