All Apps and Add-ons

Sending an indexer directly instead of a forwarder?

ssattler
Path Finder

Couple of questions

  1. Why are the directions telling you to send to an indexer directly instead of a forwarder?
  2. Why would you not have more metrics from windows, seems like an oversight on the part of the app developer not adding the perfmon metrics in a drop-down for selection instead of the basic CPU, memory, and disk...
  3. Why do does the polling go inactive, what would cause a timeout?
  4. Why are some metrics not present for a given host, for example, CPU stats collected for one but not another?
0 Karma

adonio
Ultra Champion

not sure what the context of your questions but let me try ...
1. why send to a forwarder? you can search data that is indexed in the indexer, this is the place for data, like a nest for an egg.
2. you have so many windows metrics that i am doubtful if you'll ever use them all. on top of that, each metric has many many counters. yes, they are in a drop-down menu if you install the TA on a full Splunk instance. remember that a forwarder does not have GUI. here is how to see all the metrics and all the counters possible in Windows TA click settings (top right) -> data inputs -> local performance monitoring -> New Local Performance Monitor -> enjoy the drop-down option -> enjoy picking performance counters
3. what do you mean by "polling"?
4. probably because you didnt tell splunk to collect those metrics, or because you are not searching in the right place.

hope it helps

0 Karma
Get Updates on the Splunk Community!

.conf24 | Registration Open!

Hello, hello! I come bearing good news: Registration for .conf24 is now open!   conf is Splunk’s rad annual ...

ICYMI - Check out the latest releases of Splunk Edge Processor

Splunk is pleased to announce the latest enhancements to Splunk Edge Processor.  HEC Receiver authorization ...

Introducing the 2024 SplunkTrust!

Hello, Splunk Community! We are beyond thrilled to announce our newest group of SplunkTrust members!  The ...