Hi Splunkers,
I'm trying to use ITSI to monitor my Windows intrastructure.
I used the data collection script (generated by ITSI) to automatically install and configure the splunk forwarder on a test windows 2019 server.
I see the data stream coming from the test server to indexer. The entity is correctly created but both the Sample service and base searches created with the "Data Integrations -> Monitoring MS Windows" doesn't work.
For what I understood until now there is a mismatch between the sourcetype assinged by forwarder and the one used in base searches. sourcetype=perfmonMK:LogicalDisk (in base search) vs sourcetype=PerfmonMetrics:LogicalDisk (in indexed data)
Is there someone else with the same issue? Could be a bug? Any tips to fix ?