Getting Data In

Direction on how to troubleshoot this perfmon issue?

daniel333
Builder

All,

I have the stock Splunk_TA_Windows 6.0.0 installed 6.0.0 with default inputs.conf enabled. Since pushing it out I am seeing the following errors.

08-14-2019 17:28:46.460 +0000 ERROR ExecProcessor - message from ""c:\Program Files\SplunkUniversalForwarder\bin\splunk-perfmon.exe"" splunk-perfmon - OutputHandler::composeOutput: Counter is not found: IO Data Bytes/sec

OS is Windows 2016

#inputs.conf 
...
## Process
[perfmon://Process]
counters = % Processor Time; % User Time; % Privileged Time; Virtual Bytes Peak; Virtual Bytes; Page Faults/sec; Working Set Peak; Working Set; Page File Bytes Peak; Page File Bytes; Private Bytes; Thread Count; Priority Base; Elapsed Time; ID Process; Creating Process ID; Pool Paged Bytes; Pool Nonpaged Bytes; Handle Count; IO Read Operations/sec; IO Write Operations/sec; IO Data Operations/sec; IO Other Operations/sec; IO Read Bytes/sec; IO Write Bytes/sec; IO Data Bytes/sec; IO Other Bytes/sec; Working Set - Private
disabled = 0
instances = *
interval = 10
  mode = single
object = Process
useEnglishOnly=true
  index=winmetrics

Any idea on what might the issue be? Where I can start troubleshooting?

akocak
Contributor

This means, "IO Data Bytes" counter is not found on target host's perfmon logs. Simply remove "IO Data Bytes/sec;" from
inputs.conf for that host, and restart forwarder.

0 Karma

Kawtar
Path Finder

You can put the inputs.conf here?

0 Karma

Kawtar
Path Finder

You can put the inputs.conf here?

0 Karma
Got questions? Get answers!

Join the Splunk Community Slack to learn, troubleshoot, and make connections with fellow Splunk practitioners in real time!

Meet up IRL or virtually!

Join Splunk User Groups to connect and learn in-person by region or remotely by topic or industry.

Get Updates on the Splunk Community!

Design, Compete, Win: Submit Your Best Splunk Dashboards for a .conf26 Pass

Hello Splunkers,  We’re excited to kick off a Splunk Dashboard contest! We know that dashboards are a primary ...

May 2026 Splunk Expert Sessions: Security & Observability

Level Up Your Operations: May 2026 Splunk Expert Sessions Whether you are refining your security posture or ...

Network to App: Observability Unlocked [May & June Series]

In today’s digital landscape, your environment is no longer confined to the data center. It spans complex ...