Knowledge Management

Do we need to enable counter in client sytem to collect in the splunk server?

rsathish47
Contributor

Hi all,

Do we need to enable counter in client sytem to collect in the splunk server?

Thanks
Sathish R

Tags (1)
0 Karma
1 Solution

laserval
Communicator

If you want to collect data from the counters, you will need to enable them on the machine you're running IIS on. Then the forwarder can index using the perfmon input: http://docs.splunk.com/Documentation/Splunk/6.2.0/Data/Real-timeWindowsperformancemonitoring#Configu...

If you only want client connections you could index the access log files (w3c format) with a monitor input instead.

See this previous question as well: http://answers.splunk.com/answers/187236/is-there-a-way-to-see-current-connections-on-iis-s.html

View solution in original post

0 Karma

laserval
Communicator

If you want to collect data from the counters, you will need to enable them on the machine you're running IIS on. Then the forwarder can index using the perfmon input: http://docs.splunk.com/Documentation/Splunk/6.2.0/Data/Real-timeWindowsperformancemonitoring#Configu...

If you only want client connections you could index the access log files (w3c format) with a monitor input instead.

See this previous question as well: http://answers.splunk.com/answers/187236/is-there-a-way-to-see-current-connections-on-iis-s.html

0 Karma

rsathish47
Contributor

Thank you laserval,

0 Karma

laserval
Communicator

Please clarify a bit:

  • Is this on Windows?
  • What kind of data are you trying to collect?
  • Do you have a Splunk Universal Forwarder installed on the client system?
0 Karma

rsathish47
Contributor

1) Yes it is window
2) IIS (Current Connections, Maximum Connections Total Connection Attempts )
3) yep we have installd Splunk Universal Forwarder client system.

0 Karma
Get Updates on the Splunk Community!

Accelerating Observability as Code with the Splunk AI Assistant

We’ve seen in previous posts what Observability as Code (OaC) is and how it’s now essential for managing ...

Integrating Splunk Search API and Quarto to Create Reproducible Investigation ...

 Splunk is More Than Just the Web Console For Digital Forensics and Incident Response (DFIR) practitioners, ...

Congratulations to the 2025-2026 SplunkTrust!

Hello, Splunk Community! We are beyond thrilled to announce our newest group of SplunkTrust members!  The ...