We are attempting to add Microsoft RAS Total counters from PerfMon to the Splunk UF collector. We updated the local/inputs.conf as follows.
These counters are available on the host but they aren't being collected by Splunk.
I found this useful:
Specify valid regular expressions to capture multiple performance monitor objects
instead of asterisk, you'd have to use dot-asterisk or be explicit with the object, example:
object = RAS Total