My perfmon data (example Perfmon:Windows_Memory) is being collected by WMI, I can see this data in the index but I can't see it in the Windows Inf APP (Am running the latest version 1.0.2 on SPLUNK 6.1.3).
I have added these setting to eventtypes in the local folder in the splunk_app_windows_infrastructure folder...
[windows_performance]
search = sourcetype="powershell" OR sourcetype="Perfmon:" OR sourcetype="WMI:Perfmon" OR sourcetype="WMI:FreeDiskSpace" OR sourcetype="WMI:CPUTime" OR sourcetype="WMI:UPtime" OR sourcetype="WMI:LocalPhysicalDisk" OR sourcetype="WMI:LocalNetwork" OR sourcetype="WMI:Memory"
This still doesn't make any difference.
I have been through the documentation and can't find anything on how to fix this.
Can anyone help?
The answer is NO, so don't try it.
The answer is NO, so don't try it.