Can I injest CPU, memory,eventID data in metric index by using SPLUNK app for Windows ?
I am getting data once I injest this data in event index but when I am changing the index to metric index the data stops coming to any index.
#splunkforwarder#splunkappforwindows
Thanks for the hint I was checking via index=metric_indexname query. Utilized mstat it started fetching data.
I presume you're referring to the Splunk Add-on for Windows since the app does not have any inputs.
It's not enough to change the destination index to a metrics index. The format of the data must also change.
See https://docs.splunk.com/Documentation/AddOns/released/Windows/Configuration#Collect_perfmon_data_and... for the list of Windows metrics that are available and how to enable them.
Thanks for your response @richgalloway
I have performed changes as suggested in the link you provided. And have restarted the splunk UF too.
Still facing the same issue and have no error in splunkd.log.
Verify the index name specified in inputs.conf on the UF exists on the indexers.
Please share the query you're using to find the data.
Thanks for the hint I was checking via index=metric_indexname query. Utilized mstat it started fetching data.