Getting Data In

Why not all Windows Classes show up in WMI "available classes"?

elusive
Splunk Employee
Splunk Employee

I go to "Manager » Data inputs » WMI data collections » Add New" and enter the host name under "Select target host". I don't see all the classes that I want to select. Why?

Tags (2)

elusive
Splunk Employee
Splunk Employee

The above information is true for older Splunk version, however, with 4.2.x and 4.3.x Win32_PerfFormattedData_* are filtered and will not show up in wmi Splunk Web. If you wish to monitor, it needs to be added manually directly in wmi.conf and restart Splunk.

0 Karma

elusive
Splunk Employee
Splunk Employee

Any classes with a Win32_PerfFormattedData_* prefix will show up in the list. Other classes that does not have Win32_PerfFormattedData_* prefix will not show up in the available classes list.

If you wish to index other than prefixed Win32_PerfFormattedData_* you can enter it manually directly into wmi.conf.

When collecting WMI events make sure that you are able to query in wbemtest using wql as the account who is starting up Splunk services

Career Survey
First 500 qualified respondents will receive a $20 gift card! Tell us about your professional Splunk journey.

Can’t make it to .conf25? Join us online!

Get Updates on the Splunk Community!

Community Content Calendar, September edition

Welcome to another insightful post from our Community Content Calendar! We're thrilled to continue bringing ...

Splunkbase Unveils New App Listing Management Public Preview

Splunkbase Unveils New App Listing Management Public PreviewWe're thrilled to announce the public preview of ...

Leveraging Automated Threat Analysis Across the Splunk Ecosystem

Are you leveraging automation to its fullest potential in your threat detection strategy?Our upcoming Security ...