Getting Data In

Windows Universal Forwarder stopped logging perfmon: How can I restore this feature?

twinspop
Influencer

I have ~ 800 windows servers getting their configs from a deployment server. Often when i roll a new version of the perf app out, and splunk restarts, perfmon targets stop logging completely from some hosts. Splunk UF version 4.3-6.0 running on Windows 2003-2008.

Why? Is there a known workaround?

EDIT: Non-perfmon targets continue to work normally on these servers

EDIT2:

inputs.conf

[script://$SPLUNK_HOME\bin\scripts\splunk-perfmon.path]
disabled = 0

perfmon.conf

[PERFMON:CPU]
counters = % Processor Time
disabled = 0
instances = _Total
interval = 60
object = Processor
index = perf
1 Solution

linu1988
Champion

After splunk 5 there is no perfmon.conf. While upgrading some gets migrated to inputs.conf. sometimes if the migration doesn't happen properly then they don't forward. The configurations are case sensitive.

Replace like below.

[perfmon://CPU]
counters = % Processor Time
disabled = 0
instances = _Total
interval = 60
object = Processor
index = perf

Thanks,
L

View solution in original post

linu1988
Champion

After splunk 5 there is no perfmon.conf. While upgrading some gets migrated to inputs.conf. sometimes if the migration doesn't happen properly then they don't forward. The configurations are case sensitive.

Replace like below.

[perfmon://CPU]
counters = % Processor Time
disabled = 0
instances = _Total
interval = 60
object = Processor
index = perf

Thanks,
L

twinspop
Influencer

Thank you! I didn't grok what you were saying in the first comment. 🙂

0 Karma

twinspop
Influencer

They all have identical settings. Let's just focus on the 6.0 SUF servers. Some work and some don't. They have identical configs. Reboots don't cure the problem.

0 Karma

linu1988
Champion

they have different syntax , if not migrated properly they wont forward the data.

include perfmon in the inputs.conf file and restart

0 Karma
Got questions? Get answers!

Join the Splunk Community Slack to learn, troubleshoot, and make connections with fellow Splunk practitioners in real time!

Meet up IRL or virtually!

Join Splunk User Groups to connect and learn in-person by region or remotely by topic or industry.

Get Updates on the Splunk Community!

Announcing Modern Navigation: A New Era of Splunk User Experience

We are excited to introduce the Modern Navigation feature in the Splunk Platform, available to both cloud and ...

Modernize your Splunk Apps – Introducing Python 3.13 in Splunk

We are excited to announce that the upcoming releases of Splunk Enterprise 10.2.x and Splunk Cloud Platform ...

Step into “Hunt the Insider: An Splunk ES Premier Mystery” to catch a cybercriminal ...

After a whole week of being on call, you fell asleep on your keyboard, and you hit a sequence of buttons that ...