Getting Data In

Why not all Windows Classes show up in WMI "available classes"?

elusive
Splunk Employee
Splunk Employee

I go to "Manager » Data inputs » WMI data collections » Add New" and enter the host name under "Select target host". I don't see all the classes that I want to select. Why?

Tags (2)

elusive
Splunk Employee
Splunk Employee

The above information is true for older Splunk version, however, with 4.2.x and 4.3.x Win32_PerfFormattedData_* are filtered and will not show up in wmi Splunk Web. If you wish to monitor, it needs to be added manually directly in wmi.conf and restart Splunk.

0 Karma

elusive
Splunk Employee
Splunk Employee

Any classes with a Win32_PerfFormattedData_* prefix will show up in the list. Other classes that does not have Win32_PerfFormattedData_* prefix will not show up in the available classes list.

If you wish to index other than prefixed Win32_PerfFormattedData_* you can enter it manually directly into wmi.conf.

When collecting WMI events make sure that you are able to query in wbemtest using wql as the account who is starting up Splunk services

Get Updates on the Splunk Community!

Adoption of RUM and APM at Splunk

    Unleash the power of Splunk Observability   Watch Now In this can't miss Tech Talk! The Splunk Growth ...

Routing logs with Splunk OTel Collector for Kubernetes

The Splunk Distribution of the OpenTelemetry (OTel) Collector is a product that provides a way to ingest ...

Welcome to the Splunk Community!

(view in My Videos) We're so glad you're here! The Splunk Community is place to connect, learn, give back, and ...