All Apps and Add-ons

Questions regarding setup of Splunk for Windows app and Perfmon configuration

adylent
Path Finder

What are the recommended Perfmon counters and procedures to properly and fully populate this app?

1)I am manually running the LookupManagement - Build searches. Should some of these builds be should be saved searches and run on intervals?

2) When I goto the summary page, I notice that no data is being shown because some of the searches reference counter="undefined" , but in my case the counter is always defined.

I'm looking for some best practices tips and guidelines here.

Thanks

0 Karma
1 Solution

adylent
Path Finder

2) This is related to the generator scripts. Run Settings -> Build Lookups -> Performance Counters -> WinApp_Lookup_Build_Perfmon - CreateNew - Detail and WinApp_Lookup_Build_Perfmon - CreateNew - Server

The issue was that the index with these events wasn't set to search by default. After verifying that was fixed, and rerunning the two searches detailed here all is well.

View solution in original post

adylent
Path Finder

2) This is related to the generator scripts. Run Settings -> Build Lookups -> Performance Counters -> WinApp_Lookup_Build_Perfmon - CreateNew - Detail and WinApp_Lookup_Build_Perfmon - CreateNew - Server

The issue was that the index with these events wasn't set to search by default. After verifying that was fixed, and rerunning the two searches detailed here all is well.

Get Updates on the Splunk Community!

Observe and Secure All Apps with Splunk

  Join Us for Our Next Tech Talk: Observe and Secure All Apps with SplunkAs organizations continue to innovate ...

Splunk Decoded: Business Transactions vs Business IQ

It’s the morning of Black Friday, and your e-commerce site is handling 10x normal traffic. Orders are flowing, ...

Fastest way to demo Observability

I’ve been having a lot of fun learning about Kubernetes and Observability. I set myself an interesting ...