Getting Data In

WMI in windows 2000

katalinali
Path Finder

I have polled wmi query from windows 2000 to splunk, as there is not PerfFormattedData class. I use PerfRawData, but the cpu data in PerfRawData need some calculations so that it will give same result as PerfFormattedData. Can I modify splunk-wmi.exe or have any other method so the data input to splunk is right.

Tags (1)
0 Karma

gkanapathy
Splunk Employee
Splunk Employee

gkanapathy
Splunk Employee
Splunk Employee

No you can't. Of course Splunk provides a large number of commands to evaluate and transform data when you view it instead of when you index it.

0 Karma

katalinali
Path Finder

I know what is wql, my point is the calculation after polling value from wmi and before splunk access. I need the method which allow me to modify the data after generate from splunk-wmi.exe and before index by splunk. As the restricted environment, I can't use external program for the very last minute, so is splunk can provide a way to achieve my goal, for example, may I change some files so the splunk-wmi.exe can do calculation when it queries wql

Thanks

Got questions? Get answers!

Join the Splunk Community Slack to learn, troubleshoot, and make connections with fellow Splunk practitioners in real time!

Meet up IRL or virtually!

Join Splunk User Groups to connect and learn in-person by region or remotely by topic or industry.

Get Updates on the Splunk Community!

Mastering Threat Intelligence in ES 8.5, Splunk AI Assistant v2, and More from Splunk ...

Splunk Lantern is Splunk’s customer success center that provides practical guidance from Splunk experts on key ...

Break the Build: Inside the KubeDoom Lounge at .conf26

    You step up to the machine. The pixelated corridors of a certain 1993 FPS load in front of you, EMP Pulse ...

Splunk Auto Ingestion Parallel Pipeline Scaling

Why this feature matters Many Splunk environments experience ingestion pressure long before the host is fully ...