<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: PerfMon Data from Windows Forwarders in Getting Data In</title>
    <link>https://community.splunk.com/t5/Getting-Data-In/PerfMon-Data-from-Windows-Forwarders/m-p/505232#M86092</link>
    <description>&lt;P&gt;Since you have multiple forwarders, you should be using a deployment server.&amp;nbsp; Plan on doing that soon.&amp;nbsp; It will make it easier to manage the forwarders, especially if more are added in the future.&lt;/P&gt;&lt;P&gt;The simple solution is to edit the inputs.conf files on the Windows servers.&amp;nbsp; They're probably in &lt;FONT face="courier new,courier"&gt;$SPLUNK_HOME\etc\system\local&lt;/FONT&gt;, but &lt;FONT face="courier new,courier"&gt;splunk btool --debug inputs list&lt;/FONT&gt; will tell you for sure.&lt;/P&gt;&lt;P&gt;When you edit the file, you'll see most of the perfmon stanzas have "disabled = 1" in them.&amp;nbsp; Change the "1" to "0" for those measurements you want to index.&amp;nbsp; Then restart the UF.&lt;/P&gt;</description>
    <pubDate>Fri, 19 Jun 2020 17:42:32 GMT</pubDate>
    <dc:creator>richgalloway</dc:creator>
    <dc:date>2020-06-19T17:42:32Z</dc:date>
    <item>
      <title>PerfMon Data from Windows Forwarders</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/PerfMon-Data-from-Windows-Forwarders/m-p/505222#M86089</link>
      <description>&lt;P&gt;I have my Splunk enterprise instance set up on a windows server. I also have 4 universal forwarders set up on Windows servers and 4 more universal forwarders set up on Linux servers. Right now, I want to forward PerfMon stats from the 4 Windows servers. When I was setting up the forwarders on these servers, I checked the boxes in the forwarder installers that allowed certain PerfMon counters to be sent to the Splunk server. Those are successfully sending certain counters like&amp;nbsp;&lt;SPAN&gt;"&lt;/SPAN&gt;&lt;SPAN class="t"&gt;Available&lt;/SPAN&gt; &lt;SPAN class="t"&gt;Bytes&lt;/SPAN&gt;&lt;SPAN&gt;",&amp;nbsp;"&lt;SPAN class="t"&gt;Bytes&lt;/SPAN&gt; &lt;SPAN class="t"&gt;Received/sec&lt;/SPAN&gt;", etc.&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN&gt;My question is how can I add more of these PerfMon counters to be forwarded to my Splunk Server? I saw some information about the Splunk App for Windows, but that was using Deployment clients and things like that, and I was wondering if their was a simpler way of just adding specific PerfMon counters in the forwarder settings on each server.&amp;nbsp;&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;Would it be better to use the Splunk App for Windows instead?&lt;/P&gt;</description>
      <pubDate>Fri, 19 Jun 2020 16:38:27 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/PerfMon-Data-from-Windows-Forwarders/m-p/505222#M86089</guid>
      <dc:creator>tbrown</dc:creator>
      <dc:date>2020-06-19T16:38:27Z</dc:date>
    </item>
    <item>
      <title>Re: PerfMon Data from Windows Forwarders</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/PerfMon-Data-from-Windows-Forwarders/m-p/505232#M86092</link>
      <description>&lt;P&gt;Since you have multiple forwarders, you should be using a deployment server.&amp;nbsp; Plan on doing that soon.&amp;nbsp; It will make it easier to manage the forwarders, especially if more are added in the future.&lt;/P&gt;&lt;P&gt;The simple solution is to edit the inputs.conf files on the Windows servers.&amp;nbsp; They're probably in &lt;FONT face="courier new,courier"&gt;$SPLUNK_HOME\etc\system\local&lt;/FONT&gt;, but &lt;FONT face="courier new,courier"&gt;splunk btool --debug inputs list&lt;/FONT&gt; will tell you for sure.&lt;/P&gt;&lt;P&gt;When you edit the file, you'll see most of the perfmon stanzas have "disabled = 1" in them.&amp;nbsp; Change the "1" to "0" for those measurements you want to index.&amp;nbsp; Then restart the UF.&lt;/P&gt;</description>
      <pubDate>Fri, 19 Jun 2020 17:42:32 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/PerfMon-Data-from-Windows-Forwarders/m-p/505232#M86092</guid>
      <dc:creator>richgalloway</dc:creator>
      <dc:date>2020-06-19T17:42:32Z</dc:date>
    </item>
  </channel>
</rss>

