All Apps and Add-ons

Is it possible to get performance data collected in SCOM into Splunk using the Splunk Add-on for Microsoft System Center Operations Manager?

reneeguz
New Member

How often does the SCOM Add-on poll SCOM to review alerts/events/etc?

Is it possible to get the performance data collected in SCOM into Splunk? For instance we monitor SQL with SCOM and it collects data on database free space every poll. I see were we can get alerts and or events, but no mention of performance data. If not with add-on, any other suggestions for getting this data out of SCOM repository?

0 Karma

jcoates_splunk
Splunk Employee
Splunk Employee
0 Karma

frmaasdam
Path Finder

In the SCOM add-on xml configuration file 300

0 Karma

frmaasdam
Path Finder

It was the answer on your first question.

0 Karma

reneeguz
New Member

Sorry to say I am still not following. How can changing polling interval change what type of data I can get. PerfData in SCOM is different than events, so I am trying to understand what specific configs (if possible) would be required to get perfdata (none of the documnetation mentions it as possible).

0 Karma

ppablo
Retired

Hi @reneeguz and @frmaasdam

Please be sure that when responding to someone's answer, click on "Add comment" directly below their answer or, if responding to someone's comment, type in the "Add your comment..." box directly below their comment. You keep typing your responses in the "Enter your answer here..." box at the very bottom of the page which, instead, posts a brand new answer each time. This will help with a clean continuous flow of the conversation. I already converted your answers to comments appropriately, so just something to keep in mind from here on out. Thanks and happy Splunking!

0 Karma

frmaasdam
Path Finder

I know. You can use the directives in the xml file to configure the pollinterval after how many seconds the scom_client.ps1 script pull the events out of SCOM into Splunk.

0 Karma

reneeguz
New Member

I think I am a little confused here. I am not asking how to get the data into SCOM (2012 version), I am asking how to get the data out of SCOM and into SPLUNK. Not just the events out of SCOM, but the data also.

0 Karma

reneeguz
New Member

Is this documented anywhere?

0 Karma
Get Updates on the Splunk Community!

Announcing the Expansion of the Splunk Academic Alliance Program

The Splunk Community is more than just an online forum — it’s a network of passionate users, administrators, ...

Learn Splunk Insider Insights, Do More With Gen AI, & Find 20+ New Use Cases You Can ...

Splunk Lantern is a Splunk customer success center that provides advice from Splunk experts on valuable data ...

Buttercup Games: Further Dashboarding Techniques (Part 7)

This series of blogs assumes you have already completed the Splunk Enterprise Search Tutorial as it uses the ...