Splunk Enterprise

Does anybody have a german version of perfmon.conf for Splunk for Exchange or some experience with it?

btiggemann
Path Finder

Hello,

we are using the Splunk App for Ms Exchange on Windows servers that are installed in German. I know that this is not best practise. But is there anybody who has done a translation of the perfmon counters to the German ones? Our problem is, that the default perfmon.conf is not working, because the counters are named different in an other language. Maybe someone has done a Splunk for Exchange installation in Germany and has some experiences?

Thanks in advance
and best regards
Benjamin

0 Karma
1 Solution

ahall_splunk
Splunk Employee
Splunk Employee

Localizing any splunk app is not easy. In the case of the Splunk App for Microsoft Exchange, you will need to go into perfmon.conf and localize each counter, then go into macros.conf, eventtypes.conf and each view and look for the non-localized counter and change it. While this is trivial to do, it does require time and it will break whenever we upgrade the app, causing you to repeat the process all over again.

View solution in original post

0 Karma

ahall_splunk
Splunk Employee
Splunk Employee

Localizing any splunk app is not easy. In the case of the Splunk App for Microsoft Exchange, you will need to go into perfmon.conf and localize each counter, then go into macros.conf, eventtypes.conf and each view and look for the non-localized counter and change it. While this is trivial to do, it does require time and it will break whenever we upgrade the app, causing you to repeat the process all over again.

0 Karma

sebastian_herma
New Member

Hi,
we have the same issue, we are having a mixed environment, some english servers in Amerika and some german servers in Germany.

Most of the App Dashboards and collecting jobs on the server side are not usable for our german systems.

How can we get them into the game?

Kind regards,
Sebastian

0 Karma
Get Updates on the Splunk Community!

Enterprise Security Content Update (ESCU) | New Releases

In December, the Splunk Threat Research Team had 1 release of new security content via the Enterprise Security ...

Why am I not seeing the finding in Splunk Enterprise Security Analyst Queue?

(This is the first of a series of 2 blogs). Splunk Enterprise Security is a fantastic tool that offers robust ...

Index This | What are the 12 Days of Splunk-mas?

December 2024 Edition Hayyy Splunk Education Enthusiasts and the Eternally Curious!  We’re back with another ...