I'd like to store the data collected by the "Splunk Add-on for Microsoft SQL Server" in a metrics index. Initially I installed the TA as as described and it collected data to a normal index with no problems. So I updated it's inputs.conf file to point to the metrics index which failed because the data wasn't structured correctly. So after a little bit of Googling I crafted a props and transforms files to change the counter field to metric_name (mainly based on this answer: Sending-Perfmon-data-to-metrics-index ) but it's still not working.
In inputs.conf file looks like so (I'm just showing one measure as an example):
object = Processor
counters = % Processor Time
instances = _Total
interval = 60
showZeroValue = 1
mode = single
disabled = 0
index = em_metrics
sourcetype = PerfmonMetrics:sqlserverhost:processor
Thanks for your response. I haven't really got this working still (I have a solution using Cribl to change the data later on) - I'm still struggling to get access to the heavy forwarder. However I agreed with your advice that the the props and transforms files need to go on the Heavy Forwarder.