Getting Data In

How do I add additional performance counters to the Splunk UF Collector?


We are attempting to add Microsoft RAS Total counters from PerfMon to the Splunk UF collector. We updated the local/inputs.conf as follows.
alt text

These counters are available on the host but they aren't being collected by Splunk.


I found this useful:

Specify valid regular expressions to capture multiple performance monitor objects

instead of asterisk, you'd have to use dot-asterisk or be explicit with the object, example:

object = RAS Total

If you set the useEnglishOnly attribute to true, you cannot use wildcards or regular expressions for...

Get Updates on the Splunk Community!

Detecting Remote Code Executions With the Splunk Threat Research Team

WATCH NOWRemote code execution (RCE) vulnerabilities pose a significant risk to organizations. If exploited, ...

Enter the Splunk Community Dashboard Challenge for Your Chance to Win!

The Splunk Community Dashboard Challenge is underway! This is your chance to showcase your skills in creating ...

.conf24 | Session Scheduler is Live!!

.conf24 is happening June 11 - 14 in Las Vegas, and we are thrilled to announce that the conference catalog ...