Greetings Splunk Ninjas!
I have installed the SCOM add-on, configured it using an account which has both administrative rights to the SCOM server, and SCOM console. Further, I have verified the GET-SCOM* commands work inside the server Powershell. However, when initializing the application, the message is repeated in the log: index=_internal source=*ta_scom.log
2016-06-02 07:03:39 -04:00 [ERROR] New SCOMManagementGroupConnection Fail: Unable to find type [System.Net.WebUtility]: make sure that the assembly containing this type is loaded.
did you install the add-on on the SCOM console server? Are you using HW forwarder?
did you install the add-on on the SCOM console server? Are you using HW forwarder?
Thank you. I will do that and follow up here with the answer.
i would suggest to file a support ticket and attach diag for us to take a look. It might be easier that way.
Data has stopped all of a sudden. index=_internal source=*ta_scom.log shows no results.
I installed the Add-on using the Splunk Enterprise Server. It shows up as an app.
You need to have the add-on installed on a HFW or Light W. forwarder and on the console server for data collection.
http://docs.splunk.com/Documentation/AddOns/latest/MSSCOM/Install
from the doc:
Splunk recommends using a heavy forwarder for data collection because the add-on requires Python and the Splunk Add-on for Microsoft SCOM UI is recommended to configure inputs. The Splunk Add-on for Microsoft SCOM and the forwarder must be installed on the same machine as the SCOM Operations console.
Thank you. I am getting data now.