Getting Data In

splunk-perfmon.path (sic?)

echalex
Builder

Hi,

As I'm installing TA's on windows hosts, I see that the PerformanceMonitor source is specified as

[script://$SPLUNK_HOME\bin\scripts\splunk-perfmon.path]

The file itself is called splunk-perfmon.exe. Is this intentional - as in disabling accidental usage of the exe, a Splunk trick or a typo?

Tags (2)
0 Karma
1 Solution

bmacias84
Champion

I dont think its a trick or a typo. Its very similar to having a bat or sh file referance another path and excutable. If you notice that scripted input referances [script://$SPLUNK_HOME\bin\scripts\splunk-perfmon.path] and splunk-perfmon.path referances $SPLUNK_HOME\bin\splunk-perfmon.exe. I've seen this done in a few TAs.

You could enter the splunk-perfmon.exe path directly, but you have have a script change the return data or formatting with your script. I think scripted inputs are done this way for consistancy when referancing executables.

View solution in original post

bmacias84
Champion

I dont think its a trick or a typo. Its very similar to having a bat or sh file referance another path and excutable. If you notice that scripted input referances [script://$SPLUNK_HOME\bin\scripts\splunk-perfmon.path] and splunk-perfmon.path referances $SPLUNK_HOME\bin\splunk-perfmon.exe. I've seen this done in a few TAs.

You could enter the splunk-perfmon.exe path directly, but you have have a script change the return data or formatting with your script. I think scripted inputs are done this way for consistancy when referancing executables.

echalex
Builder

Yes, it is indeed not a typo or trick. I was staring myself blind at the splunk-perfmon.exe in $SPLUNK_HOME/bin and did not see that the conf actually points to the subdirectory scripts, which includes the .path-scripts.

0 Karma
Get Updates on the Splunk Community!

Splunk Observability for AI

Don’t miss out on an exciting Tech Talk on Splunk Observability for AI!Discover how Splunk’s agentic AI ...

Splunk Enterprise Security 8.x: The Essential Upgrade for Threat Detection, ...

Watch On Demand the Tech Talk on November 6 at 11AM PT, and empower your SOC to reach new heights! Duration: ...

Splunk Observability as Code: From Zero to Dashboard

For the details on what Self-Service Observability and Observability as Code is, we have some awesome content ...