I'm trying to get all the Active Directory stuff working, and almost everything is (thanks to the nice folks on here). The only part that isn't working so far is the DNS performance monitoring. For whatever reason, the eventtype "perfmon-dns" is empty. All the DNS servers are also domain controllers, so I installed the Splunk TA for Winows, and the TA for DNS Servers and Domain Controllers on each domain controller, and everything else seems to work. I can check the status of the DNS servers and all the zones have information, but the DNS perfmon is still empty. Anyone know what I can check?
Splunk for AD v1.2 has been released and should help in this situation.
Ok, that's the issue; since the TA's that the AD app uses currently doesn't support perfmon collection on 5.0.x.
We have an AD app beta v1.2.0 to fix this very issue. Please send a email request to microsoft@splunk.com to participate in the AD app v1.2.0 beta and we will send you an updated package. Note, that you will have to replace the TA's that you already deployed with the ones in the beta package.
What version of Splunk are you running? 5.0.x?
The newest one, 5.0.2.