Getting Data In

Forwarder and WMI

jmbytemoney
Engager

Hi there,

I have a Linux splunk server running and would like to monitor the WMI data (CPU,Memory) from a Windows pc. If I install the full splunk application on the Windows pc and forward the data to my splunk server I get data using the Windows app including WMI data. I then uninstalled the full splunk on the Windows box and tried to use the universal forwarder alone. I get data flowing to my Linux splunk server from the Windows PC however the WMI data is not populating. I have read countless questions posted on here and can simply not crack it. I have checked that it is not a firewall or antivirus issue as there is data flowing.

When trying to follow the prompt: "If you want to add additional hosts you can do so in the WMI inputs section of Manager." I simply get:

404 Not Found
Return to Splunk home page
Splunk cannot find "admin/win-wmi-collections".

Any suggestions?

0 Karma

cmonig
Explorer

Hi,

have you checked that the WMI monitor stanzas in the inputs.conf on your forwarder are set / enabled?

What does the output look like when you do a

$SPLUNK_HOME/bin/splunk list monitor

on the universal forwarder?

Cheers,

Christoph

0 Karma
Get Updates on the Splunk Community!

Index This | I am a number, but when you add ‘G’ to me, I go away. What number am I?

March 2024 Edition Hayyy Splunk Education Enthusiasts and the Eternally Curious!  We’re back with another ...

What’s New in Splunk App for PCI Compliance 5.3.1?

The Splunk App for PCI Compliance allows customers to extend the power of their existing Splunk solution with ...

Extending Observability Content to Splunk Cloud

Register to join us !   In this Extending Observability Content to Splunk Cloud Tech Talk, you'll see how to ...