Splunk Search

Monitor number of threads used by a service installed on Windows Server

jfaigan
Engager

I have parts of a Windows .Net application that are installed as services and run as services under an account on Windows Server.

 

I would like to monitor the number of threads that these services are consuming.

 

Is there a way to do that with Splunk?  I have begun looking at the documentation for APM but I am not convinced this is possible under Windows + .Net.

 

Thoughts?  Suggestions?

 

Regards,
Joel

Labels (1)
Tags (2)
0 Karma

jfaigan
Engager

Ok, so I think I have found what I am looking for, however, it is clearly addressed by SignalFx Smart Agent Receiver but this is deprecated.

It is not clear if the Hosts Metric Receiver will provide the same level of info.

The SmartFx documentation clearly states the process threads is an exposed metric.  The Hosts Metric Receiver does not go into sufficient detail.

 

Fingers crossed!

0 Karma

richgalloway
SplunkTrust
SplunkTrust

Look into Microsoft's Sysmon utility (https://docs.microsoft.com/en-us/sysinternals/downloads/sysmon) and the Splunk Add-on for Microsoft Sysmon (https://splunkbase.splunk.com/app/1914/).

---
If this reply helps you, Karma would be appreciated.

jfaigan
Engager

So I do not think SysMon will provide me the info I need, I do appreciate the idea as it led me to Process Monitor.  I will see if there is any kind of integration with Process Mon.

 

Joel

0 Karma

jfaigan
Engager

Ok, great!  Thanks for the quick reply.  I will take a look at that.

0 Karma
Get Updates on the Splunk Community!

Building Reliable Asset and Identity Frameworks in Splunk ES

 Accurate asset and identity resolution is the backbone of security operations. Without it, alerts are ...

Cloud Monitoring Console - Unlocking Greater Visibility in SVC Usage Reporting

For Splunk Cloud customers, understanding and optimizing Splunk Virtual Compute (SVC) usage and resource ...

Automatic Discovery Part 3: Practical Use Cases

If you’ve enabled Automatic Discovery in your install of the Splunk Distribution of the OpenTelemetry ...