Getting Data In

List of valid [perfmon://] stanzas for inputs.conf

roychen
Path Finder

Hi,

I'm trying to configure performance monitoring inputs on a Windows universal forwarder, to send to a Linux indexer, by modifying inputs.conf as per:

http://docs.splunk.com/Documentation/Splunk/5.0.1/Data/Real-timeWindowsperformancemonitoring#Configu...

So far, I've only managed to find a few valid performance objects for the [perfmon://] stanzas by searching in Splunk Answers.

Does anyone know if there's a list of valid performance objects we can use in [perfmon://] stanzas in inputs.conf?

Thanks!

0 Karma
1 Solution

Ron_Naken
Splunk Employee
Splunk Employee

A full list of objects and counters is dependent on what software and services are installed on the target system. The best way to determine what counters are available is to install Splunk on the system, then configure Perfmon or WMI through the Splunk UI. For instance, in "Manager-->Data Inputs-->Local Performance...", you can select from a list of all available objects in a drop-down, then receive a list of available counters for the selected object.

View solution in original post

jalward
Explorer

What I usually do is just put "counters = *" in the perfmon and let that run for 5-10 minutes, then just go search in splunk for that index, host, and object and see what counters it threw.

0 Karma

jpvlsmv
Path Finder

An old question, but not an answer here that I like.

Per http://serverfault.com/questions/149816/easiest-way-to-get-perfmon-counter-names-into-a-text-file you can use the "typeperf.exe -q" (or -qx) command.

But as Ron said, the counters you get are dependent on what software is installed (and/or running) on the system. For example, when you install the .NET CLR, the counters for ".NET CLR Data()\SqlClient: ." are added. If you specify this in inputs.conf on a server that doesn't have the .NET CLR, you (obviously) won't get any data from that counter.

--Joe

0 Karma

Ron_Naken
Splunk Employee
Splunk Employee

A full list of objects and counters is dependent on what software and services are installed on the target system. The best way to determine what counters are available is to install Splunk on the system, then configure Perfmon or WMI through the Splunk UI. For instance, in "Manager-->Data Inputs-->Local Performance...", you can select from a list of all available objects in a drop-down, then receive a list of available counters for the selected object.

roychen
Path Finder

Hi Ron,

Thanks for your answer. I actually installed the Windows version of Splunk on a VM, and tried adding a data input for performance monitoring. From there I was able to determine what objects and counters I could use. It would be nice to have a documented list for easy reference when modifying configuration files, that's all.

0 Karma
Career Survey
First 500 qualified respondents will receive a $20 gift card! Tell us about your professional Splunk journey.

Can’t make it to .conf25? Join us online!

Get Updates on the Splunk Community!

Leveraging Automated Threat Analysis Across the Splunk Ecosystem

Are you leveraging automation to its fullest potential in your threat detection strategy?Our upcoming Security ...

Can’t Make It to Boston? Stream .conf25 and Learn with Haya Husain

Boston may be buzzing this September with Splunk University and .conf25, but you don’t have to pack a bag to ...

Splunk Lantern’s Guide to The Most Popular .conf25 Sessions

Splunk Lantern is a Splunk customer success center that provides advice from Splunk experts on valuable data ...