Getting Data In

How is WinHostMon data gathered?

joeybagofdonuts
Explorer

I'm trying to gather how many CPUs and Cores a server has but, it seems like on most VMs the CPUs and Cores reports as just 1 regardless of the actual number.

Here is the search I was running:

index=windows sourcetype=winhostmon source=processor
| table host cpu* Number*
| dedup host

And here is an section of the output:

hostcpu_architecturecpu_corescpu_countcpu_mhzNumberOfCoresNumberOfProcessors
server1x6411239711
server2x6411239711
server3x6411249711
server4x6411249711
server5x6411239711
server6x6411239711
server7x6411249711
server8x6411319311
server9x6411259411
server10x6411239711
server11x6411239711
server12x6411239711
server13x6411249711
server14x6411259711
server15x6411249711
server16x6411239711
server17x6411239711
server18x6411249711
server19x6411259711
server20x6411249711
server21x6411239711
server22x6411239711
server23x6411249711
server24x6411259711
server25x6411239711



This is what I have in my inputs.conf

[WinHostMon://Processor]

interval = 300

disabled = 0

type = Processor

What commands or data sources are used to gather this data? I want to view this data on the server itself and see if the server is reporting it to Splunk wrong(my assumption) or if there is a bug in winhostmon.

 

Thanks!

Get Updates on the Splunk Community!

Splunk + ThousandEyes: Correlate frontend, app, and network data to troubleshoot ...

 Are you tired of troubleshooting delays caused by siloed frontend, application, and network data? We've got a ...

Splunk Observability for AI

Don’t miss out on an exciting Tech Talk on Splunk Observability for AI!Discover how Splunk’s agentic AI ...

🔐 Trust at Every Hop: How mTLS in Splunk Enterprise 10.0 Makes Security Simpler

From Idea to Implementation: Why Splunk Built mTLS into Splunk Enterprise 10.0  mTLS wasn’t just a checkbox ...