Getting Data In

WMI in windows 2000

katalinali
Path Finder

I have polled wmi query from windows 2000 to splunk, as there is not PerfFormattedData class. I use PerfRawData, but the cpu data in PerfRawData need some calculations so that it will give same result as PerfFormattedData. Can I modify splunk-wmi.exe or have any other method so the data input to splunk is right.

Tags (1)
0 Karma

gkanapathy
Splunk Employee
Splunk Employee

gkanapathy
Splunk Employee
Splunk Employee

No you can't. Of course Splunk provides a large number of commands to evaluate and transform data when you view it instead of when you index it.

0 Karma

katalinali
Path Finder

I know what is wql, my point is the calculation after polling value from wmi and before splunk access. I need the method which allow me to modify the data after generate from splunk-wmi.exe and before index by splunk. As the restricted environment, I can't use external program for the very last minute, so is splunk can provide a way to achieve my goal, for example, may I change some files so the splunk-wmi.exe can do calculation when it queries wql

Thanks

Get Updates on the Splunk Community!

Building Reliable Asset and Identity Frameworks in Splunk ES

 Accurate asset and identity resolution is the backbone of security operations. Without it, alerts are ...

Cloud Monitoring Console - Unlocking Greater Visibility in SVC Usage Reporting

For Splunk Cloud customers, understanding and optimizing Splunk Virtual Compute (SVC) usage and resource ...

Automatic Discovery Part 3: Practical Use Cases

If you’ve enabled Automatic Discovery in your install of the Splunk Distribution of the OpenTelemetry ...