All Apps and Add-ons

Does the Splunk App for Windows Infrastructure support multikv mode for perfmon inputs?

passbt
Explorer

I can't seem to find any information out there and I was just curious if anyone out there knows for sure before I mess up my configs.

0 Karma
1 Solution

passbt
Explorer

I've found at least one search in the Splunk App for Windows Infrastructure that doesn't support Perfmon:Mk sourtypes, which is what you get when configuring perfmon inputs with the mode = mutlikv setting. For now, I've restored my perfmon inputs to use mode = single.

This is frustrating because I found not using multikv setting has increased my license usage by 5x.

View solution in original post

passbt
Explorer

I've found at least one search in the Splunk App for Windows Infrastructure that doesn't support Perfmon:Mk sourtypes, which is what you get when configuring perfmon inputs with the mode = mutlikv setting. For now, I've restored my perfmon inputs to use mode = single.

This is frustrating because I found not using multikv setting has increased my license usage by 5x.

Get Updates on the Splunk Community!

Get Your Exclusive Splunk Certified Cybersecurity Defense Engineer at Splunk .conf24 ...

We’re excited to announce a new Splunk certification exam being released at .conf24! If you’re headed to Vegas ...

Share Your Ideas & Meet the Lantern team at .Conf! Plus All of This Month’s New ...

Splunk Lantern is Splunk’s customer success center that provides advice from Splunk experts on valuable data ...

Combine Multiline Logs into a Single Event with SOCK: a Step-by-Step Guide for ...

Combine multiline logs into a single event with SOCK - a step-by-step guide for newbies Olga Malita The ...