I've managed to build my first graph and dashboard, which is supposed to monitor the free disk space of a remote host.
The remote host is a Windows OS while Splunk Enterprise is installed on a Unix system.
When I create an indexer with some parameters to pull '% Free Space' from the Universal Forwarder (the remote host I want to monitor), I almost immediately receive data from it. I set polling interval to 60s
I create a Search and build a line chart from it which is now displayed on my dashboard.
However, it seems that no data is added anymore. Executing a search is not showing any new events, even though the interval should be 60s.
Using Splunk Web, I go to 'Data inputs' > 'Local performance monitoring' > Select the input I just created
I see the following errors: Failed to fetch data: Admin handler 'win-perfmon-find-collection' not found.
This error is displayed for 'Available objects', 'Counters', 'Instances'
I'm suspecting that this error is the cause that my graph is not being updated.
Know that I didn't add additional lines in any config file.
Let me know if more information is needed.
I am experiencing the same issue. We have Splunk 7.1 on Linux and I am trying to monitor Windows infrastructure. I've deployed the Splunk app for Windows Infrastructure + all the related add-ons and when I go to "Settings" -> "Data Inputs" -> "Forwarded Inputs" -> "Windows Performance Monitoring" I am presented with a screen that says "Local Performance Monitoring". That is strange?!
Also, when I try to dig further down from there, e.g. I click on the "Processor" input I receive the above mentioned error message "Failed to fetch data: Admin handler 'win-perfmon-find-collection' not found." all over the screen.
Should I ignore this message, or there's an issue with my configuration? All the forwarders are installed on Windows desktops and servers with Local System account.
I found an answer to my second question.
I added the following config to the 'inputs.conf' file on the Universal Forwarder
[perfmon://match the name in splunk web - data input]
disabled = 0
counters = % Free Space
instances = *
interval = 60
I installed Splunk Universal Forwarder as 'Local User'