Getting Data In

Capturing CPU and Memory in remote Windows servers from a Linux -Splunk server.

dannux
Path Finder

I have Splunk installed on a Linux server. It is indexing CPU and Memory usage for many Unix server. How can I capture CPU and MeM usage for Windows servers?

Thanks,
Dan

Tags (4)

lakshman239
Influencer

Hi, do we still have the scaling issues with WMI in the latest Splunk Add on for windows?

0 Karma

sf-mike
Splunk Employee
Splunk Employee

To build upon the above answer:

The Windows app will do this but does not use Perfmon. You install the app on your Linux box and also on a Windows forwarder.

To gather the data from Windows, You'll need to install the app on the Windows forwarder. The better way is to install the forwarder on each Windows host because of scaling issues inherent with WMI. If you do decide to use WMI, then you'll need at least 1 forwarder installed on a Windows host. Typically this would be done in an AD domain. The forwarder must be installed using AD credentials that can access all the hosts in the domain.

See this article:

http://docs.splunk.com/Documentation/Splunk/4.3/Data/MonitorWMIdata

0 Karma

hexx
Splunk Employee
Splunk Employee

I strongly recommend that you read this documentation topic on Real-time Windows performance monitoring. There's two approaches to this :

You cannot collect this kind of data remotely from a Linux indexer or forwarder.

Get Updates on the Splunk Community!

.conf24 | Day 0

Hello Splunk Community! My name is Chris, and I'm based in Canberra, Australia's capital, and I travelled for ...

Enhance Security Visibility with Splunk Enterprise Security 7.1 through Threat ...

(view in My Videos)Struggling with alert fatigue, lack of context, and prioritization around security ...

Troubleshooting the OpenTelemetry Collector

  In this tech talk, you’ll learn how to troubleshoot the OpenTelemetry collector - from checking the ...