I was told that Splunk for Windows would be updated for 4.2, but I've not seen evidence of this.
What's the word on:
1) Support for the more efficient Windows Perfmon metrics - These new metrics don't show up in the dashboard. On the forwarder side, some of the useful metrics like WMI Process and WMI Disk Queue Length have no option to be configured out of the box using Perfmon. There is no working Perfmon equivalent of WMI Process that I've found, either.
2) Scale - It's not reasonable to have inline searches that search across all Windows boxes in the environment as part of the main dashboard views. These need to be separated from an individual host view. Also, all inline searches should be wrapped in a time selector.
3) A sorted host selector - When you have a thousand Windows hosts, an unsorted dropdown list is useless. We have to replace it with a text field.
Thanks for advising on any roadmap improvements that might be around the corner.
We're currently looking for folks who have used the Windows app to provide requirements and run through a survey. The purpose is to develop a app that no only acts as an update to the existing Windows app, but potentially a data engine that enables higher level apps. We have already done substantial work on the knowlege layer to support this concept, but actual views, prescriptive workflows, etc are still getting ironed out. It sounds like you would be interested in participating in our feedback phase. If so, give us a shout at email@example.com.