All Apps and Add-ons

Questions regarding setup of Splunk for Windows app and Perfmon configuration

adylent
Path Finder

What are the recommended Perfmon counters and procedures to properly and fully populate this app?

1)I am manually running the LookupManagement - Build searches. Should some of these builds be should be saved searches and run on intervals?

2) When I goto the summary page, I notice that no data is being shown because some of the searches reference counter="undefined" , but in my case the counter is always defined.

I'm looking for some best practices tips and guidelines here.

Thanks

0 Karma
1 Solution

adylent
Path Finder

2) This is related to the generator scripts. Run Settings -> Build Lookups -> Performance Counters -> WinApp_Lookup_Build_Perfmon - CreateNew - Detail and WinApp_Lookup_Build_Perfmon - CreateNew - Server

The issue was that the index with these events wasn't set to search by default. After verifying that was fixed, and rerunning the two searches detailed here all is well.

View solution in original post

adylent
Path Finder

2) This is related to the generator scripts. Run Settings -> Build Lookups -> Performance Counters -> WinApp_Lookup_Build_Perfmon - CreateNew - Detail and WinApp_Lookup_Build_Perfmon - CreateNew - Server

The issue was that the index with these events wasn't set to search by default. After verifying that was fixed, and rerunning the two searches detailed here all is well.

Get Updates on the Splunk Community!

Splunk + ThousandEyes: Correlate frontend, app, and network data to troubleshoot ...

 Are you tired of troubleshooting delays caused by siloed frontend, application, and network data? We've got a ...

Splunk Observability for AI

Don’t miss out on an exciting Tech Talk on Splunk Observability for AI!Discover how Splunk’s agentic AI ...

🔐 Trust at Every Hop: How mTLS in Splunk Enterprise 10.0 Makes Security Simpler

From Idea to Implementation: Why Splunk Built mTLS into Splunk Enterprise 10.0  mTLS wasn’t just a checkbox ...