Getting Data In

Can I injest CPU, memory,eventID data in metric index by using SPLUNK app for unix and linux ?

kate
Path Finder

Can I injest CPU, memory,eventID data in metric index by using SPLUNK app for Windows ?
I am getting data once I injest this data in event index but when I am changing the index to metric index the data stops coming to any index.

#splunkforwarder#splunkappforwindows


Labels (4)
0 Karma
1 Solution

kate
Path Finder

Thanks for the hint I was checking via index=metric_indexname query. Utilized mstat it started fetching data.

View solution in original post

richgalloway
SplunkTrust
SplunkTrust

I presume you're referring to the Splunk Add-on for Windows since the app does not have any inputs.

It's not enough to change the destination index to a metrics index.  The format of the data must also change.

See https://docs.splunk.com/Documentation/AddOns/released/Windows/Configuration#Collect_perfmon_data_and... for the list of Windows metrics that are available and how to enable them.

---
If this reply helps you, Karma would be appreciated.
0 Karma

kate
Path Finder

Thanks for your response @richgalloway 
I have performed changes as suggested in the link you provided. And have restarted the splunk UF too. 
Still facing the same issue and have no error in splunkd.log.


kate_0-1708011963118.png

 

0 Karma

richgalloway
SplunkTrust
SplunkTrust

Verify the index name specified in inputs.conf on the UF exists on the indexers.

Please share the query you're using to find the data.

---
If this reply helps you, Karma would be appreciated.
0 Karma

kate
Path Finder

Thanks for the hint I was checking via index=metric_indexname query. Utilized mstat it started fetching data.

Get Updates on the Splunk Community!

Splunk Observability for AI

Don’t miss out on an exciting Tech Talk on Splunk Observability for AI!Discover how Splunk’s agentic AI ...

🔐 Trust at Every Hop: How mTLS in Splunk Enterprise 10.0 Makes Security Simpler

From Idea to Implementation: Why Splunk Built mTLS into Splunk Enterprise 10.0  mTLS wasn’t just a checkbox ...

Observe and Secure All Apps with Splunk

  Join Us for Our Next Tech Talk: Observe and Secure All Apps with SplunkAs organizations continue to innovate ...