<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: How to query Server Stats in Splunk Search</title>
    <link>https://community.splunk.com/t5/Splunk-Search/How-to-query-Server-Stats/m-p/573701#M199935</link>
    <description>&lt;P&gt;Hi&lt;/P&gt;&lt;P&gt;if you are using linux then you should use this &lt;A href="https://docs.splunk.com/Documentation/UnixAddOn/6.0.0/User/AbouttheSplunkAdd-onforUnixandLinux" target="_blank"&gt;https://docs.splunk.com/Documentation/UnixAddOn/6.0.0/User/AbouttheSplunkAdd-onforUnixandLinux&lt;/A&gt; and follow that configuration instructions&amp;nbsp;&lt;A href="https://docs.splunk.com/Documentation/UnixAddOn/6.0.0/User/Enabledataandscriptedinputs" target="_blank"&gt;https://docs.splunk.com/Documentation/UnixAddOn/6.0.0/User/Enabledataandscriptedinputs&lt;/A&gt;&lt;/P&gt;&lt;P&gt;If you are using HF then you could configure that via GUI otherwise you must use those configuration files.&lt;/P&gt;&lt;P&gt;r. Ismo&lt;/P&gt;</description>
    <pubDate>Thu, 04 Nov 2021 21:37:12 GMT</pubDate>
    <dc:creator>isoutamo</dc:creator>
    <dc:date>2021-11-04T21:37:12Z</dc:date>
    <item>
      <title>How to query Server Stats</title>
      <link>https://community.splunk.com/t5/Splunk-Search/How-to-query-Server-Stats/m-p/573699#M199934</link>
      <description>&lt;P&gt;Good afternoon&lt;/P&gt;&lt;P&gt;i'm wondering if I may be able to get a bit of help with this one as I'm struggling on trying to achieve what I want.&amp;nbsp; I would like to query my 3 servers about their hardware status such as how much space is on the HDD etc etc however i'm really struggling to get my head around how to go about achieving this.&amp;nbsp;&lt;/P&gt;&lt;P&gt;I've seen a few posts on here which refer to making changes to the input.conf file by adding&amp;nbsp;&lt;EM&gt;perfmon&lt;/EM&gt; but firstly i'm not 100% sure on which input.conf i should be doing this on&amp;nbsp; (i'm presuming the forwarder) if this is at all the case, and secondly i'm not sure where and how this information in gleamed from.&amp;nbsp; If anyone would be able to point my in the right direction to a resource that is a step by step guide (or there abouts) i would be very grateful.&lt;/P&gt;&lt;P&gt;TIA&lt;/P&gt;</description>
      <pubDate>Thu, 04 Nov 2021 21:29:26 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Search/How-to-query-Server-Stats/m-p/573699#M199934</guid>
      <dc:creator>gherkin</dc:creator>
      <dc:date>2021-11-04T21:29:26Z</dc:date>
    </item>
    <item>
      <title>Re: How to query Server Stats</title>
      <link>https://community.splunk.com/t5/Splunk-Search/How-to-query-Server-Stats/m-p/573701#M199935</link>
      <description>&lt;P&gt;Hi&lt;/P&gt;&lt;P&gt;if you are using linux then you should use this &lt;A href="https://docs.splunk.com/Documentation/UnixAddOn/6.0.0/User/AbouttheSplunkAdd-onforUnixandLinux" target="_blank"&gt;https://docs.splunk.com/Documentation/UnixAddOn/6.0.0/User/AbouttheSplunkAdd-onforUnixandLinux&lt;/A&gt; and follow that configuration instructions&amp;nbsp;&lt;A href="https://docs.splunk.com/Documentation/UnixAddOn/6.0.0/User/Enabledataandscriptedinputs" target="_blank"&gt;https://docs.splunk.com/Documentation/UnixAddOn/6.0.0/User/Enabledataandscriptedinputs&lt;/A&gt;&lt;/P&gt;&lt;P&gt;If you are using HF then you could configure that via GUI otherwise you must use those configuration files.&lt;/P&gt;&lt;P&gt;r. Ismo&lt;/P&gt;</description>
      <pubDate>Thu, 04 Nov 2021 21:37:12 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Search/How-to-query-Server-Stats/m-p/573701#M199935</guid>
      <dc:creator>isoutamo</dc:creator>
