<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: Direction on how to troubleshoot this perfmon issue? in Getting Data In</title>
    <link>https://community.splunk.com/t5/Getting-Data-In/Direction-on-how-to-troubleshoot-this-perfmon-issue/m-p/447010#M77768</link>
    <description>&lt;P&gt;You can put the inputs.conf here? &lt;/P&gt;</description>
    <pubDate>Wed, 14 Aug 2019 18:19:55 GMT</pubDate>
    <dc:creator>Kawtar</dc:creator>
    <dc:date>2019-08-14T18:19:55Z</dc:date>
    <item>
      <title>Direction on how to troubleshoot this perfmon issue?</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/Direction-on-how-to-troubleshoot-this-perfmon-issue/m-p/447009#M77767</link>
      <description>&lt;P&gt;All, &lt;/P&gt;

&lt;P&gt;I have the stock Splunk_TA_Windows 6.0.0 installed 6.0.0 with default inputs.conf enabled. Since pushing it out I am seeing the following errors. &lt;/P&gt;

&lt;PRE&gt;&lt;CODE&gt;08-14-2019 17:28:46.460 +0000 ERROR ExecProcessor - message from ""c:\Program Files\SplunkUniversalForwarder\bin\splunk-perfmon.exe"" splunk-perfmon - OutputHandler::composeOutput: Counter is not found: IO Data Bytes/sec
&lt;/CODE&gt;&lt;/PRE&gt;

&lt;P&gt;OS is Windows 2016&lt;/P&gt;

&lt;PRE&gt;&lt;CODE&gt;#inputs.conf 
...
## Process
[perfmon://Process]
counters = % Processor Time; % User Time; % Privileged Time; Virtual Bytes Peak; Virtual Bytes; Page Faults/sec; Working Set Peak; Working Set; Page File Bytes Peak; Page File Bytes; Private Bytes; Thread Count; Priority Base; Elapsed Time; ID Process; Creating Process ID; Pool Paged Bytes; Pool Nonpaged Bytes; Handle Count; IO Read Operations/sec; IO Write Operations/sec; IO Data Operations/sec; IO Other Operations/sec; IO Read Bytes/sec; IO Write Bytes/sec; IO Data Bytes/sec; IO Other Bytes/sec; Working Set - Private
disabled = 0
instances = *
interval = 10
  mode = single
object = Process
useEnglishOnly=true
  index=winmetrics
&lt;/CODE&gt;&lt;/PRE&gt;

&lt;P&gt;Any idea on what might the issue be? Where I can start troubleshooting? &lt;/P&gt;</description>
      <pubDate>Wed, 30 Sep 2020 01:44:06 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/Direction-on-how-to-troubleshoot-this-perfmon-issue/m-p/447009#M77767</guid>
      <dc:creator>daniel333</dc:creator>
      <dc:date>2020-09-30T01:44:06Z</dc:date>
    </item>
    <item>
      <title>Re: Direction on how to troubleshoot this perfmon issue?</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/Direction-on-how-to-troubleshoot-this-perfmon-issue/m-p/447010#M77768</link>
      <description>&lt;P&gt;You can put the inputs.conf here? &lt;/P&gt;</description>
      <pubDate>Wed, 14 Aug 2019 18:19:55 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/Direction-on-how-to-troubleshoot-this-perfmon-issue/m-p/447010#M77768</guid>
      <dc:creator>Kawtar</dc:creator>
      <dc:date>2019-08-14T18:19:55Z</dc:date>
    </item>
    <item>
      <title>Re: Direction on how to troubleshoot this perfmon issue?</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/Direction-on-how-to-troubleshoot-this-perfmon-issue/m-p/447011#M77769</link>
      <description>&lt;P&gt;You can put the inputs.conf here? &lt;/P&gt;</description>
      <pubDate>Wed, 14 Aug 2019 18:19:59 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/Direction-on-how-to-troubleshoot-this-perfmon-issue/m-p/447011#M77769</guid>
      <dc:creator>Kawtar</dc:creator>
      <dc:date>2019-08-14T18:19:59Z</dc:date>
    </item>
    <item>
      <title>Re: Direction on how to troubleshoot this perfmon issue?</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/Direction-on-how-to-troubleshoot-this-perfmon-issue/m-p/447012#M77770</link>
      <description>&lt;P&gt;This means, "IO Data Bytes" counter is not found on target host's perfmon logs. Simply remove "IO Data Bytes/sec;" from&lt;BR /&gt;
inputs.conf for that host, and restart forwarder. &lt;/P&gt;</description>
      <pubDate>Tue, 07 Apr 2020 19:34:14 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/Direction-on-how-to-troubleshoot-this-perfmon-issue/m-p/447012#M77770</guid>
      <dc:creator>akocak</dc:creator>
      <dc:date>2020-04-07T19:34:14Z</dc:date>
    </item>
  </channel>
</rss>

