Getting Data In

How do I add additional performance counters to the Splunk UF Collector?

MTravisVolker
Explorer

We are attempting to add Microsoft RAS Total counters from PerfMon to the Splunk UF collector. We updated the local/inputs.conf as follows.
alt text

These counters are available on the host but they aren't being collected by Splunk.

jgibby
Explorer

I found this useful:

Specify valid regular expressions to capture multiple performance monitor objects

instead of asterisk, you'd have to use dot-asterisk or be explicit with the object, example:

object = RAS Total

also:
If you set the useEnglishOnly attribute to true, you cannot use wildcards or regular expressions for...

Get Updates on the Splunk Community!

Splunk MCP & Agentic AI: Machine Data Without Limits

  Discover how the Splunk Model Context Protocol (MCP) Server can revolutionize the way your organization ...

Finding Based Detections General Availability

Overview  We’ve come a long way, folks, but here in Enterprise Security 8.4 I’m happy to announce Finding ...

Get Your Hands Dirty (and Your Shoes Comfy): The Splunk Experience

Hands-On Learning and Technical Seminars  Sometimes, you just need to see the code. For those looking for a ...