All Apps and Add-ons

Questions regarding setup of Splunk for Windows app and Perfmon configuration

adylent
Path Finder

What are the recommended Perfmon counters and procedures to properly and fully populate this app?

1)I am manually running the LookupManagement - Build searches. Should some of these builds be should be saved searches and run on intervals?

2) When I goto the summary page, I notice that no data is being shown because some of the searches reference counter="undefined" , but in my case the counter is always defined.

I'm looking for some best practices tips and guidelines here.

Thanks

0 Karma
1 Solution

adylent
Path Finder

2) This is related to the generator scripts. Run Settings -> Build Lookups -> Performance Counters -> WinApp_Lookup_Build_Perfmon - CreateNew - Detail and WinApp_Lookup_Build_Perfmon - CreateNew - Server

The issue was that the index with these events wasn't set to search by default. After verifying that was fixed, and rerunning the two searches detailed here all is well.

View solution in original post

adylent
Path Finder

2) This is related to the generator scripts. Run Settings -> Build Lookups -> Performance Counters -> WinApp_Lookup_Build_Perfmon - CreateNew - Detail and WinApp_Lookup_Build_Perfmon - CreateNew - Server

The issue was that the index with these events wasn't set to search by default. After verifying that was fixed, and rerunning the two searches detailed here all is well.

Get Updates on the Splunk Community!

Fun with Regular Expression - multiples of nine

Fun with Regular Expression - multiples of nineThis challenge was first posted on Slack #regex channel ...

[Live Demo] Watch SOC transformation in action with the reimagined Splunk Enterprise ...

Overwhelmed SOC? Splunk ES Has Your Back Tool sprawl, alert fatigue, and endless context switching are making ...

What’s New & Next in Splunk SOAR

Security teams today are dealing with more alerts, more tools, and more pressure than ever.  Join us on ...