I am trying to troubleshoot a performance issue on a server on our network. I would like to setup some Windows Performance monitoring on the server. Can I remotely monitor Windows performance using a Universal Forwarder to get the data to the indexer or do I have to install Splunk Enterprise on the system and then forward WMI to the indexer?
Splunk App for Windows Infrastructure does much of this OTB. Part is free, need to pay or the AD part I believe.
https://apps.splunk.com/app/1680/
I´m looking to do just this after seeing the demo at Splunk live.
Thank you for the advice. I will try it out.