Getting Data In

addtional host data in the index, but not displaying data on the graph

davidfreer
New Member

Hello,

I have been try to configure the windows app to display data from additional hosts, but without success.

We have:-

1 indexer (windows app (4.2 Rev96023) installed and displaying data for just the Indexer)
1 Search head (Windows app installed and display data for the search head and Indexer)

I’ve looked at the data inputs and determined the WMI data counters are recording data in the ‘default’ (main) index.

I clone the wmi counters and enter my own hosts

I allow it to record for a period of time and manually do a search on some of the counters to confirm the data is in the index

I load the Windows app and select CPU from the performance Management drop down menu, graphs of the search head and indexer appear.

I use the dropdown box to change to the new additional hosts with the WMI counters I cloned above. The name of the host appears in the drop down list, I select it.

The graphs come up with ‘no data’, the ‘Average CPU Load Split By Host’ still display, but only display data for the search head and indexer.

The windows app seems to come with very little information and the help link doesn't work. Can confirm I have followed the correct actions, or are there any additional steps. I did see something about editing a WMI.conf files in the apps/Windows/local folder but not sure what values to put in there.

Please can you help.

Thank you

David

Tags (2)
0 Karma

rovechkin_splun
Splunk Employee
Splunk Employee

I am afraid at this time the application doesn't support CPU statistics from remote hosts. The issue is that it expects the statistics to come from WMI:CPU sourcetype (if you click on a link along "No results found" message you will see a search string like "search source=WMI:CPUTime host= | eval CPULoad = PercentProcessorTime"). The search doesn't include events forwarder from remote hosts.

0 Karma
Get Updates on the Splunk Community!

Index This | I am a number, but when you add ‘G’ to me, I go away. What number am I?

March 2024 Edition Hayyy Splunk Education Enthusiasts and the Eternally Curious!  We’re back with another ...

What’s New in Splunk App for PCI Compliance 5.3.1?

The Splunk App for PCI Compliance allows customers to extend the power of their existing Splunk solution with ...

Extending Observability Content to Splunk Cloud

Register to join us !   In this Extending Observability Content to Splunk Cloud Tech Talk, you'll see how to ...