Splunk Enterprise

Intermediate Forwarder not sending Windows Metrics

Jordan1
Loves-to-Learn Lots

Hi all,

 

We have a Splunk Intermediate Forwarder (Heavy Forwarder) set up to receive logs from Universal Forwarders that sit in different networks. The Forwarding is working fine for logs as we can see the internal logs and Windows Events in our index cluster.

This issue is with the Windows Performance Metrics which aren't in our performance metrics indexes. I can see the Universal Forwarders are collecting the metrics from the Internal logs as these are being forwarded successfully. 

Any suggestions would be helpful

0 Karma

kiran_panchavat
Champion

@Jordan1 Hey Jordan, Can you please check your inputs.conf configuration files are properly configured to collect and forward these metrics. If it is possible, can you paste your inputs.conf here. Make sure that the data from the Universal Forwarders is being routed to the correct index for performance metrics.

Refer the below documents. 

https://community.splunk.com/t5/All-Apps-and-Add-ons/What-is-the-best-way-to-migrate-Windows-perform...

https://docs.splunk.com/Documentation/WindowsAddOn/latest/User/Configuration?_gl=1*41uap*_ga*OTg0MDQ... 

Did this help? If yes, please consider giving kudos, marking it as the solution, or commenting for clarification — your feedback keeps the community going!
0 Karma
Career Survey
First 500 qualified respondents will receive a $20 gift card! Tell us about your professional Splunk journey.

Can’t make it to .conf25? Join us online!

Get Updates on the Splunk Community!

Can’t Make It to Boston? Stream .conf25 and Learn with Haya Husain

Boston may be buzzing this September with Splunk University and .conf25, but you don’t have to pack a bag to ...

Splunk Lantern’s Guide to The Most Popular .conf25 Sessions

Splunk Lantern is a Splunk customer success center that provides advice from Splunk experts on valuable data ...

Unlock What’s Next: The Splunk Cloud Platform at .conf25

In just a few days, Boston will be buzzing as the Splunk team and thousands of community members come together ...