Getting Data In

Capturing CPU and Memory in remote Windows servers from a Linux -Splunk server.

dannux
Path Finder

I have Splunk installed on a Linux server. It is indexing CPU and Memory usage for many Unix server. How can I capture CPU and MeM usage for Windows servers?

Thanks,
Dan

Tags (4)

lakshman239
Influencer

Hi, do we still have the scaling issues with WMI in the latest Splunk Add on for windows?

0 Karma

sf-mike
Splunk Employee
Splunk Employee

To build upon the above answer:

The Windows app will do this but does not use Perfmon. You install the app on your Linux box and also on a Windows forwarder.

To gather the data from Windows, You'll need to install the app on the Windows forwarder. The better way is to install the forwarder on each Windows host because of scaling issues inherent with WMI. If you do decide to use WMI, then you'll need at least 1 forwarder installed on a Windows host. Typically this would be done in an AD domain. The forwarder must be installed using AD credentials that can access all the hosts in the domain.

See this article:

http://docs.splunk.com/Documentation/Splunk/4.3/Data/MonitorWMIdata

0 Karma

hexx
Splunk Employee
Splunk Employee

I strongly recommend that you read this documentation topic on Real-time Windows performance monitoring. There's two approaches to this :

You cannot collect this kind of data remotely from a Linux indexer or forwarder.

Get Updates on the Splunk Community!

Introducing the Splunk Community Dashboard Challenge!

Welcome to Splunk Community Dashboard Challenge! This is your chance to showcase your skills in creating ...

Wondering How to Build Resiliency in the Cloud?

IT leaders are choosing Splunk Cloud as an ideal cloud transformation platform to drive business resilience,  ...

Updated Data Management and AWS GDI Inventory in Splunk Observability

We’re making some changes to Data Management and Infrastructure Inventory for AWS. The Data Management page, ...