Getting Data In

How do I add additional performance counters to the Splunk UF Collector?

MTravisVolker
Explorer

We are attempting to add Microsoft RAS Total counters from PerfMon to the Splunk UF collector. We updated the local/inputs.conf as follows.
alt text

These counters are available on the host but they aren't being collected by Splunk.

jgibby
Explorer

I found this useful:

Specify valid regular expressions to capture multiple performance monitor objects

instead of asterisk, you'd have to use dot-asterisk or be explicit with the object, example:

object = RAS Total

also:
If you set the useEnglishOnly attribute to true, you cannot use wildcards or regular expressions for...

Get Updates on the Splunk Community!

Accelerating Observability as Code with the Splunk AI Assistant

We’ve seen in previous posts what Observability as Code (OaC) is and how it’s now essential for managing ...

Integrating Splunk Search API and Quarto to Create Reproducible Investigation ...

 Splunk is More Than Just the Web Console For Digital Forensics and Incident Response (DFIR) practitioners, ...

Congratulations to the 2025-2026 SplunkTrust!

Hello, Splunk Community! We are beyond thrilled to announce our newest group of SplunkTrust members!  The ...