Getting Data In

Enable WMI:LocalNetwork

rgraetz
New Member

Hello,

How to enable WMI:LocalNetwork? Where is the correct config file? Doesn't find anything about the syntax in the wiki.....

thx alot.....

Tags (1)
0 Karma

proctorgeorge
Path Finder

Hello rgraetz,

Here are some assumptions I am making about your question, if these are incorrect then please clarify in your question.

1: That you have the Windows App installed and are using it to gather WMI information.

2: That you are not using deployment clients or light weight forwarders.

If that is the case then in the folder %SPLUNK-INSTALL%\etc\apps\windows\local (ex. C:\Program Files\Splunk\etc\apps\windows\local) on the server you want to monitor there should be a file called wmi.conf that holds configurations for WMI inputs. It's got stanzas like this inside:

 [WMI:FreeDiskSpace] 
 interval = 60
 disabled = 0 
 server = localhost

You want to Add (or un-disable) the LocalNetwork one, which will look something like this:

[WMI:LocalNetwork]
interval = 300
disabled = 0

TL;DR: The correct config file is wmi.conf in the folder %SPLUNK-INSTALL%\etc\apps\windows\local and the syntax is like above 🙂

Got questions? Get answers!

Join the Splunk Community Slack to learn, troubleshoot, and make connections with fellow Splunk practitioners in real time!

Meet up IRL or virtually!

Join Splunk User Groups to connect and learn in-person by region or remotely by topic or industry.

Get Updates on the Splunk Community!

Data Management Digest – August 2026

MichelleCorpora_1-1788182384472.png Welcome to the August 2026 edition of Data Management Digest! August was a ...

Your Feedback. Our Roadmap. Visit the PX Feedback Booth at .conf26

You use Splunk every day, come and help shape what's next.  Save Your Seat: Product-Focused Sessions at ...

Agentic SOC Triage: Investigating Splunk ES Notables with MCP Server and a Local LLM

The Problem: Too Many Alerts, Too Little Context Security operations teams running Splunk Enterprise Security ...