      <dc:date>2021-11-04T21:37:12Z</dc:date>
    </item>
    <item>
      <title>Re: How to query Server Stats</title>
      <link>https://community.splunk.com/t5/Splunk-Search/How-to-query-Server-Stats/m-p/573703#M199936</link>
      <description>&lt;P&gt;Hi&amp;nbsp;&lt;a href="https://community.splunk.com/t5/user/viewprofilepage/user-id/214410"&gt;@isoutamo&lt;/a&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;I'm using windows machines i'm afraid, I'm also using a UniversalForwarder - I've just read that perhaps I need to enable the introspective_generator_addon.&amp;nbsp; Is that correct?&lt;/P&gt;</description>
      <pubDate>Thu, 04 Nov 2021 21:42:21 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Search/How-to-query-Server-Stats/m-p/573703#M199936</guid>
      <dc:creator>gherkin</dc:creator>
      <dc:date>2021-11-04T21:42:21Z</dc:date>
    </item>
    <item>
      <title>Re: How to query Server Stats</title>
      <link>https://community.splunk.com/t5/Splunk-Search/How-to-query-Server-Stats/m-p/573706#M199937</link>
      <description>&lt;P&gt;You can try this one &lt;A href="https://docs.splunk.com/Documentation/AddOns/released/Windows/AbouttheSplunkAdd-onforWindows" target="_blank" rel="noopener"&gt;https://docs.splunk.com/Documentation/AddOns/released/Windows/AbouttheSplunkAdd-onforWindows&lt;/A&gt;&lt;/P&gt;&lt;P&gt;Just install it on your windows machines which are running UF. Do configuration via conf-files or install it first on some HF/your test server and then take conf-files there and install then those (without host name) to UFs.&lt;/P&gt;</description>
      <pubDate>Thu, 04 Nov 2021 21:46:56 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Search/How-to-query-Server-Stats/m-p/573706#M199937</guid>
      <dc:creator>isoutamo</dc:creator>
      <dc:date>2021-11-04T21:46:56Z</dc:date>
    </item>
    <item>
      <title>Re: How to query Server Stats</title>
      <link>https://community.splunk.com/t5/Splunk-Search/How-to-query-Server-Stats/m-p/573735#M199944</link>
      <description>&lt;P&gt;Hello,&lt;/P&gt;&lt;P&gt;&lt;BR /&gt;Best solution is to install the splunk add on for windows available on splunk base on the windows server where splunk agent is installed.&lt;/P&gt;&lt;P&gt;this package has got all system level and perfmon metric collection inputs&amp;nbsp;&lt;/P&gt;&lt;P&gt;just enable those, it will be a lot easier for your situation.&lt;/P&gt;</description>
      <pubDate>Fri, 05 Nov 2021 03:41:11 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Search/How-to-query-Server-Stats/m-p/573735#M199944</guid>
      <dc:creator>Roy_9</dc:creator>
      <dc:date>2021-11-05T03:41:11Z</dc:date>
    </item>
    <item>
      <title>Re: How to query Server Stats</title>
      <link>https://community.splunk.com/t5/Splunk-Search/How-to-query-Server-Stats/m-p/574316#M200148</link>
      <description>&lt;P&gt;Good evening&amp;nbsp;&lt;a href="https://community.splunk.com/t5/user/viewprofilepage/user-id/214410"&gt;@isoutamo&lt;/a&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;apologies for the delay in response, i&amp;nbsp; was pulled away from the office the last couple of days.&lt;/P&gt;&lt;P&gt;So, i believe i've got it installed correctly, utilised the deployment server and edited the inputs.conf file enabling the sections that I want to monitor - checking the servers they seemed to have pulled down the files correctly.&lt;/P&gt;&lt;P&gt;I've also created an index (client_monitoring) and used:&lt;/P&gt;&lt;P&gt;&lt;EM&gt;index = client_monitoring&lt;/EM&gt;&lt;/P&gt;&lt;P&gt;in the inputs.conf file.&amp;nbsp; However if I try and do a search on that index I get&amp;nbsp;&lt;EM&gt;No results found.&lt;/EM&gt;&lt;/P&gt;&lt;P&gt;If I look at the Index's management page no data appears to be coming in as the Event Count is 0.&lt;/P&gt;&lt;P&gt;Apologies if this is all quite straight forward, I'm trying to teach myself this as I go along lol&lt;/P&gt;</description>
