Hi @skrish91
Have a look at this :
[perfmon://<name>]
* This section explains possible settings for configuring
the Windows Performance Monitor input.
* Each perfmon:// stanza represents an individually configured performance
monitoring input. If you configure the input through Splunk Web, then the
value of "<NAME>" matches what was specified there. While you can add
performance monitor inputs manually, Splunk recommends that you use Splunk
Web to configure them, because it is easy to mistype the values for
Performance Monitor objects, counters and instances.
* NOTE: The perfmon stanza is for local systems ONLY. To define performance
monitor inputs for remote machines, use wmi.conf.
You can enable the perfmon you need and then add it to your inputs.conf file.
Cheers,
David
... View more