My perfmon data (example Perfmon:Windows_Memory) is being collected by WMI, I can see this data in the index but I can't see it in the Windows Inf APP (Am running the latest version 1.0.2 on SPLUNK 6.1.3).
I have added these setting to eventtypes in the local folder in the splunk_app_windows_infrastructure folder...
[windows_performance]
search = sourcetype="powershell" OR sourcetype="Perfmon:" OR sourcetype="WMI:Perfmon" OR sourcetype="WMI:FreeDiskSpace" OR sourcetype="WMI:CPUTime" OR sourcetype="WMI:UPtime" OR sourcetype="WMI:LocalPhysicalDisk" OR sourcetype="WMI:LocalNetwork" OR sourcetype="WMI:Memory"
This still doesn't make any difference.
I have been through the documentation and can't find anything on how to fix this.
Can anyone help?
The answer is NO, so don't try it.