      <pubDate>Wed, 10 Nov 2021 04:13:10 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Search/How-to-query-Server-Stats/m-p/574316#M200148</guid>
      <dc:creator>gherkin</dc:creator>
      <dc:date>2021-11-10T04:13:10Z</dc:date>
    </item>
    <item>
      <title>Re: How to query Server Stats</title>
      <link>https://community.splunk.com/t5/Splunk-Search/How-to-query-Server-Stats/m-p/574351#M200159</link>
      <description>&lt;P&gt;Have you rebooted the UF service after installing and (every) configuration changes?&lt;/P&gt;&lt;P&gt;Have you gotten those internal logs from that UF server or is those application logs only which are missing?&lt;/P&gt;</description>
      <pubDate>Wed, 10 Nov 2021 08:59:04 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Search/How-to-query-Server-Stats/m-p/574351#M200159</guid>
      <dc:creator>isoutamo</dc:creator>
      <dc:date>2021-11-10T08:59:04Z</dc:date>
    </item>
    <item>
      <title>Re: How to query Server Stats</title>
      <link>https://community.splunk.com/t5/Splunk-Search/How-to-query-Server-Stats/m-p/574462#M200192</link>
      <description>&lt;P&gt;good morning&amp;nbsp;&lt;a href="https://community.splunk.com/t5/user/viewprofilepage/user-id/214410"&gt;@isoutamo&lt;/a&gt;&amp;nbsp;so I did restart the UF on one server (i was just testing it at the time to see if it works).&lt;/P&gt;&lt;P&gt;Apologies, i don't fully understand you logs sentence.&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Wed, 10 Nov 2021 17:49:26 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Search/How-to-query-Server-Stats/m-p/574462#M200192</guid>
      <dc:creator>gherkin</dc:creator>
      <dc:date>2021-11-10T17:49:26Z</dc:date>
    </item>
    <item>
      <title>Re: How to query Server Stats</title>
      <link>https://community.splunk.com/t5/Splunk-Search/How-to-query-Server-Stats/m-p/574482#M200204</link>
      <description>&lt;P&gt;Internal logs are UF’s own logs which told how it works. Application logs are e.g. windows, web servers or other logs which are generated by some application.&lt;/P&gt;</description>
      <pubDate>Wed, 10 Nov 2021 19:27:51 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Search/How-to-query-Server-Stats/m-p/574482#M200204</guid>
      <dc:creator>isoutamo</dc:creator>
      <dc:date>2021-11-10T19:27:51Z</dc:date>
    </item>
    <item>
      <title>Re: How to query Server Stats</title>
      <link>https://community.splunk.com/t5/Splunk-Search/How-to-query-Server-Stats/m-p/574676#M200265</link>
      <description>&lt;P&gt;Ok cool, gotcha.&amp;nbsp; So restarted the UF again today just to make sure and everything has kicked in, so either I restarted it to soon last time (ie before the conf file had come down) or it didn't necessarily start correctly.&lt;/P&gt;&lt;P&gt;Thank you once again, onto the my next research topic.....Dashboards &lt;span class="lia-unicode-emoji" title=":slightly_smiling_face:"&gt;🙂&lt;/span&gt;&lt;/P&gt;</description>
      <pubDate>Fri, 12 Nov 2021 00:50:58 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Search/How-to-query-Server-Stats/m-p/574676#M200265</guid>
      <dc:creator>gherkin</dc:creator>
      <dc:date>2021-11-12T00:50:58Z</dc:date>
    </item>
  </channel>
</rss>

