My Infrastructure App on Splunk 6.1.3 is only showing 1 counter from the perfmon index. I am sending the perfmon data using a UF and can see all of it in the perfmon index when I search it (CPU, Memory etc).
I can't see any difference with this counter (network interface) and the others.
I have been through the documentation and troubleshooting steps but am drawing a blank. Anyone?
Here is part of the Inputs.conf from the Windows add-on local folder on the UF..
Splunk 5.0+ Performance Counters
CPU
[perfmon://CPU]
counters = % Processor Time; % User Time
disabled = 0
instances = *
interval = 300
object = Processor
useEnglishOnly = true
index = perfmon
Logical Disk
[perfmon://LogicalDisk]
counters = % Free Space; Free Megabytes;
disabled = 0
instances = C; D
interval = 7200
object = LogicalDisk
useEnglishOnly = true
index = perfmon
Physical Disk
[perfmon://PhysicalDisk]
counters = Current Disk Queue Length
disabled = 0
instances = *
interval = 10
object = PhysicalDisk
useEnglishOnly = true
index = perfmon
Memory
[perfmon://Memory]
counters = Pages/sec; Available MBytes
disabled = 0
interval = 300
object = Memory
useEnglishOnly = true
index = perfmon
Network
[perfmon://Network]
counters = Bytes Received/sec; Bytes Sent/sec
disabled = 0
instances = *
interval = 300
object = Network Interface
useEnglishOnly = true
index = perfmon
... View more